InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2401. |
Solve : Virus affecting search engine! PLEASE HELP ME GET RID OF THIS THING!? |
|
Answer» Your welcome. |
|
| 2402. |
Solve : Zonealarm help and annoying popups.? |
|
Answer» A friend of mine has asked me for help on popups that appear on the taskbar when leaving sites. They use AVG, Spybot, and this Zonealarm thing which l NOTHING about. The taskbar is now showing a black "z" whereas it was in colour before and ANY trusted site l happen to post to them is blocked by Zonealarm. But when l do a search on zonealarm some sites say it's an "all in one prevention" package and some sites say it is just a "firewall" package. ] That's the thing....If it's the antivirus version, then definitely get rid of it. Two antivirus programs can cause problems. If it's the firewall version, then just play around with the settings a bit. Look for something like "popup control" or similar.no problem willy |
|
| 2403. |
Solve : svchost.exe?????? |
|
Answer» Man your good!!!!! No more error messages and my sound card is working again! Thanks Sooooo much for all your help! So did I have a virus that was causing all of my problems and will Norton be able to protect my system in the future?No antivirus is bulletproof so anything can happen. Just be careful what you download.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your COMPUTER. Also stop certain cookies from being ADDED to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2404. |
Solve : virtumonde infecting my computer? |
|
Answer» Without being able to log on then you will have a hard time trying to reset a password. Unless you are familiar with Linux then you might be able to GET into Windows that way and reset or crack it but I'm not sure it would WORK or not. never done it myself. |
|
| 2405. |
Solve : How do I remove Norton AV?? |
|
Answer» What is a good freeware TOOL to REMOVE Norton AV? How do I remove it? It came pre-installed with my Vista.Here YA go: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039Kpac..Can I please jump in here? I don't mean to hijack this CONVERSATION, but I WENT to your link and it asks to name the product I have and they gave a long list of Norton products. ie..Norton 2003, 2004, etc. How can I find out which Norton one I have ? My Norton has expired, but I am having a horrible time uninstalling it. It just creates more and more problems trying to get rid of it. Can someone Help tell me In extremely simple terms? I am very computers illiterate?? PLEASE HELP ! Universal removal tool. http://www.majorgeeks.com/Norton_Removal_Tool_SymNRT_d4749.html |
|
| 2406. |
Solve : Ready to Lock and Load? |
|
Answer» Ok guys (and or gals), I have produced the needed logs to GET rid of this cursed problem: Could you please just double check the spelling of the error message you provided as a quick search on google for the filename 'luneap.dll' gives zero results...?? Strange... If you look at the below line from his HijackThis log you will see luneap.dll. O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,luneap.dll,gexixj.dll,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLLtrojan downloader malware OFTEN randomly generates names for the dlls it installs.Yes, that is the exact spelling. I too searched for this file on google and found nothing. I also thought that strange. HJT found it. Should I delete this? If so, How? If this file name was created by a virus, any ideas on zapping it? I feel better knowing experts are on the job here!No point deleting it, it will most likely come back. If I was you I'd hold on for professional help to post back to you here.Quote from: mroilfield on April 14, 2009, 10:14:58 AM If you look at the below line from his HijackThis log you will see luneap.dll. Yeah, sorry seen them now... I was LOGGED out due to inactivity when i replied before so did not see his attachments...Should I delete this? If so how? Thanks..... Quote from: mareze2 on April 14, 2009, 04:42:11 PM Should I delete this? If so how? Thanks..... Just hold on before deleting anything and let one of the specialist have a good look at your logs and then give you guidance. |
|
| 2407. |
Solve : Sysxd and possible trogan? |
|
Answer» Quote Why RENAME HijackThis to "sniper.exe"? Some malware can "hide" from the hijackthis.exe. Renaming it ensures that won't happen. Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: SAVE Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. If needed, this animation will guide you through the process. |
|
| 2408. |
Solve : search engine pages being rerouted? |
|
Answer» I've recently experienced a lot of virus activity on my computer...Have downloaded multiple programs, but am currently USING RegCure and it is able to identify and remove malware and viruses. Also using Symatic Antivirus...both programs have cleaned anything found...but I'm still experiencing this re-routing problem..when i click on the link to a search result, it goes to another page, i have to go back and re-click for it to go to the intended page. I've followed the procedure for hijackthis (i read on another thread)...hopefully i'm doing the right thing by making a new thread..my apologies if i'm not following the correct procedure...i'm attaching the log file from hijack this (i read u wanted it attached rather than posted)...please help me..i'm so frustrated with all this crap on my comptuer! crap..ok uninstall it i assume? Yes, definitely uninstall. Unfortunately, you'll have to wait for a Specialist to help with the malware removal....... |
|
| 2409. |
Solve : Viruses wont let my computer Boot up! need Help!!!? |
|
Answer» I've been RUNNING into a buffer overload problem recently on my laptop (i'm sure its DUE to spyware) so i downloaded a software called COMODO. I had problems installing it... and then... it just wouldnt' boot up anymore... it loads the SCREEN that says "LOADING Windows..." then it stays like that for hours on end... what can i do?? |
|
| 2410. |
Solve : Sysxvd.exe Error Message? |
|
Answer» Hello,
---------- Download DDS by sUBs and save it to your desktop. Alternate DDS download link Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply. DDS (Ver_09-03-16.01) - NTFSx86 Run by Steven Guiles at 19:42:35.07 on Thu 04/16/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.210 [GMT -4:00] AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe svchost.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Steven Guiles\Desktop\dds.pif C:\WINDOWS\system32\wuauclt.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mWindow Title = Microsoft Internet Explorer provided by Comcast mSearch Bar = uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1 BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar.dll EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe -NoStart uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [DeadAIM] rundll32.exe "c:\program files\aim95\\DeadAIM.ocm",ExportedCheckODLs mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe IE: &Google Search - c:\program files\google\googletoolbar.dll/cmsearch.html IE: Backward &Links - c:\program files\google\googletoolbar.dll/cmbacklinks.html IE: Cac&hed Snapshot of Page - c:\program files\google\googletoolbar.dll/cmcache.html IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: Si&milar Pages - c:\program files\google\googletoolbar.dll/cmsimilar.html IE: Translate into English - c:\program files\google\googletoolbar.dll/cmtrans.html IE: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ IE: {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ IE: {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}c:\program files\partygaming\partypoker\runapp.exe - c:\program files\partygaming\partypoker\runapp.exe\inprocserver32 does not exist! DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1239502760031 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} - hxxp://zone.msn.com/binGame/ZAxRcMgr.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://playgames.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://zone.msn.com/bingame/feed/default/SproutLauncher.cab DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\steven~1\applic~1\mozilla\firefox\profiles\default.lv3\ FF - prefs.js: browser.startup.homepage - www.google.com FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-13 64160] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-10-24 34824] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944] R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2008-10-24 468224] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652] S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-8-18 3584] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408] =============== Created Last 30 ================ 2009-04-16 19:36--d-----c:\docume~1\alluse~1.win\applic~1\NortonInstaller 2009-04-16 19:33--d-h---c:\windows\PIF 2009-04-16 16:46a-dshr--C:\cmdcons 2009-04-16 16:42161,792a-------c:\windows\SWREG.exe 2009-04-16 16:4298,816a-------c:\windows\sed.exe 2009-04-16 13:00--d-----c:\docume~1\steven~1\applic~1\Malwarebytes 2009-04-16 13:0015,504a-------c:\windows\system32\drivers\mbam.sys 2009-04-16 13:0038,496a-------c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-16 12:59--d-----c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2009-04-16 12:59--d-----c:\program files\Malwarebytes' Anti-Malware 2009-04-16 11:01--d-----c:\docume~1\alluse~1.win\applic~1\SUPERAntiSpyware.com 2009-04-16 11:01--d-----c:\program files\SUPERAntiSpyware 2009-04-16 11:01--d-----c:\docume~1\steven~1\applic~1\SUPERAntiSpyware.com 2009-04-16 11:00--d-----c:\program files\common files\Wise Installation Wizard 2009-04-16 10:51--d-----c:\program files\CCleaner 2009-04-16 08:39284,160-c------c:\windows\system32\dllcache\pdh.dll 2009-04-16 08:39401,408-c------c:\windows\system32\dllcache\rpcss.dll 2009-04-16 08:39110,592-c------c:\windows\system32\dllcache\services.exe 2009-04-16 08:39473,600-c------c:\windows\system32\dllcache\fastprox.dll 2009-04-16 08:39227,840-c------c:\windows\system32\dllcache\wmiprvse.exe 2009-04-16 08:39453,120-c------c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-16 08:39729,088-c------c:\windows\system32\dllcache\lsasrv.dll 2009-04-16 08:39714,752-c------c:\windows\system32\dllcache\ntdll.dll 2009-04-16 08:39617,472-c------c:\windows\system32\dllcache\advapi32.dll 2009-04-16 08:382,560--------c:\windows\system32\xpsp4res.dll 2009-04-16 08:381,203,922-c------c:\windows\system32\dllcache\sysmain.sdb 2009-04-16 08:38215,552-c------c:\windows\system32\dllcache\wordpad.exe 2009-04-14 11:1215,688a-------c:\windows\system32\lsdelete.exe 2009-04-13 22:034,096a--sh---C:\Thumbs.db 2009-04-13 20:1064,160a-------c:\windows\system32\drivers\Lbd.sys 2009-04-13 20:09-cd-h---c:\docume~1\alluse~1.win\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-04-12 22:29--d-----c:\docume~1\alluse~1.win\applic~1\vsosdk 2009-04-12 20:5447,360a-------c:\windows\system32\drivers\pcouffin.sys 2009-04-12 20:5447,360a-------c:\docume~1\steven~1\applic~1\pcouffin.sys 2009-04-12 20:5327,496a-------c:\windows\system32\mucltui.dll.mui 2009-04-12 20:53268,648a-------c:\windows\system32\mucltui.dll 2009-03-21 10:06989,696-c------c:\windows\system32\dllcache\kernel32.dll ==================== Find3M ==================== 2009-03-09 05:19410,984a-------c:\windows\system32\deploytk.dll 2009-03-06 10:22284,160a-------c:\windows\system32\pdh.dll 2009-03-02 20:18826,368a-------c:\windows\system32\wininet.dll 2009-02-20 14:0978,336a-------c:\windows\system32\ieencode.dll 2009-02-09 08:10729,088--------c:\windows\system32\lsasrv.dll 2009-02-09 08:10401,408a-------c:\windows\system32\rpcss.dll 2009-02-09 08:10714,752--------c:\windows\system32\ntdll.dll 2009-02-09 08:10617,472--------c:\windows\system32\advapi32.dll 2009-02-09 07:131,846,784--------c:\windows\system32\win32k.sys 2009-02-07 19:022,066,048--------c:\windows\system32\ntkrnlpa.exe 2009-02-06 07:11110,592--------c:\windows\system32\services.exe 2009-02-06 07:082,189,056--------c:\windows\system32\ntoskrnl.exe 2009-02-06 06:3935,328--------c:\windows\system32\sc.exe 2009-02-03 15:5956,832a-------c:\windows\system32\secur32.dll 2009-02-01 13:3548,583a-------c:\docume~1\steven~1\applic~1\upd.exe 2008-07-30 20:5135,296a-------c:\docume~1\steven~1\applic~1\GDIPFONTCACHEV1.DAT 2005-09-25 13:51774,144a-------c:\program files\RngInterstitial.dll 2004-07-22 01:000ac--h---c:\documents and settings\steven guiles\hpothb07.dat 2008-09-18 22:1932,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091820080919\index.dat ============= FINISH: 19:45:38.50 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 5/29/2004 10:25:12 PM System Uptime: 4/16/2009 7:40:55 PM (0 hours ago) Motherboard: Intel Corporation | | D845EPT2 Processor: Intel(R) Pentium(R) 4 CPU 1.80GHz | X1 | 1794/100mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 75 GiB total, 23.548 GiB free. D: is CDROM () E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {36FC9E60-C465-11CF-8056-444553540000} Description: Universal Serial Bus (USB) Controller Device ID: PCI\VEN_8086&DEV_24CD&SUBSYS_01321028&REV_01\3&267A616A&0&EF Manufacturer: Name: Universal Serial Bus (USB) Controller PNP Device ID: PCI\VEN_8086&DEV_24CD&SUBSYS_01321028&REV_01\3&267A616A&0&EF Service: ==== System Restore Points =================== RP1752: 1/29/2009 10:03:30 AM - System Checkpoint RP1753: 1/30/2009 12:57:14 PM - System Checkpoint RP1754: 1/31/2009 1:15:31 PM - System Checkpoint RP1755: 2/1/2009 2:15:55 PM - System Checkpoint RP1756: 2/2/2009 2:27:33 PM - System Checkpoint RP1757: 2/3/2009 3:15:37 PM - System Checkpoint RP1758: 2/4/2009 4:15:31 PM - System Checkpoint RP1759: 2/5/2009 5:14:31 PM - System Checkpoint RP1760: 2/6/2009 6:14:33 PM - System Checkpoint RP1761: 2/7/2009 8:38:45 PM - System Checkpoint RP1762: 2/8/2009 9:34:12 PM - System Checkpoint RP1763: 2/9/2009 10:45:11 PM - System Checkpoint RP1764: 2/10/2009 11:33:02 PM - System Checkpoint RP1765: 2/11/2009 4:44:33 PM - Software Distribution Service 3.0 RP1766: 2/12/2009 5:40:00 PM - System Checkpoint RP1767: 2/13/2009 5:54:43 PM - System Checkpoint RP1768: 2/14/2009 6:36:25 PM - System Checkpoint RP1769: 2/15/2009 6:41:17 PM - Removed ESET NOD32 Antivirus RP1770: 2/15/2009 6:42:00 PM - Removed ESET NOD32 Antivirus RP1771: 2/15/2009 6:46:43 PM - Installed ESET NOD32 Antivirus RP1772: 2/16/2009 6:47:36 PM - System Checkpoint RP1773: 2/17/2009 8:50:50 PM - System Checkpoint RP1774: 2/18/2009 9:18:39 PM - System Checkpoint RP1775: 2/19/2009 9:50:30 PM - System Checkpoint RP1776: 2/20/2009 11:03:01 PM - System Checkpoint RP1777: 2/21/2009 11:50:28 PM - System Checkpoint RP1778: 2/23/2009 12:50:32 AM - System Checkpoint RP1779: 2/24/2009 2:03:02 AM - System Checkpoint RP1780: 2/25/2009 2:49:29 AM - System Checkpoint RP1781: 2/25/2009 8:29:43 AM - Software Distribution Service 3.0 RP1782: 2/26/2009 8:39:37 AM - System Checkpoint RP1783: 2/27/2009 8:40:21 AM - System Checkpoint RP1784: 2/28/2009 11:13:29 AM - System Checkpoint RP1785: 3/1/2009 11:20:43 AM - System Checkpoint RP1786: 3/2/2009 12:08:43 PM - System Checkpoint RP1787: 3/3/2009 1:08:43 PM - System Checkpoint RP1788: 3/4/2009 2:07:45 PM - System Checkpoint RP1789: 3/5/2009 3:07:50 PM - System Checkpoint RP1790: 3/6/2009 4:07:45 PM - System Checkpoint RP1791: 3/7/2009 5:06:56 PM - System Checkpoint RP1792: 3/8/2009 5:27:10 PM - System Checkpoint RP1793: 3/9/2009 6:07:54 PM - System Checkpoint RP1794: 3/10/2009 7:18:58 PM - System Checkpoint RP1795: 3/11/2009 8:06:54 PM - System Checkpoint RP1796: 3/12/2009 2:00:25 AM - Software Distribution Service 3.0 RP1797: 3/13/2009 2:12:00 AM - System Checkpoint RP1798: 3/14/2009 3:12:00 AM - System Checkpoint RP1799: 3/15/2009 10:37:34 AM - Removed Java(TM) 6 Update 11 RP1800: 3/15/2009 10:38:33 AM - Installed Java(TM) 6 Update 12 RP1801: 3/16/2009 11:09:57 AM - System Checkpoint RP1802: 3/17/2009 12:09:52 PM - System Checkpoint RP1803: 3/18/2009 12:47:35 PM - System Checkpoint RP1804: 3/19/2009 12:51:53 PM - System Checkpoint RP1805: 3/20/2009 8:23:31 AM - Software Distribution Service 3.0 RP1806: 3/21/2009 9:30:35 AM - System Checkpoint RP1807: 3/22/2009 9:52:10 AM - System Checkpoint RP1808: 3/23/2009 10:52:02 AM - System Checkpoint RP1809: 3/24/2009 11:50:59 AM - System Checkpoint RP1810: 3/25/2009 12:51:04 PM - System Checkpoint RP1811: 3/26/2009 1:50:11 PM - System Checkpoint RP1812: 3/27/2009 2:50:07 PM - System Checkpoint RP1813: 3/28/2009 3:35:16 PM - System Checkpoint RP1814: 3/29/2009 10:58:03 PM - System Checkpoint RP1815: 3/31/2009 10:11:13 AM - System Checkpoint RP1816: 4/1/2009 6:31:47 PM - Installed Java(TM) 6 Update 13 RP1817: 4/2/2009 9:29:16 PM - System Checkpoint RP1818: 4/3/2009 10:03:13 PM - System Checkpoint RP1819: 4/4/2009 10:56:54 PM - System Checkpoint RP1820: 4/7/2009 8:22:54 AM - System Checkpoint RP1821: 4/8/2009 6:20:09 PM - System Checkpoint RP1822: 4/9/2009 9:12:10 PM - System Checkpoint RP1823: 4/10/2009 9:48:08 PM - System Checkpoint RP1824: 4/11/2009 8:31:04 PM - Removed Bonjour RP1825: 4/11/2009 8:32:00 PM - Removed MobileMe Control Panel RP1826: 4/11/2009 8:32:55 PM - Removed Norton Security Scan RP1827: 4/11/2009 8:33:51 PM - Removed Safari RP1828: 4/11/2009 10:16:38 PM - Software Distribution Service 3.0 RP1829: 4/11/2009 10:27:11 PM - Software Distribution Service 3.0 RP1830: 4/12/2009 11:21:33 PM - System Checkpoint RP1831: 4/13/2009 11:56:54 PM - System Checkpoint RP1832: 4/15/2009 5:49:02 PM - System Checkpoint RP1833: 4/16/2009 8:45:57 AM - Software Distribution Service 3.0 RP1834: 4/16/2009 11:01:00 AM - Installed SUPERAntiSpyware Free Edition RP1835: 4/16/2009 4:43:22 PM - ComboFix created restore point RP1836: 4/16/2009 5:31:52 PM - Removed Adobe Photoshop CS2 RP1837: 4/16/2009 5:37:51 PM - Removed Apple Mobile Device Support RP1838: 4/16/2009 5:39:46 PM - Removed Apple Software Update RP1839: 4/16/2009 5:42:01 PM - Removed HP Memories Disc RP1840: 4/16/2009 5:42:49 PM - Removed LiveUpdate Notice (Symantec Corporation) ==== Installed Programs ====================== Ad-Aware Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Audition 1.5 Adobe Bridge 1.0 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.1.0 Adobe Shockwave Player Adobe Stock Photos 1.0 AOL Instant Messenger Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5 Azureus CCleaner (remove only) Conexant HSF V92 56K RTAD Speakerphone PCI Modem Critical Update for Windows Media Player 11 (KB959772) DeadAIM Dell ResourceCD DVD Decrypter (Remove Only) ESET NOD32 Antivirus FLAC Installer 1.1.0k (remove only) Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) HP Photo and Imaging 2.0 - All-in-One HP Photo and Imaging 2.0 - All-in-One Drivers HP Photo and Imaging 2.0 - hp psc 1200 series hp psc 1200 series iTunes Java(TM) 6 Update 13 Java(TM) 6 Update 7 Logitech Harmony Remote Software 7 Malwarebytes' Anti-Malware Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB928367) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Word 2002 Microsoft Works 2002 Setup Launcher Microsoft Works 6.0 Microsoft Works Suite Add-in for Microsoft Word mkw Audio Compression Toolkit Mozilla Firefox (3.0.9) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Nero 7 Ultra Edition NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up NVIDIA Display Driver OLYMPUS Master QuickTime Remote Control USB Driver Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) SoundMAX Spybot - Search & Destroy 1.2 SUPERAntiSpyware Free Edition TDK Launcher Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VideoLAN VLC media player 0.6.2 Viewpoint Manager (Remove Only) Viewpoint Media Player (Remove Only) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WildTangent Multiplayer Library Winamp Windows Defender Signatures Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver Works Suite OS Pack Works Synchronization ==== Event Viewer Messages From Past Week ======== 4/16/2009 5:39:19 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 4/16/2009 5:25:14 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 4/16/2009 5:13:52 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service to connect. 4/16/2009 5:13:52 PM, error: Service Control Manager [7000] - The Eset Nod32 Boot service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 4/16/2009 1:22:05 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 4/14/2009 3:45:25 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s). 4/14/2009 3:44:11 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 4/14/2009 3:44:00 PM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 4/14/2009 3:42:17 PM, error: Service Control Manager [7034] - The PC Tools Auxiliary Service service terminated unexpectedly. It has done this 1 time(s). 4/14/2009 3:04:09 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The class is configured to run as a security id different from the caller 4/13/2009 5:39:54 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). ==== End Of File ===========================
---------- ---------- Run CCleaner. ---------- How is the computer running now? Many thanks!Sounds good. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2411. |
Solve : THREE LOGS? |
|
Answer» Hello, here are my logs for SuperAntispyware, Malwarebytes' Anti-Malware, and HijackThis. If anything stands out as really harmful and/or can be easily remedied, I would greatly appreciate any advice. Thank you!
----- How is the computer running now?Thank you so much! The pop-ups and error messages are gone, and that was the primary issue. My computer is still somewhat slow, and the fan runs loudly, but the computer is also about four years old. Thanks for your help!Set a New Restore Point to prevent POSSIBLE reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here I would also recommend that you Defrag the computer. There may be a lot of fragmented sections on the drive after cleaning the malware. You can use the built in Windows Defrag or a faster FREE program. Defraggler is very effective and easy to use. Be sure to clean out temp files and restart the computer just before using this. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Done. I am now working through the "Slow Computer? It May Not Be Malware" section, which has awesome information. Thank you again. |
|
| 2412. |
Solve : Need to reformat hard drive do to computer viruses and can't? |
|
Answer» I'm stuck, viruses have taken over the os and I can't reformat hd CAUSE I can't get to a dos prompt or recovery console. I changed the boot sequence to cd/dvd, but when the screen says enter any key to boot from cd nothing happens and it goes straight to hard drive. I can't get in safe mode either and the login screen is asking for an administrative password which I don't know. Any suggestions??? What happens when you try to get into safe mode. |
|
| 2413. |
Solve : Virus/Trojan: DNSCharger or Gaopdxcounter? |
|
Answer» Your welcome. |
|
| 2414. |
Solve : Missing tray icon or two? |
|
Answer» I've searched thru some of the other "tray icon" posts and mine seems like a UNIQUE behavior. |
|
| 2415. |
Solve : Browers not working spontaneously? |
|
Answer» All of my browers (IE, Firefox, and Opera) stop working spontaneously, and the only way I can get them to work is to do a HARD shutdown. My system will not allow me to do a SOFT shutdown, or reset when the browsers stop working. I am still able to use instant messengers when this happens. I had a virus a few DAYS AGO but I don't think it is completely gone, even though the virus was causing a completely different problem (see six POINTED star post) Here are the logs that were mentioned to post. |
|
| 2416. |
Solve : New version of TDSSServ.Q ?? |
|
Answer» My logs: HJT & random/random |
|
| 2417. |
Solve : gateway boot issue? |
|
Answer» A friend brought his g-way over to the house and said he had a virus....it will bring up the black logo screen and boot MENU f10 and bios settings f2 but will do NOTHING else. I noticed that it could only detect the mouse after I CHECKED the hard drive connections??? |
|
| 2418. |
Solve : PowerReg Scheduler? |
|
Answer» Does anybody KNOW what PowerReg Scheduler is? ViRobot found it and I had it deleted.Is is NORMALLY advised to REMOVE it. Among other THINGS it slows many computers down. |
|
| 2419. |
Solve : Multiple IE windows opening, appears to be adware/malware, now IE won't connect? |
|
Answer» We started noticing all the problems when about 25 IE windows were open on my wife's laptop last Saturday morning when we got up. Not sure what was downloaded that started all of this.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Open the SDFix folder and double click RunThis.bat to start the script.
======================================= SDFix: Version 1.220 Run by Julie on Tue 09/02/2008 at 11:01 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\system32\atsxyzd.sys - Deleted C:\WINDOWS\system32\comsa32.sys - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-02 23:32:10 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized APPLICATION Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"="C:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe:*:Enabled:TrueVector Service" "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe" "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Mon 11 May 1998 93,880 ..SH. --- "C:\COMMAND.COM" THU 21 Apr 2005 101,376 A..H. --- "C:\MPC-Backup\docs on Derrek's Trading Computer 1 (Dbtrading1)\~WRL3518.tmp" Wed 17 Oct 2007 145,920 ..SHR --- "C:\Program Files\Sprint music manager\Setup.exe" Wed 1 Aug 2007 53,248 A.SHR --- "C:\Program Files\Sprint music manager\_Setupx.dll" Mon 2 Jan 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Thu 21 Apr 2005 101,376 A..H. --- "C:\MPC-Backup\11-07-06-backup\docs\~WRL3518.tmp" Sun 24 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp" Sun 17 Jul 2005 26,624 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL0549.tmp" Tue 26 Jul 2005 25,088 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL0750.tmp" Sun 17 Jul 2005 26,624 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1032.tmp" Tue 26 Jul 2005 24,064 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1113.tmp" Sun 17 Jul 2005 27,648 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1116.tmp" Tue 26 Jul 2005 26,112 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1119.tmp" Sun 17 Jul 2005 27,648 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1183.tmp" Wed 27 Jul 2005 25,088 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1286.tmp" Tue 26 Jul 2005 24,064 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL1364.tmp" Tue 26 Jul 2005 24,064 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2305.tmp" Sun 17 Jul 2005 28,160 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2443.tmp" Sun 17 Jul 2005 28,160 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2697.tmp" Sun 17 Jul 2005 28,160 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2754.tmp" Sun 17 Jul 2005 28,160 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2757.tmp" Sun 17 Jul 2005 25,088 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2778.tmp" Sun 17 Jul 2005 28,160 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2797.tmp" Sun 17 Jul 2005 28,672 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2819.tmp" Sun 17 Jul 2005 24,064 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL2969.tmp" Tue 26 Jul 2005 24,576 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL3211.tmp" Tue 26 Jul 2005 25,600 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL3449.tmp" Sun 17 Jul 2005 20,992 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL3920.tmp" Sun 17 Jul 2005 27,136 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Marketing\~WRL3931.tmp" Mon 2 Jan 2006 4,348 A..H. --- "C:\Documents and Settings\Julie\My Documents\My Music\License Backup\drmv1key.bak" Sun 26 Feb 2006 20 A..H. --- "C:\Documents and Settings\Julie\My Documents\My Music\License Backup\drmv1lic.bak" Mon 2 Jan 2006 400 A.SH. --- "C:\Documents and Settings\Julie\My Documents\My Music\License Backup\drmv2key.bak" Sat 2 Dec 2006 85,504 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL0026.tmp" Sun 3 Dec 2006 84,992 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL0263.tmp" Sun 3 Dec 2006 88,064 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL0875.tmp" Sat 2 Dec 2006 77,312 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL0953.tmp" Sat 2 Dec 2006 76,800 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL1334.tmp" Sat 2 Dec 2006 51,200 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL1499.tmp" Sat 2 Dec 2006 73,216 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2218.tmp" Sat 2 Dec 2006 24,576 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2256.tmp" Sat 2 Dec 2006 84,992 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2383.tmp" Sun 3 Dec 2006 87,552 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2446.tmp" Sat 2 Dec 2006 73,216 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2505.tmp" Sat 2 Dec 2006 76,800 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2756.tmp" Sat 2 Dec 2006 51,200 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2763.tmp" Sat 2 Dec 2006 74,240 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2820.tmp" Sat 2 Dec 2006 85,504 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2929.tmp" Sat 2 Dec 2006 74,240 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL2952.tmp" Sat 2 Dec 2006 84,992 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3125.tmp" Sun 3 Dec 2006 87,552 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3297.tmp" Sat 2 Dec 2006 85,504 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3302.tmp" Sat 2 Dec 2006 35,840 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3556.tmp" Sat 2 Dec 2006 27,136 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3774.tmp" Sat 2 Dec 2006 27,136 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\LarryGoins\Mentoring\~WRL3775.tmp" Wed 14 May 2008 32,256 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Properties\1307 Ewing Ave\Sale\~WRL1348.tmp" Wed 14 May 2008 32,256 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Properties\1307 Ewing Ave\Sale\~WRL1598.tmp" Wed 14 May 2008 62,464 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Properties\1307 Ewing Ave\Sale\~WRL1743.tmp" Wed 14 May 2008 31,744 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Properties\1307 Ewing Ave\Sale\~WRL2961.tmp" Wed 14 May 2008 62,464 A..H. --- "C:\MPC-Backup\11-07-06-backup\RealEstate\Properties\1307 Ewing Ave\Sale\~WRL3259.tmp" Finished! =========================================================================== Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:37:25 PM, on 9/2/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\afisicx.exe C:\WINDOWS\System32\Atievxx.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\noxtcyr.exe C:\WINDOWS\system32\noytcyr.exe C:\WINDOWS\system32\roxtctm.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\sotpeca.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wsldoekd.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Sprint music manager\MEMonitor.exe C:\Program Files\Trend Micro\HijackThis\snyper.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HotSync Manager.lnk = ? O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'c:\windows\system32\mmchost.dll' missing O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: Domain = kc.rr.com O17 - HKLM\System\CCS\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: NameServer = 24.94.165.25,24.94.163.113 O17 - HKLM\System\CS1\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: Domain = kc.rr.com O17 - HKLM\System\CS1\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: NameServer = 24.94.165.25,24.94.163.113 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLLavgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: afisicx Manages messages (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: noxtcyr Co. Ltd. (noxtcyr) - Unknown owner - C:\WINDOWS\system32\noxtcyr.exe O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe O23 - Service: roxtctm Corporation inc. (roxtctm) - Unknown owner - C:\WINDOWS\system32\roxtctm.exe O23 - Service: sotpeca Corporation (sotpeca) - Unknown owner - C:\WINDOWS\system32\sotpeca.exe O23 - Service: wsldoekd Corporation inc. (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe -- End of file - 7633 bytes Were getting there but there are still some very nasty ones left. Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved DIRECTLY to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. Next set of logs... ================== ComboFix 08-08-31.01 - Julie 2008-09-03 7:45:31.1 - NTFSx86 Running from: C:\Documents and Settings\Julie\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\test.txt C:\WINDOWS\Install.txt C:\WINDOWS\system32\afisicx.exe C:\WINDOWS\system32\inf\svchoct.exe C:\WINDOWS\system32\Install.txt C:\WINDOWS\system32\mywfhit.ini C:\WINDOWS\system32\mywfhit.ini.tmp C:\WINDOWS\system32\noxtcyr.exe C:\WINDOWS\system32\roxtctm.exe C:\WINDOWS\system32\rtl60.bpl C:\WINDOWS\system32\sotpeca.exe C:\WINDOWS\system32\tmpacj0.exe C:\WINDOWS\system32\wsldoekd.exe C:\WINDOWS\tawisys.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_AFISICX -------\Legacy_INTERNET_SERVICE -------\Legacy_MACIDWE -------\Legacy_MSSERVICE -------\Legacy_NOXTCYR -------\Legacy_ROXTCTM -------\Legacy_SEUICTOL -------\Legacy_SOTPECA -------\Legacy_TDXDOWKC -------\Legacy_WSLDOEKD -------\Service_afisicx -------\Service_noxtcyr -------\Service_roxtctm -------\Service_seuictol -------\Service_sotpeca -------\Service_wsldoekd ((((((((((((((((((((((((( Files Created from 2008-08-03 to 2008-09-03 ))))))))))))))))))))))))))))))) . 2008-09-02 22:58 . 2008-09-02 22:58d--------C:\WINDOWS\ERUNT 2008-09-02 19:00 . 2008-09-02 23:34d--------C:\SDFix 2008-09-02 15:16 . 2008-09-02 15:16d--------C:\Program Files\Trend Micro 2008-09-02 15:05 . 2008-06-10 02:3273,728--a------C:\WINDOWS\SYSTEM32\javacpl.cpl 2008-09-02 15:03 . 2008-09-02 15:05d--------C:\Program Files\Java 2008-09-02 15:03 . 2008-09-02 15:03d--------C:\Program Files\Common Files\Java 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Program Files\Malwarebytes' Anti-Malware 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Documents and Settings\Julie\Application Data\Malwarebytes 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-09-02 12:55 . 2008-08-17 15:0438,472--a------C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys 2008-09-02 12:55 . 2008-08-17 15:0417,144--a------C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Program Files\SUPERAntiSpyware 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Documents and Settings\Julie\Application Data\SUPERAntiSpyware.com 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-09-02 07:56 . 2008-09-02 07:56d--------C:\Program Files\CCleaner 2008-09-01 14:38 . 2008-09-03 06:26d--h-----C:\$AVG8.VAULT$ 2008-09-01 13:00 . 2008-09-01 13:00d---s----C:\Documents and Settings\LocalService\UserData 2008-09-01 12:53 . 2008-09-01 12:5376,040--a------C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys 2008-09-01 12:53 . 2008-09-01 12:5310,520--a------C:\WINDOWS\SYSTEM32\avgrsstx.dll 2008-09-01 12:52 . 2008-09-02 07:34d--------C:\WINDOWS\SYSTEM32\DRIVERS\Avg 2008-09-01 12:52 . 2008-09-01 12:52d--------C:\Program Files\AVG 2008-09-01 12:52 . 2008-09-01 12:52d--------C:\Documents and Settings\All Users\Application Data\avg8 2008-09-01 12:52 . 2008-09-01 12:5296,520--a------C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys 2008-09-01 01:06 . 2008-09-01 01:12d--------C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-09-01 01:03 . 2008-09-02 08:25d--------C:\Program Files\Common Files\Wise Installation Wizard 2008-08-31 21:26 . 2008-09-03 07:46d--------C:\WINDOWS\SYSTEM32\inf 2008-08-30 22:23 . 2008-09-01 12:42d--------C:\Documents and Settings\NetworkService\Application Data\StumbleUpon 2008-08-22 14:18 . 2008-08-22 15:38d--------C:\WINDOWS\SYSTEM32\CatRoot_bak 2008-08-20 09:33 . 2008-08-20 09:33d--------C:\WINDOWS\Cache 2008-08-20 09:33 . 2008-08-30 22:47d--------C:\Program Files\Coupons 2008-08-14 19:26 . 2008-05-01 09:30331,776-----c---C:\WINDOWS\SYSTEM32\dllcache\msadce.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-09-02 21:10---------d-----wC:\Documents and Settings\Julie\Application Data\StumbleUpon 2008-09-01 17:24---------d-----wC:\Program Files\Viewpoint 2008-09-01 17:24---------d-----wC:\Documents and Settings\Julie\Application Data\Viewpoint 2008-09-01 17:24---------d-----wC:\Documents and Settings\All Users\Application Data\Viewpoint 2008-09-01 06:09---------d-----wC:\Program Files\Lavasoft 2008-09-01 06:09---------d-----wC:\Documents and Settings\Julie\Application Data\Lavasoft 2008-08-22 00:08---------d-----wC:\Program Files\StumbleUpon 2005-06-17 18:40266--sh--wC:\Program Files\desktop.ini 2005-06-17 18:4011,079-c-ha-wC:\Program Files\folder.htt . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 18:09 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-03 08:00 1235736] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24 278528] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-07-07 02:26 169984] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE] C:\Documents and Settings\Julie\Start Menu\Programs\Startup\ MEMonitor.lnk - C:\Program Files\Sprint music manager\MEMonitor.exe [2008-05-07 18:32:58 951640] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.NTN1"= nuvision.ax [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProvidersmsapsspc.dllschannel.dlldigest.dllmsnss pc.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-03 08:00] R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-03 08:00] R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-03 08:00] R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-01 12:53] R3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 07:48] R3 maestro;ESS Maestro 3 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 07:19] S2 noytcyr;noytcyr Service;C:\WINDOWS\system32\noytcyr.exe [2002-08-29 07:00] S3 ISLP2;Intersil 802.11 Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\islp2nds.sys [2002-10-03 19:07] S3 NuVision;Hauppauge WinTV USB Pro (NTSC);C:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 15:40] . - - - - ORPHANS REMOVED - - - - HKCU-Run-Aim6 - (no file) HKLM-Run-ZoneAlarm Client - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/ R0 -: HKCU-Main,Search Page = hxxp://www.google.com R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 -: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage O17 -: HKLM\CCS\Interface\{435AE094-C503-484D-A19D-AB4437F1BB6F}: NameServer = 24.94.165.25,24.94.163.113 O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-03 07:56:37 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\SYSTEM32\WudfHost.exe C:\WINDOWS\SYSTEM32\Atievxx.exe C:\WINDOWS\SYSTEM32\wscntfy.exe C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\AVG\AVG8\avgupd.exe.old4.Config C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\AVG\AVG8\avgrsx.exe . ************************************************************************** . Completion time: 2008-09-03 8:04:28 - machine was rebooted ComboFix-quarantined-files.txt 2008-09-03 13:04:13 Pre-Run: 11,819,463,168 bytes free Post-Run: 11,758,628,864 bytes free 183--- E O F ---2008-08-15 08:16:19 ============================================================================================================ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:06:17 AM, on 9/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\Atievxx.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Sprint music manager\MEMonitor.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\notepad.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Trend Micro\HijackThis\snyper.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HotSync Manager.lnk = ? O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: Domain = kc.rr.com O17 - HKLM\System\CCS\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: NameServer = 24.94.165.25,24.94.163.113 O17 - HKLM\System\CS1\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: Domain = kc.rr.com O17 - HKLM\System\CS1\Services\Tcpip\..\{435AE094-C503-484D-A19D-AB4437F1BB6F}: NameServer = 24.94.165.25,24.94.163.113 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe -- End of file - 7121 bytes Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: AFISICX INTERNET_SERVICE MACIDWE MSSERVICE NOXTCYR ROXTCTM SEUICTOL SOTPECA TDXDOWKC WSLDOEKD afisicx noxtcyr roxtctm seuictol sotpeca wsldoekd File:: C:\WINDOWS\system32\noytcyr.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Download FixWareout by LonnyRJonesfrom one of the two below links and save it to your desktop.
When you run fixwareout, just follow the prompts, you will need to restart when prompted. After rebooting (restart) back into normal boot mode. Make sure you have all web browsers closed.
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.297 [GMT -5:00] Running from: C:\Documents and Settings\Julie\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Julie\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\mabidwe.exe C:\WINDOWS\system32\noytcyr.exe C:\WINDOWS\system32\roytctm.exe C:\WINDOWS\system32\soxpeca.exe C:\WINDOWS\system32\tdydowkc.exe C:\WINDOWS\system32\tpszxyd.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NOYTCYR -------\Service_noytcyr ((((((((((((((((((((((((( Files Created from 2008-08-03 to 2008-09-03 ))))))))))))))))))))))))))))))) . 2008-09-02 22:58 . 2008-09-02 22:58d--------C:\WINDOWS\ERUNT 2008-09-02 19:00 . 2008-09-02 23:34d--------C:\SDFix 2008-09-02 15:16 . 2008-09-02 15:16d--------C:\Program Files\Trend Micro 2008-09-02 15:05 . 2008-06-10 02:3273,728--a------C:\WINDOWS\SYSTEM32\javacpl.cpl 2008-09-02 15:03 . 2008-09-02 15:05d--------C:\Program Files\Java 2008-09-02 15:03 . 2008-09-02 15:03d--------C:\Program Files\Common Files\Java 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Program Files\Malwarebytes' Anti-Malware 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Documents and Settings\Julie\Application Data\Malwarebytes 2008-09-02 12:55 . 2008-09-02 12:55d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-09-02 12:55 . 2008-08-17 15:0438,472--a------C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys 2008-09-02 12:55 . 2008-08-17 15:0417,144--a------C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Program Files\SUPERAntiSpyware 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Documents and Settings\Julie\Application Data\SUPERAntiSpyware.com 2008-09-02 08:26 . 2008-09-02 08:26d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-09-02 07:56 . 2008-09-02 07:56d--------C:\Program Files\CCleaner 2008-09-01 14:38 . 2008-09-03 18:36d--h-----C:\$AVG8.VAULT$ 2008-09-01 13:00 . 2008-09-01 13:00d---s----C:\Documents and Settings\LocalService\UserData 2008-09-01 12:53 . 2008-09-01 12:5376,040--a------C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys 2008-09-01 12:53 . 2008-09-01 12:5310,520--a------C:\WINDOWS\SYSTEM32\avgrsstx.dll 2008-09-01 12:52 . 2008-09-03 18:27d--------C:\WINDOWS\SYSTEM32\DRIVERS\Avg 2008-09-01 12:52 . 2008-09-01 12:52d--------C:\Program Files\AVG 2008-09-01 12:52 . 2008-09-01 12:52d--------C:\Documents and Settings\All Users\Application Data\avg8 2008-09-01 12:52 . 2008-09-03 08:0097,928--a------C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys 2008-09-01 01:06 . 2008-09-01 01:12d--------C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-09-01 01:03 . 2008-09-02 08:25d--------C:\Program Files\Common Files\Wise Installation Wizard 2008-08-31 21:26 . 2008-09-03 07:46d--------C:\WINDOWS\SYSTEM32\inf 2008-08-30 22:23 . 2008-09-01 12:42d--------C:\Documents and Settings\NetworkService\Application Data\StumbleUpon 2008-08-22 14:18 . 2008-08-22 15:38d--------C:\WINDOWS\SYSTEM32\CatRoot_bak 2008-08-20 09:33 . 2008-08-20 09:33d--------C:\WINDOWS\Cache 2008-08-20 09:33 . 2008-08-30 22:47d--------C:\Program Files\Coupons 2008-08-14 19:26 . 2008-05-01 09:30331,776-----c---C:\WINDOWS\SYSTEM32\dllcache\msadce.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-09-03 23:36---------d-----wC:\Documents and Settings\Julie\Application Data\StumbleUpon 2008-09-01 17:24---------d-----wC:\Program Files\Viewpoint 2008-09-01 17:24---------d-----wC:\Documents and Settings\Julie\Application Data\Viewpoint 2008-09-01 17:24---------d-----wC:\Documents and Settings\All Users\Application Data\Viewpoint 2008-09-01 06:09---------d-----wC:\Program Files\Lavasoft 2008-09-01 06:09---------d-----wC:\Documents and Settings\Julie\Application Data\Lavasoft 2008-08-22 00:08---------d-----wC:\Program Files\StumbleUpon 2005-06-17 18:40266--sh--wC:\Program Files\desktop.ini 2005-06-17 18:4011,079-c-ha-wC:\Program Files\folder.htt . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-03 1235736] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 282624] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 278528] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-07-07 169984] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Logitech Utility"="Logi_MwX.Exe" [2003-12-17 C:\WINDOWS\LOGI_MWX.EXE] C:\Documents and Settings\Julie\Start Menu\Programs\Startup\ MEMonitor.lnk - C:\Program Files\Sprint music manager\MEMonitor.exe [2008-05-07 951640] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.NTN1"= nuvision.ax [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProvidersmsapsspc.dllschannel.dlldigest.dllmsnss pc.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-03 97928] R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-03 875288] R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-03 231704] R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-01 76040] R3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 281600] R3 maestro;ESS Maestro 3 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 174464] S3 ISLP2;Intersil 802.11 Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\islp2nds.sys [2002-10-03 611840] S3 NuVision;Hauppauge WinTV USB Pro (NTSC);C:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 260144] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-03 18:53:12 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\SYSTEM32\Atievxx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe . ************************************************************************** . Completion time: 2008-09-03 18:58:08 - machine was rebooted ComboFix-quarantined-files.txt 2008-09-03 23:57:54 ComboFix2.txt 2008-09-03 13:04:32 Pre-Run: 11,735,892,480 bytes free Post-Run: 11,731,142,144 bytes free 138--- E O F ---2008-08-15 08:16:19 =========================================================================================== Username "Julie" - 09/03/2008 19:02:34 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check Successfully flushed the DNS Resolver Cache. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run] "Logitech Utility"="Logi_MwX.Exe" "AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup" "Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\AutorunsDisabled] "ISLP2STA.EXE"="ISLP2STA.EXE START" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run] "MsnMsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe\" /background" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe" .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~
Place a check mark next to the following entries: (if there) O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Next, run HijackThis, but instead of scanning, click on the Open the MISC tools section button at the bottom of the choices. Select Delete an NT Service Copy/paste noytcyr into the box that opens, and press OK If you receive any error messages just ignore them and continue. Now do the same with the following entry. Copy/paste noxtcyr into the box that opens, and press OK ---------- Download OTMoveIt2 by OldTimer
C:\WINDOWS\system32\noxtcyr.exe C:\WINDOWS\system32\noytcyr.exe EmptyTemp [start explorer]
Explorer killed successfully File/Folder C:\WINDOWS\system32\noxtcyr.exe not found. File/Folder C:\WINDOWS\system32\noytcyr.exe not found. < EmptyTemp > File delete failed. C:\DOCUME~1\Julie\LOCALS~1\Temp\~DF2D9C.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Julie\LOCALS~1\Temp\~DF2DB8.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Julie\LOCALS~1\Temp\~DFFE2F.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Julie\LOCALS~1\Temp\~DFFE4C.tmp scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09032008_193243
---------- 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Delete temporary files Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- Run the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.-------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Thursday, September 4, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, September 03, 2008 23:31:57 Records in database: 1189161 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 63393 Threat name: 6 Infected objects: 8 Suspicious objects: 12 Duration of the scan: 03:50:10 File name / Threat name / Threats count C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbxInfected: Trojan-Spy.HTML.Paylap.jg1 C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbxSuspicious: Trojan-Spy.HTML.Fraud.gen12 C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbxInfected: Trojan-Spy.HTML.Paylap.je2 C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbxInfected: Trojan-Spy.HTML.Bayfraud.jv3 C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbxInfected: Trojan-Spy.HTML.Paylap.iy1 C:\WINDOWS\SYSTEM32\udxfytw.sysInfected: Trojan-Clicker.Win32.VB.bzc1 The selected area was scanned.
Download
C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx C:\WINDOWS\SYSTEM32\udxfytw.sys EmptyTemp [start explorer]
============================== Explorer killed successfully File/Folder C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx not found. File/Folder C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx not found. File/Folder C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx not found. File/Folder C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx not found. File/Folder C:\Documents and Settings\Julie\Local Settings\Application Data\Identities\{EF8D8B41-A217-48F2-BF2E-9EC4EC7D7934}\Microsoft\Outlook Express\eBay.dbx not found. File/Folder C:\WINDOWS\SYSTEM32\udxfytw.sys not found. < EmptyTemp > Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09042008_182735 Looks good. 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible REINFECTION from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2420. |
Solve : can't connect to certain websites, am I hijacked?? |
|
Answer» You can try this first instead of reinstalling.
If you want to see what was replaced, right-click My Computer and click on Manage. In the new window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System.Thanks so much for all of your help. I did that last step and the problem remained the same. I decided to reformat and reinstall. The problem is the same. I can't GET in touch with the local end of my ISP to discuss this issue, so will be going in person to their office tomorrow to appraise them of the situation. Hopefully it is not my NIC as it is integrated on my motherboard. Just wanted to let ya'll know after all of that, it was my ISP after all. Whatever the problem on their end, it is now fixed. Thanks for letting us know.
. The above procedure will:
---------- Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed) 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 Check out Keeping Yourself Safe On The Web for tips and free tools to help KEEP you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2421. |
Solve : What is Adware.RK.331776?? |
|
Answer» I swear, I don't know how I got it. I keep deleting the thing and it keeps coming back. But every time it comes back, it comes back as 3 copies of Adware.RK.331776, with 2 being able to be deleted and 1 copy not being able to be deleted.
|
|
| 2422. |
Solve : Trojan killing my VAIO? |
|
Answer» Quote just need to transfer it to this computer Can you connect to the Internet with the PC? Go ahead and uninstall ComboFix, we are done with it. Go to Start > Run and copy/paste the below line in then press Enter to uninstall ComboFix. "%userprofile%\Desktop\combofix" /u Now press Enter. ---------- Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
Important: Restart the computer before continuing. ---------- Delete temporary files Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- How is everything now?No, it won't connect in safe mode. I can get WIRELESS sometimes here (at my MIL's to use her computer to do this) but it won't connect even hooked up.Was it like this before the malware or is it a result of it? I though that you were USING it to download this whole time.... No, I've been downloading to my flash drive and then uploading it to my computer in safe mode. I haven't been able to get internet since yesterday when this happened. I ran Kaspersky because it suddenly POPPED up saying it found a trojan and I needed to delete it. It freaked out and shut down and then started the restarting continually thing. It will only do anything at all in safe mode except for print or get internet access. But none of the other options (start normal, last normal, safe with networking, etc.) work and only continually restart. I'm sorry, I thought I typed that out but I have an infant on my lap who likes to type with me! I finished the last instructions you gave me. Seems to be the same. I will try restarting and see if any of the other options work again. Update: nope, still the same. No you probably mentioned it, I'm involved in a lot of threads here and sometimes have to be told twice lol. All of these logs can get me a little loopy at times. You are doing very good though, that's why it didn't dawn on me. Usually people have a hard time transferring some of these files.... Let's try to reset the connection.
What about now?Sorry I'm just now back. The baby needed to sleep and I was gone all morning. There is nothing in the box under Dial up and Virtual network settings. The add button is next to it, but there is nothing in the box. I have internet at home but just the wireless will work here. Lets do this. Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
Open Dial-a-fix and click the hammer icon. Select Flush DNS and click Go When complete, select Repair Permissions and click Go When complete, select Repair/reinstall IE and click Go If at any time you are prompted for the XP CD, insert it Make note of any error messages and post them here Reboot when complete and let me KNOW if there's any change. Any changes?We don't have an XP CD. We bought the VAIO (VGN SZ240) online from sony and it didn't come with anything but a brochure about buying from sony, an invoice, and the laptop and power cord. Maybe a flash adapter. I am not sure what to think at this point. Have you tried reinstalling the router or wireless card? |
|
| 2423. |
Solve : Need some advice please? |
|
Answer» thank u so much for all your help =-). this program is still in my control panel its a monitor with a magnifying glass thru the screen. when i HOVER over it it says : displays all software that is running on your computer or REGISTERED to run automatically. that program was not there 2 DAYS ago lol Can you post a SCREENSHOT of it? |
|
| 2424. |
Solve : virusburst infected-HJT and malwarebytes log? |
|
Answer» hello and thank you for helping me!
Follow this link to download and install Java Runtime Environment (JRE) 6 Update 7 ---------- Run the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the INFORMATION on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.thanks evilfantasy ! i did the first 2 steps above ,but i had some problems scanning online (such as my connection speed and many errors from kaspersky that cause restarting process..) but i have already installed kaspersky antivirus 2009 on my computer and it's updated,isn't it enough ? may i post the scan log of it here instead? Do this instead. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
i chose cure all of them and delete uncurable . BetterSP2.exe;C:\Program Files\BitSpirit;Program.Tcpip;; Process.exe;C:\Program Files\roguescanfix;Tool.Prockill;; SmitfraudFix.exe\SmitfraudFix\Process.exe;C:\Users\Administrator\Desktop\trojan\SmitfraudFix.exe;Tool.Prockill;; SmitfraudFix.exe\SmitfraudFix\restart.exe;C:\Users\Administrator\Desktop\trojan\SmitfraudFix.exe;Tool.ShutDown.11;; SmitfraudFix.exe;C:\Users\Administrator\Desktop\trojan;Archive contains infected objects;Moved.; smitRem.exe\smitRem/Process.exe;C:\Users\Administrator\Desktop\trojan\smitRem.exe;Tool.Prockill;; smitRem.exe\smitRem/pv.exe;C:\Users\Administrator\Desktop\trojan\smitRem.exe;Program.PrcView.3741;; smitRem.exe;C:\Users\Administrator\Desktop\trojan;Archive contains infected objects;Moved.; VirtumundoBeGone.exe\data005;C:\Users\Administrator\Desktop\trojan\VirtumundoBeGone.exe;Tool.Prockill;; VirtumundoBeGone.exe;C:\Users\Administrator\Desktop\trojan;Archive contains infected objects;Moved.; Process.exe;C:\Users\Administrator\Desktop\trojan\SmitfraudFix;Tool.Prockill;; restart.exe;C:\Users\Administrator\Desktop\trojan\SmitfraudFix;Tool.ShutDown.11;; Process.exe;C:\Users\Administrator\Desktop\trojan\smitRem;Tool.Prockill;; pv.exe;C:\Users\Administrator\Desktop\trojan\smitRem;Program.PrcView.3741;; fg672p.exe;R:\ShiMaH\PrOgrAm\Filter Shekan;Trojan.Proxy.3292;Deleted.; Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
Note that your system will run slower for a reboot or two after having used this tool so don't panic. Important: Restart the computer before continuing. ---------- ---------- Download OTCleanIt.exe and save it to your Desktop.
---------- Delete temporary files Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- Clear your System Restore of infected Restore points. Reset and Re-enable your System Restore to remove any infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are infected, but that's good news) Turn OFF System Restore
Restart your computer Turn ON System Restore
System Restore will now be active again ---------- How is everything now?thank you very much. but i think the problem is something else. my problem with windows explorer and my internet explorer browser still exists. i just need to undo the changes made by the viruses ,and there is no virus in my computer any more.maybe i need to reinstall the whole windows to fix it. what's your idea ?Try this. Reset Settings in Internet Explorer 7 Reset Explorer Settings IE 7 it's not working at all !! it disapears one second after starting ,so i can't do anything with it. i may try reinstaling it to fix the problem .That may be the best option at this point. I reinstall IE and it's working now . and after restarting my computer ,the windows explorer also seems to work as normal and without problem. there's no problem anymore. thanks alot evilfantasy for your help. GOOD LUCK Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security THREATS that are on the Internet. Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2425. |
Solve : Win 2000 Pro - tools for hard to find? |
|
Answer» Read your "Removing Malware "- excellent. Also your list of free SOFTWARE Open to correction here but - wasn't 2k based on the NT4 kernel Pretty SURE your right. There are a few applications that are coming out recently that won't work with Win 2000 (Google Chrome) but everything we use here should work fine.Re: "which softwares are saying this: " AVG - in the link you provided, when CLICKED on says: for "XP and Vista" The second half of my initial response was the idea that Microsoft isn't interested in servicing older editions - so they may just be leaving out the info that 2K Pro could handle it O.K. -- as well as XP and Vista.AVG may heve phased out 2000. Not sure as I stopped using it. Too much of a headache. I would suggest using Avira or Avast. MS is still supporting Win 2000 for a few more years I think. Other companies, especially free software companies will be moving away from supporting it sooner or later. It costs them extra money to maintain multiple VERSIONS. |
|
| 2426. |
Solve : Installshield Update Manager? |
|
Answer» An icon appeared on my task bar for Installshield Update Manager. I didn't download it. I want to UNINSTALL it. Is there any removal tools out there for this unwanted program?This software came bundled with your computer. |
|
| 2427. |
Solve : On-line scanners? |
|
Answer» I'm trying to run an on-line scan on my Toshiba laptop RUNNING Vista but Kaspersky is not designed for Vista 64 bit, Panda keeps giving me an error and Trend Micro has been trying to download files for over 1 hrs. Are there any others I could try?There ia a list of them here http://www.techsupportteam.org/forum/reviews/3184-trusted-security-tools-resources.html Trend Micro has been trying to download files for over 1 hrs If I'm not mistaken, Trend Micro is hijackthis program? I have Vista Windows with x64 and it downloaded and installed just fine. There may be a problem with the site? I'm not sure. Just thought I'd let you know. Thanks for the REPLIES. I was finally able to get Kaspersky to scan my laptop. Trend Micro also has an on-line scanner but it kept hanging. I also was able to get Panda to do a scan and it found 19 threats but they wanted $$ to remove them. I ran SuperAntiSpyware and it found 32 threats. This is why we NEED logs. Without them there isn't anything we can do to HELP. |
|
| 2428. |
Solve : MalwareBytes Critical bug, please read? |
|
Answer» MalwareBytes Critical bug, please read Quote It has come to our attention that a critical bug existed between Malwarebytes' Anti-Malware version 1.00 and version 1.25. If you ever removed anything using Malwarebytes' Anti-Malware during that time, please run the attached file. Your SecurityProviders value may have been corrupted. [recovering disk space -- attachment deleted by admin]Thanks for noticing and getting this posted so fast. Thanks for heads up. I've been spreading the word.Version 1.27 will repair these registry values so even if you don't run the fix as long as MBAM is updated it will be repaired.Nice catch!If a system is experiencing no problem, should the fix be run? What are the symptoms of the bad SecurityProviders values?No symptoms that I am aware of, the bug was actually discovered by someone not affiliated with MBAM. Yes it needs to be run, if the Security Providers values are faulty, it will tell you and then fix it.Can i still run it CORRECTLY if I have removed MBAM after using it? I ran it on my laptop (even tho MBAM is not longer installed), and it found no errors...It will work the same with or without MBAM installed.More information. Quote This particular bug would only affect you if your computer was part of a LAN in a configuration that required it AUTHENTICATE itself to others. It has nothing to do with antivirus, or security otherwise.thank you , just did what you said and everything was fine , keep up the good work ,harry MBAM v1.27 is now available. As long as everyone who has at one point used MBAM to fix anything updates their copy of MBAM the bug will automatically be fixed. Unsticking this topic.
|
|
| 2429. |
Solve : task manager is disabled? |
|
Answer» Your HJT log is clean. |
|
| 2430. |
Solve : Strange MSN messages? |
|
Answer» O4 - Global STARTUP: 802.11g Wireless Client Utility.lnk = ? is a dead link, so it may be safely "fixed", but it REALLY doesn't matter that much. Anyway, your HJT log is now clean. I asked, if your connection is wireless, because maybe there is something wrong with your wireless security, and someone is getting into your network. Did you by any chance play with "port forwarding"?I tried to forward the ports on my router for µtorrent LIKE half a year ago but for some reason that didn't work. I'll get rid of those, just in case.or...try to hardwire your computer straight to the modem, and see, if those messages will keep coming. But, try one solution at a time.The messages only came from one person, and they seem to have stopped. I think it was something with their computer.Must be some FORMER girlfriend, who KNEW what ports you opened, while playing with port forwarding...LOOOOL |
|
| 2431. |
Solve : all of my desk icons and start up is missing.Really need help please???...? |
|
Answer» After doing a daily check on my computer a trojan was discovered.I fixed that PROBLEM,but after restarting the computer all of my desk icons are gone as well as the windows start up.I had to go through the back door to get on the net.Can anyone please tell me how I can fix that or even maybe how to back my computer up going through the back door? I really need some help.My 17 year old son lives in Ga.while I am here in Co.and using the computer is the only way I have been able to keep in touch with him. I would really appreciate it if someone can help me. What exactly do you mean by "the back door"? a trojan was discovered.I fixed that problemHow?We quarentined the trojan.We also reinstalled desktop.The trojan got into our windows somehow and corrupted the files so now we going to take it to someone because we do not have our windows disc to fix all that. I ran a virus check on it this morning and there was no virus or trojans so I guess that is a GOOD thing. Please See Here First On top of that you have been asked some questions... The info you are not providing is only slowing this process down. I understand this is NEW to you but without knowing what you have done to this point and the PROGRAMS you have run to determine you are infected we would all just be guessing at this point... Looking forward to your replies... |
|
| 2432. |
Solve : oops...I've did it again, should have bin written about me, HELP NEEDED? |
|
Answer» Hi all, can anyone help me with a problem that i have encountered only this evening? |
|
| 2433. |
Solve : i have no idea what im doing someone help me? |
|
Answer» im about to have a breakdown. |
|
| 2434. |
Solve : Why I am getting paranoid about Cyber Security.? |
|
Answer» Here is Why I am getting paranoid about |
|
| 2435. |
Solve : New VGN-CR240E laptop.? |
|
Answer» Hi, I just received my new laptop, and can I have any recommendations on what to do before surfing the net? THANK you.Everything listed below is free. |
|
| 2436. |
Solve : Trojan removal?? |
|
Answer» Hello here are my logs. What do I do Next? Any help will be greatly appreciated!
Restart your computer Turn ON System Restore
System Restore will now be active againHi Matt. Just wanted to let you know I did what you said and I will be getting AVG OR Avast first thing tomorrow. Until then I am turning my PC off. Thank you so much. I am in SCHOOL online and my computer is my lifeline. You have been an angel. Once again thank you. Peace.You're very welcome. I'm just glad I was able to help. |
|
| 2437. |
Solve : Malwarebytes' Anti-Malware? |
|
Answer» Hey guys, hope you can help me... |
|
| 2438. |
Solve : Stolen passwords?? |
|
Answer» I've been wondering if SOMEONE has stolen some account passwords and been LOGGING into them. How would I KNOW for sure if this is happening? Are there signs to indicate that someones in your computer VIEWING personal information and stealing passwords. Could it be possible if I'm connected to an unsafe wireless NETWORK but with the firewall on that someone could be doing any of this? |
|
| 2439. |
Solve : My computer keeps randomly freezing, forcing me to reboot? |
|
Answer» I have an Acer Aspire with AMD Athlon 64 X2 Dual Core Processor 5200+ with 3GB of ram and I'm running Vista on it. I do download alot of torrents but I don't know if its a memory issue or a virus. All the SUDDEN while I'm doing something on the computer the WHOLE screen locks up and i can do anything, not even pull up task manager, it makes me turn off and on my computer. My logs are all in the attachments, please help me out. |
|
| 2440. |
Solve : Having a problem with hangups? |
|
Answer» I'm having a problem with slowness and hangups... browsers keep closing suddenly.. both firefox 3.0 and IE 7. The clock won't update either, it says the RPC server is unavailable. I'm running Zonealarm Pro for a firewall. |
|
| 2441. |
Solve : Please help! My pc is so slow? |
|
Answer» My computer has been running very slow. It sometimes takes 5 minutes for IE to open and each new window takes just as long. Other programs also seem to take forever to open and if I have several things open (Outlook and IE, for example) it may take even longer. I had thought that maybe all the junk my kids had downloaded was the problem, but they both left home recently and I removed all their files. No help.
Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the Desktop. Run CCleaner and restart the computer. ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. For Windows XP Systems install the Recovery Console: - If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes. - If for some REASON your Internet is not working click No. - If you are not using Windows XP, you will not be prompted. - When prompted to accept the EULA click OK. - Accept Microsoft's EULA (Click Yes). - When you are told that the RC is installed correctly click YES to continue scanning for malware. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.-modest- Welcome to CH. As you can see this is a virus related issue and not just regular maintenance. Please read this thread: Would you like to learn to fight malware? Again, Welcome...And after you take care of your virus issue, buy some more RAM. I do not even try to run Windows with less than 1GB. Windows is a memory hog and loves to eat it. 256MB is just a snack for Windows. You will get a lot of trashing on your system page/swap file, (slow disk I/O) which can slow your system way down. Even with 1 and 1/2 to 2GB on all my systems, I still use IOBit's Advanced SystemCare SmartRAM utility. Windows is terrible about not freeing up RAM that should be on your free memory list. It is a great freeware tuneup package for adware, registry, disk defragger, privacy, etc. I run it once a week on all my systems. The first time scan found and fixed dozens of potential issues. Just pick any download site listed in the middle column and wait for the dialog box to pop up. http://www.majorgeeks.com/download.php?det=5927 Good luck.Here are the new logs. [Saving space - attachment deleted by admin]Quote from: cwayneu on November 30, 2008, 01:14:27 AM Windows is terrible about not freeing up RAM that should be on your free memory list. a bit off-topic- but windows doesn't necessarily free memory such as that used for file buffers, file handles, GDI handles, etc- rather, it caches it- then, if that same file is opened again, then windows will re-use the same handle and buffers. If another process needs memory and all physical RAM is OCCUPIED, the file read buffers will be flushed and the handles deleted, etc.. to make room for the other processes data. This is essentially what RAM optimization programs do. A very simple ram optimization program would simply be calls to GlobalCompact() and similiar functions every minute or so, as well as a current free memory display. Another method used is to send WM_COMPACTING to every top-level window in the system, but that greatly reduces performance, and so is not used. Not to say the programs do no good at all- when in the situations mentioned, with very little total RAM- you don't want to waste it on some old file buffer. With a lot of memory- the operation takes a lot longer and the benefits are far reduced, though.
Place a check mark next to the following entries: (if there) - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Download Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
---------- How is everything now? . Thank you! To give it a test, I had Outlook, Media Player, and IE all open and things ran, no stalls, no 5 minute waits! Which of the programs that I downloaded should I keep? Thank you!Keep SUPERAntiSpyware and MBAM. Update and run a scan now and then with them. Disable the System Restore Utility to prevent re-infection from an old one 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Put a check mark next to Turn off System Restore on All Drives 4) Click the OK button. 5) You will be prompted to restart the computer. Click the Yes button. Now re-enable System Restore To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'. 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Remove the check mark next to Turn off System Restore on All Drives 4) Click the OK button. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business PRACTICES and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2442. |
Solve : YT8A.exe? |
|
Answer» If you're concerned about those files, then try uploading them to VirusTotal. Head over to the site and in the little browse box, search for one of the files and scan it. When the scan has completed, do the same for the other file. Do they come up as infected? If so, post the results here. If not, then you probably don't have to worry about it. I don't THINK those files are there anymore. I'm quite confused. Not that I could LOOK for them if they were. I went to system32, couldn't find them. I tried uploading from the directory (c:\windows\system32\japanesename.exe) but it said it wasn't found. |
|
| 2443. |
Solve : windows task manager error? is it malware at work? (with screenshot)? |
|
Answer» windows task manager is working but i cannot close it using the 'x' button, unless i hit alt-f4... here's the screenshot... |
|
| 2444. |
Solve : Network adapter sudden unistall?? |
|
Answer» I was showing a friend a move, and while playing it, the whole computer froze up. Well, you may want to consider a third-party firewall, but aside from that, I don't see anything malicious. Have you viewed this particular video before? If so, has it ever given you problems? I was using VLC media player , lol And it was random, it HAPPENS all the time, random disconnections, uninstalls of my network driver?To be honest, I'm really not sure what could be causing this issue. Perhaps it's a hardware issue; maybe something's loose or not working properly. I hate to just pass you along, but this isn't my area of expertise, so I think maybe you would have better luck making a post over at the Hardware or Software section of this forum. |
|
| 2445. |
Solve : looking for a virus scanner??? |
|
Answer» For your GUIDANCE, http://money.canoe.ca/Forbes/2008/12/18/7793761-forbes.html truenorth |
|
| 2446. |
Solve : Virus/Malware Scans? |
|
Answer» There's something fishy going on with my computer-the "shut down" BUTTON is gone from the "Start" menu and the task manager has been disabled. After doing all the steps listed in the Malware Removal Post by evilfantasy, the task manager is now available, but the "shut down" button is still missing from the "Start" menu. Attached are the logs from SUPER Antispy, Malwarebytes' Anti-Malware, and HJT. Thanks for everything, please advise if I need to do anything else!! Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
---------- Before you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or PRINT them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode. Download SDFix by AndyManchesta and save it to your desktop. When using this tool, you must use the Administrator's account or an account with Administrative rights
When your computer has started in safe mode, and you see the desktop, close all open Windows.
|
|
| 2447. |
Solve : Troj Arpoison.b? |
|
Answer» Okay, apparently I've been infected with a TROJAN called TROJ ARPOISON.B according to Trend Micro's real-time virus protection. The detection always pops up on the screen whenever I OPEN an internet browser. The incident name is C:\Windows\system32\msqpdxxcrdxrei.dll but I've searched and searched but this file is no where to be found. At least to me. |
|
| 2448. |
Solve : spyware.ispynow? |
|
Answer» Well, first of all, you should go ahead and UNINSTALL ComboFix since you don't need it anymore. Go to Start > Run and type combofix /u (note the space between combofix and /u) and click OK.
As for Norton...if I were you, I would ditch it completely. You would be much better off with AVG or Avast; they surpass Norton and they're free. As for a firewall, I would go with COMODO, ZoneAlarm, or Kerio Sunbelt. Just pick one you like, download it, disconnect from the internet, disable WINDOWS Firewall, install the new one, and restart. I ASSURE you that your security will INCREASE significantly. |
|
| 2449. |
Solve : Windows Explorer Error On Clicking On AVI? |
|
Answer» Every Time I Right-Click On A AVI File To Select What Player To Play It In, I Recieve 'Windows Explorer Has Encounted A Error'. Raptor, don't be rude. If you want to help, help. Otherwise, keep comments like that to yourself. I want to help as soon as the person in question mends their ways of typing. It's not an art, there are rules to how you have to write and if you know them but not follow them because you think it's 'original' or 'cute' I'll be the first to burst your little bubble and welcome you to the real world. Quote from: Raptor on December 21, 2008, 08:49:04 AM I want to help as soon as the person in question mends their ways of typing. It's not an art, there are rules to how you have to write and if you know them but not follow them because you think it's 'original' or 'cute' I'll be the first to burst your little bubble and welcome you to the real world. Listen, what has the "real world" got to do with typing properly? "I'll be the first to burst your little bubble" and tell you that you seriously need to drop the attitude you have. If the OP wants to type the way they do, that's up to them.Quote from: kpac on December 21, 2008, 11:58:09 AM Quote from: Raptor on December 21, 2008, 08:49:04 AMI want to help as soon as the person in question mends their ways of typing. It's not an art, there are rules to how you have to write and if you know them but not follow them because you think it's 'original' or 'cute' I'll be the first to burst your little bubble and welcome you to the real world. Or else what, son? You'll spill capital letters all over me? Just don't bother. |
|
| 2450. |
Solve : Q: McAfee & AOL Security Center? |
|
Answer» Well for the New Year I decided I'd clean up my moms computer, which I've been putting off for quite some time. There are plenty of problems that I PLAN to go through the process of like I have with my computer so many times. I just had a question first, I don't know if this is the right forum or allowed, and it is: |
|