Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2551.

Solve : resident shield pop-up and av2009 virus?

Answer»

You're very welcome. Just TRY out a few different ONES and I'm sure you'll find one that's APPROPRIATE for them.

2552.

Solve : question about quarantined files/programs?

Answer»

Quote from: evilfantasy on January 22, 2009, 06:51:24 PM


thanks. will reply tomorrow!Okay... bringing you up to date. I followed the prior steps and found disabled everything including teatimer.

only question.. i disabled AviraAntivirus, teatimer S&D, and diabled my firewall. Malewarebytes and SuperAntispy had no options to disable realtime etc.. Well SAspy did but since i have the free version it dosent allow me to enable it for realtime... So thats all i could find to disable while running ComboFix. Also my internet connection dropped during the ComboFix run and it prompted me to reconnect. I did so and it completed. Just throwing that out there.

below are my logs from ComboFix. ComboFix 09-01-21.04 - Gary Hamlett 2009-01-23 8:52:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.588 [GMT -5:00]
Running from: c:\documents and settings\Gary Hamlett\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-12-23 to 2009-01-23 )))))))))))))))))))))))))))))))
.

2009-01-22 09:01 . 2009-01-22 09:03d--------c:\program files\Trend Micro
2009-01-21 23:38 . 2009-01-21 23:38d--------c:\program files\Malwarebytes' Anti-Malware
2009-01-21 23:38 . 2009-01-21 23:38d--------c:\documents and settings\Gary Hamlett\Application Data\Malwarebytes
2009-01-21 23:38 . 2009-01-21 23:38d--------c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-21 23:38 . 2009-01-14 16:1138,496--a------c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-21 23:38 . 2009-01-14 16:1115,504--a------c:\windows\system32\drivers\mbam.sys
2009-01-21 17:51 . 2009-01-21 17:51d--------c:\program files\SUPERAntiSpyware
2009-01-21 17:51 . 2009-01-21 17:51d--------c:\documents and settings\Gary Hamlett\Application Data\SUPERAntiSpyware.com
2009-01-21 17:51 . 2009-01-21 17:51d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-21 17:50 . 2009-01-21 17:50d--------c:\program files\Common Files\Wise Installation Wizard
2009-01-21 17:30 . 2009-01-21 17:30d--------c:\program files\CCleaner
2009-01-21 16:44 . 2009-01-21 16:44d--------c:\program files\Avira
2009-01-21 16:44 . 2009-01-21 16:44d--------c:\documents and settings\All Users\Application Data\Avira
2009-01-19 13:01 . 2009-01-19 13:00410,984--a------c:\windows\system32\deploytk.dll
2009-01-18 22:49 . 2009-01-22 10:45d--------c:\documents and settings\Gary Hamlett\Application Data\HPAppData
2009-01-13 20:00 . 2009-01-13 20:00d--------c:\documents and settings\Gary Hamlett\Application Data\HP
2009-01-10 21:20 . 2009-01-10 21:20d--------c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-01-10 21:19 . 2009-01-10 21:19d--------c:\program files\Hewlett-Packard
2009-01-10 21:19 . 2009-01-10 21:19d--------c:\program files\Common Files\HP
2009-01-10 21:19 . 2009-01-10 21:19d--------c:\program files\Common Files\Hewlett-Packard
2009-01-10 21:19 . 2009-01-10 21:20d--------c:\documents and settings\All Users\Application Data\HP
2009-01-10 21:18 . 2009-01-10 21:18d--------c:\windows\yellowtail
2009-01-10 21:18 . 2009-01-10 21:18d----c---c:\windows\system32\DRVSTORE
2009-01-10 21:18 . 2007-11-06 21:041,373,528-ra------c:\windows\hpzshl01.exe
2009-01-10 21:18 . 2007-11-06 21:151,140,056-ra------c:\windows\hpzmsi01.exe
2009-01-10 21:18 . 2008-01-07 09:1010,563-ra------c:\windows\hpwscr19.dat
2009-01-10 21:17 . 2009-01-10 21:20d--------c:\program files\HP
2009-01-10 21:17 . 2008-04-13 14:4725,856--a------c:\windows\system32\drivers\usbprint.sys
2009-01-10 21:17 . 2008-04-13 14:4725,856--a------c:\windows\system32\dllcache\usbprint.sys
2009-01-10 21:14 . 2009-01-10 21:54176,379--a------c:\windows\hpwins19.dat
2009-01-10 21:14 . 2008-01-07 09:08997-ra------c:\windows\hpwmdl19.dat
2009-01-01 00:27 . 2007-10-17 15:351,299,520--a------c:\windows\system32\drivers\WMP110.sys
2009-01-01 00:27 . 2007-10-29 23:34405,583--a------c:\windows\system32\jswscsup.dll
2009-01-01 00:27 . 2003-10-13 00:3094,208--a------c:\windows\system32\GTW32N50.dll
2009-01-01 00:27 . 2007-08-28 21:4657,344--a------c:\windows\system32\jswscimd.sys
2009-01-01 00:27 . 2007-08-28 21:4657,344--a------c:\windows\system32\drivers\jswscimd.sys
2009-01-01 00:27 . 2003-09-25 08:2831,930--a------c:\windows\system32\GTNDIS3.VXD
2009-01-01 00:27 . 2007-09-21 12:0927,298--a------c:\windows\system32\jswscimdp.cat
2009-01-01 00:27 . 2007-09-21 12:0926,869--a------c:\windows\system32\jswscimd.cat
2009-01-01 00:27 . 2009-01-01 00:2721,035--a------c:\windows\system32\drivers\AegisP.sys
2009-01-01 00:27 . 2003-09-25 07:1515,872--a------c:\windows\system32\GTNDIS5.sys
2009-01-01 00:27 . 2007-08-28 21:455,529--a------c:\windows\system32\jswscimdp.inf
2009-01-01 00:27 . 2007-08-28 21:452,231--a------c:\windows\system32\jswscimd.inf
2009-01-01 00:26 . 2009-01-01 00:26d--------c:\program files\Linksys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 13:12---------d-----wc:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-21 21:32---------d-----wc:\program files\Dell
2009-01-21 21:29---------d-----wc:\documents and settings\All Users\Application Data\Viewpoint
2009-01-21 21:03---------d-----wc:\documents and settings\All Users\Application Data\McAfee.com
2009-01-21 19:41---------d-----wc:\documents and settings\All Users\Application Data\Kodak
2009-01-19 18:00---------d-----wc:\program files\Java
2009-01-19 17:30---------d-----wc:\program files\Yahoo!
2009-01-19 17:28---------d-----wc:\program files\Kodak
2009-01-19 17:25---------d-----wc:\program files\Common Files\Corel
2009-01-19 17:12---------d-----wc:\program files\AdvancedEnhancer
2009-01-01 05:26---------d--h--wc:\program files\InstallShield Installation Information
2009-01-01 04:30---------d-----wc:\program files\Common Files\Adobe
2008-12-14 08:08---------d-----wc:\program files\Spybot - Search & Destroy
2008-12-13 06:403,593,216----a-wc:\windows\system32\dllcache\mshtml.dll
2008-12-11 10:57333,952----a-wc:\windows\system32\drivers\srv.sys
2008-12-11 10:57333,952------wc:\windows\system32\dllcache\srv.sys
2008-12-01 15:244,184--sha-wc:\windows\system32\KGyGaAvL.sys
2008-10-24 11:21455,296------wc:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36286,720----a-wc:\windows\system32\gdi32.dll
2008-10-23 12:36286,720------wc:\windows\system32\dllcache\gdi32.dll
2006-11-09 20:45251----a-wc:\program files\wt3d.ini
2008-08-30 11:3388--SH--rc:\windows\system32\F35501B0EF.sys
2008-08-31 01:1632,768--sha-wc:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083020080831\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-07 4670968]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-02-01 8699904]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"NapsterShell"="c:\program files\Napster\napster.exe" [2008-05-09 323216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-06 282624]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"WMP110"="c:\program files\Linksys\WMP110\WMP110.exe" [2008-02-27 962560]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-02-01 8699904]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecuteREG_MULTI_SZ autocheck autochk *\0sprecovr \SystemRoot\sprecovr.txt

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-01-01 57344]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 WMP110;Linksys WMP110 RangePlus Wireless PCI Adapter Service;c:\windows\system32\drivers\WMP110.sys [2009-01-01 1299520]
R4 GTWPSService;GTWPSSRV;c:\program files\Linksys\WMP110\gtwpssrv.exe [2009-01-01 34816]
R4 WLSng Service;WLSng Service;c:\program files\Linksys\WMP110\WLSngS.exe [2009-01-01 233472]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Linksys\WMP110\jswpsapi.exe [2009-01-01 352338]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6e3929e-40ed-11dc-8707-001372233781}]
\Shell\AutoRun\command - e:\jdsecure\Windows\JDSecure20.exe
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.wildblue.net
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: partypoker.com\www
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Gary Hamlett\Application Data\Mozilla\Firefox\Profiles\yd6w8dcv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.wildblue.net/
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\wildblue.js - pref("network.proxy.type", 2);
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-23 08:53:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1024)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-01-23 8:56:22
ComboFix-quarantined-files.txt 2009-01-23 13:56:10

Pre-Run: 217,746,849,792 bytes free
Post-Run: 217,732,108,288 bytes free

186--- E O F ---2009-01-18 08:02:13
Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

How is the computer running now?Quote from: evilfantasy on January 23, 2009, 09:46:44 AM
Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

How is the computer running now?

okay. completed that. will see how everything is running from now on and keep you posted. thanks so far. hopefully this helpsMight as well do some cleanup steps now.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than EVER before.

    For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable.

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Quote from: evilfantasy on January 23, 2009, 03:49:14 PM
    Might as well do some cleanup steps now.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before.

      For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable.

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
      okay. i will run these in the morning. Also any particular way i should have my malwarebyte, SuperAntivirusBlock, and ANTIVIRUS should be set up. I made the changes to preferences as suggested when i downloaded them. My antivirus is enabled as my firewall is too.. just wondering. Also how often should I run them all and how often should i update them.

      just looking for the correct actions to take once i'm back to normal.. thanks for all the help.
      **edit*** i overlooked you link to keeping safe while on internet...! checking it out now!I usually switch up running either SAS or MBAM. You shouldn't need to do anything to them, just run one or the other every few weeks.

      Okay i've run the Secunia scan on my system. it keeps bringing up updates that i need. for example Adobe 4x was detected and needs updating.. while i've updated to Adobe 8x and got a check beside that one it keeps SAYING i need to update the 4x. the same thing with Macromedia flash player.. here is a cut and past of the screen below

      [attachment deleted by admin]Do this to remove all unstable older versions of Flash.

      Download the Flash Player Uninstaller and save it to your desktop.

      Run the uninstaller program and then reboot your computer to complete the uninstall.

      Download and install the latest version of Flash PlayerQuote from: evilfantasy on January 27, 2009, 11:17:09 AM
      Do this to remove all unstable older versions of Flash.

      Download the Flash Player Uninstaller and save it to your desktop.

      Run the uninstaller program and then reboot your computer to complete the uninstall.

      Download and install the latest version of Flash Player
      I uninstalled and then downloaded the new version. the adobe flash player is updated but i still get issues with Macromedia flash player. I downloaded that new patch only to see its a adobe file... i dont understand it. see attachment for what i'm looking at.

      I guess I just dont understand the Secunia web site. Its doing the same thing with Adobe Reader. It keeps bringing up that I need newer versions. Versions that i have. Should I be uninstalling before I download new versions.

      Update. I removed Adobe Reader. Scanned Secunia and that program didnt come up with errors (or come up at all). Now i'm attempting to upload Adobe Reader again.Update 2 I fixed Adobe Reader.

      I also downloaded the Macromedia flash player patch and ran it from desktop. After rescanning with Secunia it still shows up as error seen in previous attachments. I cannot figure out how to uninstall it as it does not show up on my ADD/REMOVE tabs. Thoughts. >>

      [attachment deleted by admin]That is pointing to files in your i386 folder which is you Windows Installation Files. I wouldn't worry about it.Quote from: evilfantasy on January 28, 2009, 10:27:45 AM
      That is pointing to files in your i386 folder which is you Windows Installation Files. I wouldn't worry about it.

      okay. yeah i looked in the folders after not able to find it on add/remove in the control panel. everything else seems to be okay now. had issues with my java but i removed an old version (i think) and uploaded the new version again. so far so good. thanks for all of the help.

      2553.

      Solve : Help on Trojan/Virus Removal: Logs Posted?

      Answer» HI guys,

      Need your help on this one. My pc's always COMING up with alerts of xpack trojans and a few worms besides.. So FAR, I have followed the steps on the pinned thread.
      Logs attached below. Thanks, I would appreciate any help.

      --Eve

      [ATTACHMENT deleted by admin]Help please, anyone? (much much appreciated). You MIGHT be in trouble with you PC, but please don't bump your topic.
      2554.

      Solve : would a partition defend against virus??

      Answer»

      Hello and thank you for taking interest.
      Would a PARTITION on a 500 gig drive, of say 20 gig, help against virus attacks?
      I could load programs onto the 20 gig section and if they were INFECTED then they wouldnt get into the main OS REGISTRY, would they?In a virus point of view, this doesn't matter at all.

      Windows gets infected, which infects your FILES.Closed... Thanks CARBON Dudeoxide.. I understand now.Okay.

      If you want to protect your files, have an antivirus installed on the computer.

      2555.

      Solve : evilfantasy's 3rd topic above ( would you like to learn )?

      Answer»

      how do you reply to this , there is no reply button's on the pageits lockedoh , right ok , , just wanting to know if there is a way i could help at times i'm 63 and have cleaned out 3 stalled pc's ( virus's etc ) for friend's , what would i have to do , or would it be to much to learn for my age , even in another subjectI locked it because most of the questions I expected to be asked were and have answers.

      You need to have some TIME in one of the online courses. Malware is constantly EVOLVING and only getting harder to solve. Reading a ComboFix log and knowing the script fixes as well as using GMER Rootkit are two things that anyone wanting the Malware Specialist title must know how to do. But there is also a lot more.

      Bottom line. Unless you are in or complete training it's not LIKELY.

      We do desperately need the help and I do appreciate the offer. thanks for your reply , i love messing around with and digging into pc's as with some of my posts , but it might be to much for me to take in at my age , harryYour not too old at all. Many retirees are malware specialists, and some of the very best. It's just too easy to destroy someones computer by giving the wrong advice. Like Broni!I've noticed lately some of my posts seem to be removed... I didn't do it... I definitely posted in this topic, but I don't know where it's gone! It was reply no. 3....

      I doesn't matter, really, but if it keeps happening I'll find out somehow... Are you sure you hit reply?

      Nothing of yours is in the spam forum.Yes, it definitely appeared, and the post ICON (on topic index - the blue icon) was there.

      2556.

      Solve : Weird problem - can't access antispyware sites?

      Answer»

      Hello everybody, this is my first post here. I found this forum searching for my problem....

      Yesterday I found out that I have some viruses (or spyware)....my hardisk was infected with the help of my usb pendrive that had over 16 viruses after a scan with nod32.

      So, basically I couldn't OPEN my C:\ drive. Whenever i tried that , an error came upon, saying that Windows cannot find C:\Recycler\S-7-7-78-100018602-100019476-100002195-2406.com .... if i deleted the S-x-x-xx ... file another file was created. I did a scan wiht NOD32...and found some trojans in the temp directory, and deleted them.
      I fixed the autorun thing with SDfix, so i can access my disk drives now....but the recyler still has that same file witch i can't delete.

      Another weird thing is that i can't access antispyware sites like: spybot, spyware doctor, superantispyware. I just can't connect to those sites...and i can't update.


      Here is my Hijackthis log:

      Code: [Select]Logfile of HijackThis v1.99.1
      Scan saved at 18:02:41, on 30.01.2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.20935)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Spyware Doctor\SDTrayApp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
      C:\Program Files\MagicDisc\MagicDisc.exe
      C:\Program Files\Gigabyte\ET5\GUI.exe
      C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
      C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
      C:\WINDOWS\system32\nvsvc32.exe
      c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
      C:\Program Files\CyberLink\Shared files\RichVideo.exe
      C:\Program Files\Spyware Doctor\svcntaux.exe
      C:\Program Files\Spyware Doctor\swdsvc.exe
      C:\spm\spmdib.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
      C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
      C:\WINDOWS\system32\taskmgr.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      C:\Program Files\Spyware Doctor\update.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Documents and Settings\Lucian\Desktop\hijack\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\ETcall.exe
      O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
      O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [PC Suite TRAY] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
      O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O11 - Options group: [TABS] Tabbed Browsing
      O17 - HKLM\System\CCS\Services\Tcpip\..\{6000D462-308C-4AF7-B760-4AEEFB31DF2B}: NameServer = 82.76.253.115 82.76.253.125
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
      O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown OWNER - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
      O23 - Service: MENTAL ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
      O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe



      i've tried to fix this entry:

      Code: [Select]O17 - HKLM\System\CCS\Services\Tcpip\..\{6000D462-308C-4AF7-B760-4AEEFB31DF2B}: NameServer = 82.76.253.115 82.76.253.125
      but it's coming back again...

      also my computer is working very slow.

      i've attached my nod32 log (2.txt)

      Code: [Select]29.01.2009 12:59:01 Real-time file system protection file C:\WINDOWS\TEMP\tempo-2261750.tmp a variant of Win32/Kryptik.GA trojan cleaned by DELETING - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\system32\spoolsv.exe.
      28.01.2009 21:40:33 Real-time file system protection file J:\Funny UST Scandal.avi.exe Win32/Sohanad.NBT worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE.
      28.01.2009 21:39:54 Real-time file system protection file J:\Autorun.inf Win32/Autoit.BE worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      28.01.2009 20:41:34 Real-time file system protection file C:\WINDOWS\TEMP\tempo-13260812.tmp a variant of Win32/Kryptik.GA trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\system32\spoolsv.exe.
      27.01.2009 19:54:37 Real-time file system protection file J:\Autorun.inf INF/Conficker worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      23.01.2009 01:31:34 Real-time file system protection file J:\Autorun.inf INF/Autorun.gen trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      20.12.2008 19:05:27 Real-time file system protection file I:\Autorun.inf INF/Autorun.gen trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      18.12.2008 12:07:50 Real-time file system protection file I:\Autorun.inf INF/Autorun.gen trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      17.12.2008 20:04:40 Real-time file system protection file C:\DOCUME~1\Lucian\LOCALS~1\Temp\NERO1002529\unit_app_75\Toolbar.exe Win32/Toolbar.AskSBar application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: F:\Downloads\Torrents\Nero.9.0.9.4.Ultra.Edition.WinALL.Cracked.by.TAMer\Setup\Nero-9.0.9.4.exe.
      16.12.2008 22:59:30 Real-time file system protection file I:\Autorun.inf Win32/AutoRun.IX worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      15.12.2008 11:17:17 Real-time file system protection file I:\Autorun.inf Win32/PSW.OnLineGames.NNU trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
      [attachment deleted by admin]

      2557.

      Solve : Malware. Don't worry, just some kids doing pranks.?

      Answer»

      In the news someone from India lost his job at Fannie Mae.
      For, so they say, putting 'mallware' in a server. Interesting topic. Microsoft programmers used to put a whole host of undocumented features (eater eggs) in microsoft producets (cheats for games, games in office apps, etc.) but since they're undocumented/unregistered Microsoft has no way of knowing that they really are what they say they are. So now they have a 'safe programming' ethic, which says nothing undocumented has been put in their programs. Abit of a shame because the features were funny but it was a necessary step by Microsoft. I'm not entirely sure this story relates directly to your post as your story is two lines long.

      FBQuote

      I'm not entirely sure this story relates directly to your post as your story is two lines long.
      Yes, it is relevant. Even if you read the full story the two lines WOULD be what you come away with. The information you gave has more detail that what the media would report.
      The point I am looking for is whether on not the public perception of 'malware' is an organizational, institutional problem or just coming from individuals who are are inmature or DERANGED mentally.
      Many, myself included, believe that a company who indulges and allows malicious software and later makes denials is big part of the problem.

      I chose "No, the threat is very big" and "Just don't be an idiot".

      Because....
      Yes, the threat of malware is becoming bigger and bigger EVERY year, and yes, the people creating it are getting younger. But, whatever way you look at it, malware is ALSO evolving rapidly, and is able to do uncompromised things to the operating system.

      And "Just don't be an idiot" is a major issue. It is common sense to never download and/or install anything you don't 100% TRUST. It is also common sense to scan everything before "double-clicking" on. It is the same as chatting to people you don't know - it's a stupid thing to do.
      2558.

      Solve : download againest new virus?

      Answer»

      can you give me the download which is sweeping the world or were to find it please , i do not have it yetUmmm....What do you want? Sweeping the world? You mean like this:

      FBHah, nice.And why would you want to download a virus?It's easy! Disable all FIREWALLS and antivirus/malware programs, then search google for serials. surefire way.
      P.S: don't actually do this.sorry i typed it wrong , never MIND this is the virus i was LOOKING the fix for


      Computer Worm Goes Out Of Control


      Sky News
      Print Story
      A computer virus attacking Microsoft Windows has infected almost nine million machines and is spreading faster than ever before. Skip related content
      Related photos / videos Computer Worm Goes Out Of Control Experts say the worm has "skyrocketed" in recent days.

      It is sweeping through thousands of offices in the UK and has affected computers at the Ministry of Defence.

      The virus - known variously as Conficker, Kido or Downadup - burrows deep into the operating system and tricks the machine into running the infected program.

      Once the worm is running on the computer it automatically starts to download more malicious programs from hackers' websites, with devastating effects.

      The majority of computers infected by the worm, which was first identified in OCTOBER, are in RUSSIA, China, Brazil and India. But the virus is now taking hold in the UK.

      The worm has password cracking capabilities, often successful because company passwords sometimes match a predefined password list that it carries.

      Eddy Willems, a security analyst with anti-virus firm Kaspersky Labs, said that a new strain of the worm was now causing additional problems.


      2559.

      Solve : Computer beeps until completely unplugged?

      Answer»

      When ever I turn my computer on it starts to beep and you cant stop it. Its like a siren no windows screen COME up its just blank.

      Im using Windows Xp

      UMM i have

      3 Gigs Ram
      QuadCore Proccessor
      and a NVidia 8800 GT graphics I cant find the papers it came with Ive TRIED everything.Undocumented VIDEO Cards are
      returned to their country of origin.
      Its the Law!

      2560.

      Solve : Antivirus help needed?

      Answer»

      I need some advice for a good FREE antivirus software PROGRAM. I believe I have installed a "bad" copy of AVG Anti-Virus Free Edition 8.0 that now requires me to manually update on a daily BASIS, since I get the constant message "You may not be PROTECTED!" The older 7.5 version ran automatically. Since I need to change to another antivirus program, I would like some help in choosing a RELIABLE one. What works for you? I use Windows XP Pro and also Windows Vista on my computers.
      Thank you.

      jandal Try having a look at Avira and Avast.

      http://www.free-av.com/
      http://www.avast.com/eng/download-avast-home.html

      Remember to uninstall AVG first. hrmmm ... that is odd
      I upgraded to avg 8 on 3 xp pro's and a vista computer. Does just as good as 7.5 did, if not better... if you had it before and liked it.. maybe just uninstall and reinstall a fresh copy. You should be able to get a good copy here, or should I say this is where I downloaded mine from.

      http://free.avg.com/

      but as suggested by Carbon Dudeoxide I have heard good things about the avast he mentions too!
      I'm not too sure, but I think there are some problems with AVG 8.0 on some machines.What an awful experience it was trying to download and install a good copy of AVG 8.0!! I finally decided on Avira because it has a more user-friendly interface than avast! and it is working just great. Thanks for making the time to give your advice, Carbon. It is much appreciated.

      jandal



      Quote from: Carbon Dudeoxide on January 26, 2009, 09:44:40 PM

      Try having a look at Avira and Avast.

      http://www.free-av.com/
      http://www.avast.com/eng/download-avast-home.html

      Remember to uninstall AVG first.
      Okay, no problem. Safe computing.
      2561.

      Solve : computer running really really slow```?

      Answer»

      I am using a windows compaq COMPUTER with SP3. Heres the scoop, I got a virus on 1-19, have taken alot of stuff out & added a lot of new stuff trying to get rid of virus. The virus is cinmeng, located in Windows/sony/pctools. I had Norton, it told me I had a vrus & it couldn't get rid of it., so I deleted norton & in F-seure through my ISP. F-secure dosen't detect the virus; however,I know it is still there because Norten told me where it was when they found it, but couldn't remove it and now my computer is running really, really slow. computer won't let me do system recovery, I have done sys retsore so many times I lost count. Am really going crazy now, any advice?? Here are all my logs, I have read many of the other peoples problems on here & think you guys/girls are great at what you do.

      I am using windows XP compaq computer. Heres the scoop, I got a virus on 1-19, have taken alot of stuff out & added a lot of new stuff trying to get rid of virus. The virus is cinmeng, located in Windows/sony/pctools. I had Norton, it told me I had a vrus & it couldn't get rid of it., so I deleted norton & in F-seure through my ISP. F-secure can't get rid of the virus either, but now my computer is running really really slow. computer won't let me do system recovery, I have done sys retsore so many times I lost count. Am really going crazy now, any advice??


      Thanks for reading

      SUPERAntiSpyware Scan Log
      HTTP://www.superantispyware.com

      Generated 02/03/2009 at 04:54 PM

      Application Version : 4.25.1012

      Core Rules Database Version : 3724
      Trace Rules Database Version: 1709

      Scan type : Complete Scan
      Total Scan Time : 06:45:09

      Memory items scanned : 456
      Memory threats detected : 0
      Registry items scanned : 4822
      Registry threats detected : 0
      File items scanned : 74190
      File threats detected : 124

      Adware.Tracking Cookie
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Compaq_Owner\Cookies\[emailprotected][1].txt




      Malware scan:

      Malwarebytes' Anti-Malware 1.33
      Database version: 1722
      Windows 5.1.2600 Service Pack 3

      2/3/2009 6:24:52 PM
      mbam-log-2009-02-03 (18-24-52).txt

      Scan type: Quick Scan
      Objects scanned: 58145
      Time elapsed: 29 minute(s), 42 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 2
      Registry Values Infected: 1
      Registry Data Items Infected: 0
      Folders Infected: 44
      Files Infected: 233

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CURRENT_USER\SOFTWARE\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\adwarealert\ (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      C:\Program Files\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Program Files\zzToolBar (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert (Rogue.AdwareAlert) -> Delete on reboot.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine (Rogue.AdwareAlert) -> Delete on reboot.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59 (Rogue.AdwareAlert) -> Delete on reboot.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59 (Rogue.AdwareAlert) -> Files: 415 -> Delete on reboot.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\102.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\110.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\114.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\123.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\140.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\144.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\158.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\165.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\166.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\172.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\175.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\176.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\184.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\185.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\192.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\195.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\196.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\202.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\205.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\206.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\209.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\42.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\43.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\83.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\25-01-2009-10-49-59\87.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Settings (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner\Application Data\FunWebProducts (Adware.MyWay) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner\Application Data\FunWebProducts\Data (Adware.MyWay) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner\Application Data\FunWebProducts\Data\Compaq_Owner (Adware.MyWay) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\ErrorKiller\Log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\ErrorKiller\Registry Backups (Rogue.ErrorKiller) -> Quarantined and deleted successfully.

      (more of Malware scan):

      Files Infected:
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\94Q9VW3G\xunleiBHO12[1].dll (Adware.BHO) -> Quarantined and deleted successfully.
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UDQRST6P\xunleiBHO12[1].dll (Adware.BHO) -> Quarantined and deleted successfully.
      C:\Program Files\zzToolBar\IP.dat (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\Program Files\zzToolBar\SearchEngineConfig (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\Program Files\zzToolBar\uISGRLFile.dat (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\fp.dat (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Log\2009 Jan 30 - 03_00_02 AM_250.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Log\2009 Jan 30 - 03_00_03 AM_265.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\10.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\10.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\11.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\11.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\12.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\12.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\13.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\13.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\14.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\14.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\15.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\15.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\16.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\16.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\17.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\17.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\18.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\18.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\19.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\19.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\20.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\20.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\4.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\4.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\5.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\5.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\6.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\6.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\7.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\7.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\8.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\8.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\9.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\26-01-2009-07-48-54\9.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      CC:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\10.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\10.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\11.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\11.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\12.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\12.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\13.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\13.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\14.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\14.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\15.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\15.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\16.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\16.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\17.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\17.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\18.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\18.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\19.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\19.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\20.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\20.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\21.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\21.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\4.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\4.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\5.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\5.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\6.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\6.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\7.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\7.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\8.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\8.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\9.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\27-01-2009-07-25-23\9.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\10.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\10.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\11.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\11.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\12.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\12.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\13.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\13.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\14.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\14.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\15.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\15.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\16.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\16.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\17.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\17.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\18.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\18.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\4.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\4.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\5.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\5.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\6.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\6.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\7.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\7.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\8.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\8.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\9.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\28-01-2009-07-10-30\9.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\10.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\10.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\11.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\11.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\12.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\12.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\13.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\13.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\14.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\14.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\15.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\15.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\16.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\16.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\17.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\17.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\18.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\18.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\19.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\19.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\4.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\4.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\5.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\5.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\6.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\6.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\7.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\7.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\8.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\8.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\9.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\29-01-2009-06-28-42\9.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\10.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\10.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\11.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\11.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\12.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\12.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\13.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\13.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\14.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\14.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\15.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\15.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\16.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\16.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\17.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\17.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\18.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\18.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\19.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\19.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\20.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\20.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\21.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\21.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\22.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\22.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\23.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\23.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\24.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\24.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\25.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\25.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\26.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\26.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\4.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\4.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\5.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\5.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\6.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\6.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\7.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\7.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\8.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\8.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\9.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\AdwareAlert\Quarantine\30-01-2009-08-05-44\9.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\ErrorKiller\Log\2009 Jan 27 - 10_32_38 AM_812.log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Application Data\ErrorKiller\Registry Backups\2009-01-26_07-47-44.reg (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
      C:\bot.txt (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\SysFile.brk (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\AdwareAlert SCHEDULED Scan.job (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner.KATHY\Favorites\Ò»ÆðÀ´ÒôÀÖÉçÇø.url (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\test.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
      Finally, the HiJack Ma log:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 7:34:56 PM, on 2/3/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\ZoomTown Internet Security\Anti-Virus\fsgk32st.exe
      C:\Program Files\ZoomTown Internet Security\Common\FSMA32.EXE
      C:\Program Files\ZoomTown Internet Security\Anti-Virus\FSGK32.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\ZoomTown Internet Security\Common\FSMB32.EXE
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\System32\snmp.exe
      C:\Program Files\ZoomTown Internet Security\Common\FCH32.EXE
      C:\Program Files\ZoomTown Internet Security\Common\FAMEH32.EXE
      C:\Program Files\ZoomTown Internet Security\Anti-Virus\fsqh.exe
      C:\Program Files\ZoomTown Internet Security\FSAUA\program\fsaua.exe
      C:\Program Files\ZoomTown Internet Security\FWES\Program\fsdfwd.exe
      C:\Program Files\ZoomTown Internet Security\Anti-Virus\fssm32.exe
      C:\Program Files\ZoomTown Internet Security\FSAUA\program\fsus.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\HP\KBD\KBD.EXE
      C:\WINDOWS\system32\VTTimer.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\ZoomTown Internet Security\Common\FSM32.EXE
      C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
      C:\Program Files\ZoomTown Internet Security\FSGUI\fsguidll.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\sniper.exe\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\ZoomTown Internet Security\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\ZoomTown Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
      O8 - Extra context menu item: Add To Compaq ORGANIZE... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1232666774014&h=4b539f1bb5fa01705e12895c78241647/&filename=jinstall-6u11-windows-i586-jc.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\ZoomTown Internet Security\Anti-Virus\fsgk32st.exe
      O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\ZoomTown Internet Security\FSAUA\program\fsaua.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\ZoomTown Internet Security\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\ZoomTown Internet Security\Common\FSMA32.EXE
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

      --
      End of file - 7779 bytes

      2562.

      Solve : i was sent here?

      Answer»

      Thank you.

      Try Dial-a-fix.

      Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

      • Open the folder and run Dial-a-fix.exe
      • 2 windows will open. Close the one in the background labeled Restrictive Policies
      • Check the box in section 1, Empty temp folders.
      • Check the box in section 2, Fix Windows Installer.
      • Check the box in section 3, Fix Windows Update.
      • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
      • Check all boxes in section 5, labeled REGISTRATION Center.
      • Click Go
      • OK any error messages if received, but write them down and post them here.
      • Restart the computer when done.
      How is it running now?i WENT the combofix im running this program now ill post the results once finished.
      system is still a bit sluggish especially the internet but i havnt run dial-a-fix yet so hopefully it solves it ill be posting soonAlright i ran Dial-a-Fix, no errors at all, and IVE rebooted my computer im still getting huge LAG on browser only now, the pc seems to have sped up quite a bit. Thanks so much for all your helpUse the ESET Online Antivirus Scanner

      This scanner requires Internet Explorer

      1. Check the box next to YES, I accept the Terms of Use.
      2. Click Start
      3. When asked, allow the activex control to install
      4. Click Start
      5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
      6. Click Scan
      7. Wait for the scan to finish
      8. Use NOTEPAD to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.
      2563.

      Solve : Browser hijack?

      Answer»

      Hello!

      I have a question concerning my hijackthis logfile.

      Recently, google behaves weirdly by opening pages that I did not request (sometimes ads and crap), so there seems to be something going on, although my Antivir and Adware and CCleaner did not complain.

      I did find a little_helper2.exe a few DAYS ago, which I deleted.

      The log file is:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:57:36, on 01.02.2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet EXPLORER v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Programme\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Programme\iTunes\iTunesHelper.exe
      C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Programme\Logitech\SetPoint\KEM.exe
      C:\Programme\Logitech\SetPoint\KHALMNPR.EXE
      C:\Programme\OpenOffice.org 2.0\program\soffice.exe
      C:\Programme\OpenOffice.org 2.0\program\soffice.BIN
      C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Programme\XAMMP\xampp\apache\bin\apache.exe
      C:\Programme\Gemeinsame Dateien\Apple\Mobile DEVICE Support\bin\AppleMobileDeviceService.exe
      C:\Programme\Bonjour\mDNSResponder.exe
      C:\Programme\XAMMP\xampp\apache\bin\apache.exe
      C:\Programme\XAMMP\xampp\mysql\bin\mysqld-nt.exe
      C:\Programme\iPod\bin\iPodService.exe
      C:\Programme\iTunes\iTunes.exe
      C:\Programme\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\cmd.exe
      C:\Programme\Opera\Opera.exe
      C:\Programme\Trend Micro\HijackThis\HijackThis.exe

      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKCU\..\Run: [WinRoll] -
      O4 - HKCU\..\Run: [RK Launcher] -
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OpenOffice.org 2.0.lnk = C:\Programme\OpenOffice.org 2.0\program\quickstart.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\KEM.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
      O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227052222306
      O17 - HKLM\System\CCS\Services\Tcpip\..\{4A52E1FD-8AC9-420D-8650-D4FB28DFBE04}: NameServer = 10.80.0.2
      O17 - HKLM\System\CCS\Services\Tcpip\..\{AD150D3E-3041-4C66-9764-BBABFC851C0C}: NameServer = 85.255.114.51,85.255.112.8
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.51,85.255.112.8
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.51,85.255.112.8
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programme\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Programme\Adobe\Adobe Version Cue\service\VersionCue.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apache2 - Apache Software Foundation - C:\Programme\XAMMP\xampp\apache\bin\apache.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe
      O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
      O23 - Service: MATLAB Server (matlabserver) - Unknown owner - G:\Matlab\webserver\bin\win32\matlabserver.exe
      O23 - Service: mysql - Unknown owner - C:\Programme\XAMMP\xampp\mysql\bin\mysqld-nt.exe
      O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Programme\XAMMP\xampp\service.exe

      --
      End of file - 6123 bytes

      I marked something in RED which I thought might be suspicious, so PLEASE let me know what you think.
      I have XAMPP running (manages an Apache client and a mysql process), so maybe the red lines have sth. to do with that or are they malicious?

      Thanks for your help!
      yeah i am getting the exact same thing. Whenever I click on a link on google or yahoo a new tab pops up and instead of being the page i clicked on its an ad or something. This is very frustrating.

      2564.

      Solve : im sure i have some type of malware, i have logs posted HELP PLZ?!?

      Answer»

      I definately have malware of sorts, i have attatched logs pleasse PLEASE PLEASE HELP ME!
      IM a beginner so i need a LOT of HELP it would be TRULY APPRECIATED....

      [attachment deleted by admin]

      2565.

      Solve : Systems Check?

      Answer»

      So I'm new here and I ended up downloading a virus...

      It was disguised as a flash update that i downloaded on the 28th.

      I followed the main directions and have all the logs..

      I was wondering IF anyone can run through and make sure everything is clear...

      Malwarebytes' Anti-Malware 1.33
      Database version: 1705
      Windows 6.0.6001 Service Pack 1

      1/30/2009 3:43:41 PM
      mbam-log-2009-01-30 (15-43-41).txt

      Scan type: Quick Scan
      Objects scanned: 57732
      Time elapsed: 18 minute(s), 24 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


      http://www.superantispyware.com

      Generated 01/30/2009 at 04:30 PM

      Application Version : 4.25.1012

      Core Rules Database Version : 3734
      Trace Rules Database Version: 1703

      Scan type : Complete Scan
      Total Scan Time : 04:20:43

      Memory items scanned : 859
      Memory threats detected : 0
      Registry items scanned : 8713
      Registry threats detected : 2
      File items scanned : 381324
      File threats detected : 0

      Adware.MyWebSearch/FunWebProducts
      HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
      HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs



      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 5:18:29 PM, on 1/30/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\SYSTEM32\WISPTIS.EXE
      C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\hp\support\hpsysdrv.exe
      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
      C:\WINDOWS\RtHDVCpl.exe
      C:\Windows\system32\schtasks.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\AVG\AVG8\avgtray.exe
      C:\WINDOWS\System32\hkcmd.exe
      C:\WINDOWS\System32\igfxpers.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Windows\system32\jusched.exe
      C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\vVX3000.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\AIM6\aim6.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Users\Zeshen\Program Files\DNA\btdna.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Hamachi\hamachi.exe
      C:\Windows\system32\WTablet\Wacom_TabletUser.exe
      C:\Program Files\MagicDisc\MagicDisc.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Skype\Plugin MANAGER\skypePM.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\AIM6\aolsoftware.exe
      C:\hp\kbd\kbd.exe
      C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
      O2 - BHO: Adobe PDF Reader LINK Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
      O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
      O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [HP Health CHECK Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
      O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
      O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
      O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [lifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
      O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Zeshen\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
      O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
      O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java CONSOLE - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
      O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
      O23 - Service: Apple MOBILE Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

      --
      End of file - 13586 bytes



      The order is Mbam, SAS, then HJT..

      Is My system Ok?I just need someone to check this please...

      I haven't had a problem since following the directions laid out...

      tho i had a weird thing when i got kicked off AIM and a IRC chat at the same time but nothing bad...

      is the system ok?

      2566.

      Solve : Some websites The Page Cannot be Displayed (I gotta HiJackThis Log!)?

      Answer»

      I saw a similar thread to my problem on ANOTHER website http://www.daniweb.com/forums/thread11183.html

      I just rebooted my computer, because it was doing the same THINGS, still it struggles opening sites like YouTube, FACEBOOK, Microsoft Updates, etc.

      Since I just rebooted it I don't have Java installed, I only have my drivers installed, HiJackThis, and Norton but it's not activated, so I'll think I'll remove it.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:44:58 PM, on 1/30/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
      C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
      C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
      O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Forceware Web INTERFACE (ForcewareWebInterface) - Apache Software Foundation - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
      O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

      --
      End of file - 5665 bytes

      Please Help

      2567.

      Solve : Help with virus? or not?

      Answer»

      I have a LAPTOP that runs GOOD for about 5 MINUTES and shuts itself down Any ideasAre you able to restart the Latop After the it shuts down? YES I can boot it back up. Then 3-5 minutes it just shuts down

      2568.

      Solve : computer shutsdown constantly/ virus suspected?

      Answer»

      my computer constantly shutsdown to power safe mode. like 5 to 6 times in an hour. not sure if there is a virus or what. sometimes screen turns watery, like water was thrown on a painting and paint is slowly running down the paper everthing looks like it from start menu to screen. also windows has a icon on the menu bar that states I have no antivirus but I have mcafee, which i will upgrade to something else some day because it sucks. but free only gets u so much right. sorry can't remember if I should do the get started virus removal guide or just wait for advice from u guys. hope u can help like before .A million thanx.

      [attachment deleted by admin]Go ahead and start the guide and post the logs.could any of these programs be bad? none on malware site though. thanks again for help. sorry response took so long. will continue with guide and post logs later.

      [attachment deleted by admin]con'd list of my programs

      [attachment deleted by admin]Not at first glance. Then again, malware doesn't hide in Add and Remove Programs.can't save stuff to the desktop anymore, got to step 5 with java, it said that old VERSIONS were removed but they are still listed in the programs and features. decided to post progress and logs and wait for answer to continue. scan took about 6 hours, so many files, not sure what files are really but we just use the computer for pics on desktop not many, watch movies and shows online and chat wit friends on myspace and email. why do I have so many files. and can i get rid of some. read somewhere that i should say when problems started, that was when i visited a site to watch movies online, watch-movies .net and surfthechannel.com. recognized by mcafee siteadvisor green so hope thats not the culprit.

      [attachment deleted by admin]just need to know if I should continu. still no way to save stuff to desktop tried to save somthin again, no go. waitn 4 the go ahead from u guys.Ok SEEMS that u guys are really busy Just hope you can get bac 2 me after today. after my last post I realized it was just better to uninstall the old versions of java, hope that was the right move. computer is really shutting down alot. white x in red shield gone, that says no antivirus is installed, after I uninstalled mcafee and installed avg free edition , my expiration was approaching anyway. wasnt to crazy about it since i got viruses even with it.really hope this one is better until I can afford to upgrade this one or ANOTHER. computer shutsdown and comes bac with quick blue screen saying windows shut down unexpectedly, etc. Then window says I have to do system restore and start up repair, cause windows could not startup, this has happend a lot. well I truly hope u guys can help. EVILFANTASY U REALLY GOT ME THRU :)last time, hope u can assist also. so much thankx i have for this forum cause I cant afford to get help from the geeks that COME to ur house. pray some one can help me with my problem. PLEASE HELP. It took me forever to get my family a computer and I hope to have it a long time with u guys help. heres other log u guys requested ok here is the log, computer freezing alot too had to come bac to post this log. Is there a site advisor for AVG like mcafee THAT WILL SHOW CHEC MARK, RED X OR WATEVER SO MY KIDS KNOW WHAT SITES ARE GREEN AND OK TO VISIT.

      [attachment deleted by admin]Uh Oh.

      <snip>

      Please don't post this type of instructions. EFIts been over a week now is there any one there to help. im totally freeking out. my computer takes almost 3 to 5 mins to get to the login screen , i think thats its name. and even longer for the internet windows page to load. when i type a page it goes to some totally different . my icons from the start up ment are gone but came BACK when I tried to shutdown. and now I truly scared I just want my computer to work correctly still shuttin down a lot crazy. and now so scary avg throw me this alert which freaked me out even more went to the place where they said the threat is i think and posted a screen shot of both / please evilfantasy or anyone there to help a girl scared out of her mind. took me forever to afford this computer, trying to take care of it the best way i can, please help PLEASE.

      [attachment deleted by admin]here is another what is going on this is so scary.

      ok computer shutdown to safe mode once more and blue screen says unexpected shutdown some other words but could not read it fast enough so i tried to restart, windows said it has to do a startup repair which took over 5mins and was not able to repair itself and info was sent to microsoft. said I should contact a system administrator or computer manufaturer 4 assistince. but im hoping u guys could assist instead because I fear my computer needs some serious help.

      [attachment deleted by admin]

      2569.

      Solve : Unable to login after trojan removal?

      Answer»

      I'm using a 2003 Dell laptop running WINDOWS XP.
      Lately I have had no new file downloads or other exposures, but it was taking longer to boot up than usual, and sometimes the screen would go black during startup; if I restarted by pushing the power button, it would start normally.
      Last night my Symantec scan found 5 viruses; it quaranted 4 of them but could not quarantine the last, Trojan.Vundo. I got a trojan vundo removal tool from the symantec website, downloaded it successfully, and had it scan my COMP, but it said it couldn't find trojan vundo, on 2 occasions.
      Today when i turned on my computer it didn't show my desktop, only the background picture. I figured out how to get into my files, and rescanned with my normal Symantec scan system. It again found the trojan.vundo, although the specific tool couldn't find it. I started getting lots of popups from internet explorer. I google'd trojan vundo and found a tool on PCtools.com, however after using this I realized it only scanned but didn't remove. I then found another tool that would actually remove it on download3k.com. This downloaded fine, scanned my computer, found several sketching-sounding files (khalicn.exe etc.) which it deleted, and found 2 trojan worms, which it said it deleted. It also told me that I had several restrictive settings, like ones preventing me from making changes ot or accessing my desktop icons; it said it could turn these off and I said OKAY. This included deleting what MAY have been a windows desktop startup file, but I don't know the name for sure. It finished scanning, and then restarted my computer.
      Upon restarting, I get to the welcome screen, CLICK on my name, and it says "loading your settings." My usual background flashes on the screen, then it immediately returns to the welcome screen with my name and little picture square, saying "Saving your settings" and 'logging off."
      It doesn't let me actually get on to my computer, my desk top, or to any of my files. I don't know if this is still a virus, or a file missing that was deleted in the cleanup process. I thought the download3k tool looked legit but what do I know.
      Do I have to lose my harddrive and re-install Windows? or pay Dell $130 to save it?
      If there was a windows desktop startup file that was deleted, is there any way other than reinstalling everything to get it?
      Thanks for any ideas or suggestions!
      C

      2570.

      Solve : Some kind of weasle blocking me from any malware program?

      Answer»

      I can install and scan but not repair. Have TRIED spybot, adware, hyjackthis, spysweeper etc. Even tried the adware in safe mode to no avail.
      Some items are reported as dangerous or severe. Common items to these programs were istbar and winfixer. Don't even know if I can believe them.

      Would really appreciate some feedback before my hair goes completely WHITE and my eyeballs are popped out to my knees. I'll try anything, especially if the end result is that F12 anyway.try getting them on a jump DRIVE off a frends pcI must not have LISTENED to the door mouse. I did not read ahead.

      But I corrected that I think. Thank you in advance for any assistance here.

      I have ATTACHED the SAS log to this post

      [attachment deleted by admin]Here are the other log attachments.
      The Malware then the hyjack this log.

      Thank you again in advance, Lil

      [attachment deleted by admin]

      2571.

      Solve : 3 laptops losing internet connections, multiple access points?

      Answer»

      3 out of the 4 laptops at my home suffer a very particular problem:

      Wireless connections drop, and die. I will be connected to my home wireless network (with WEP protection) and websites won't come up, connections to online games are severed, and this happens before the wireless symbol changes from it's normal blue circle to the red X, or sometimes first to the yellow triangle before going to the red X. Occasionally websites will come back up on refreshes before the signal symbol ever changes. Sometimes I will get a reconnect without doing anything. Sometimes I can reconnect manually. Sometimes I try to reconnect manually and I just get a generate "Windows cannot connect" message. Sometimes (and this is most disturbing) no wireless networks even show up, Windows can't find any. Turning off my wireless adapter and turning it back on will NOT help, the only fix is to restart the computer. The problem is very intermittent - I can go for hours without seeing a problem, I might have one disconnect and then nothing else for a while, or it can disconnect and reconnect 5-10 times in the span of an hour.

      I have verified this with three networks - my home network, my school's network (unsecured, but requires a user name and password), and a completely unsecured coffee shop network.

      Here are the three computers and their stories

      #1 - Asus R1F convertible laptop with Windows Vista Premium (purchased in summer 2007). The problem started about 2 weeks ago.

      #2 - MSI Wind netbook with Windows Vista Home (purchased Christmas 2008). Has never come into contact with the Asus (E.g., via USB or ethernet cable) except over the network. Problem started shortly after Asus started.

      #3 - Gateway C-143XL with Windows Vista Ultimate (purchased a week ago). Because my Asus was having many mechanical functions, this was meant to replace the Asus. I used an easy transfer cable to move everything to this computer, but before I did that, being aware of the internet problems, I installed a paid anti-virus (AVG). Immediately after TRANSFERRING files, I started to have the same internet problems.

      I thought it might be router problems (Linksys WRT54GL), except for (a) it's happening elsewhere now, and (b) the whole "can't find any networks" problem

      The only major thing I can think of in common between the MSI Wind & the Asus/Gateway is that both installed ZUNE software right at that time, and Zune was installed on the Asus first, the Wind a few days later (two different Zune players have been used as well). I seem to recall a period when I was D'Ling tons of music from Zune that I kept constantly having the internet problems as well.

      Ok on to following the steps under "Read this before REQUESTING malware removal help"

      Step A - I had AVG installed since I first started running this computer
      Step 1 - I had already done an add/remove program check. I recognize everything
      Step 2 - House cleaning ran fine
      Step 3 - WARNING - SuperAntiSpyware would not complete a scan. It looked like it got caught in an infinite feedback loop of some kind for over an hour, it looked like it was in Firefox, I could see it flash by, and it would "rest" for about 3/4 of a second on a file called xul.dll (or maybe xull.dll) before starting over. Occasionally it would break the loop and I would notice a file path that looked like:

      C:\Documents and Settings\Users\Application Data\Application Data\Application Data\Application Data (etc.)

      I canceled it and started it over, but had the same problem. For some reason it made a log for the second try, but not the first. I include it below

      Step 4 - Nothing was found with Mbam
      Step 5 - I had to upgrade from 6-7 to 6-10, I think, and re-ran CCleaner
      Step 6 - I did the HijackThis stuff as described.

      Please help!

      LOGS:

      SuperAntiSpyware:

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 01/26/2009 at 02:35 PM

      Application Version : 4.25.1012

      Core Rules Database Version : 3729
      Trace Rules Database Version: 1699

      Scan type : Complete Scan
      Total Scan Time : 00:11:09

      Memory items scanned : 673
      Memory threats detected : 0
      Registry items scanned : 6136
      Registry threats detected : 0
      File items scanned : 32675
      File threats detected : 0

      MBAM:

      Malwarebytes' Anti-Malware 1.33
      Database version: 1696
      Windows 6.0.6001 Service Pack 1

      1/26/2009 2:42:29 PM
      mbam-log-2009-01-26 (14-42-29).txt

      Scan type: Quick Scan
      Objects scanned: 44352
      Time elapsed: 1 minute(s), 54 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)

      HJT:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 3:06:23 PM, on 1/26/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\SYSTEM32\WISPTIS.EXE
      C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\AVG\AVG8\avgtray.exe
      C:\Program Files\Protector Suite QL\psqltray.exe
      C:\Program Files\Zune\ZuneLauncher.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\BigFix\bigfix.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
      C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=PTB&M=C-143XL
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=PTB&M=C-143XL
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
      O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
      O4 - Global Startup: Bluetooth.lnk = ?
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O13 - Gopher Prefix:
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

      --
      End of file - 6627 bytes

      JAVARA:

      JavaRa 1.12 Removal Log.

      Report follows after line.

      ------------------------------------

      The JavaRa removal process was started on Mon Jan 26 14:53:08 2009

      Found and removed: C:\Program Files\Java\jre1.6.0

      Found and removed: C:\Program Files\Java\jre1.6.0_01

      Found and removed: C:\Program Files\Java\jre1.6.0_02

      Found and removed: C:\Program Files\Java\jre1.6.0_04

      Found and removed: C:\Program Files\Java\jre1.6.0_05

      Found and removed: C:\Program Files\Java\jre1.6.0_07

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}

      Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

      Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

      Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

      Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

      Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

      Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

      Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}

      Found and removed: Software\Classes\JavaPlugin.160_05

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

      Found and removed: Software\JavaSoft\Java2D\1.6.0_05

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\

      ------------------------------------

      Finished reporting.



      JavaRa 1.12 Removal Log.

      Report follows after line.

      ------------------------------------

      The JavaRa removal process was started on Mon Jan 26 14:53:16 2009

      ------------------------------------

      Finished reporting.

      Thank you!I don't see anything to indicate a malware problem.

      Do you think your router or a reciever could be going bad?I would have thought the router was the problem until I ran into problems at school, especially.

      The big thing that worries me is that when the disconnects happen, I am sometimes unable to even FIND a wireless connection at all.

      For example - I disconnected from my school's network about 2 hours ago. When I tried to reconnect, I got the message saying Windows Cannot Find any Wireless Networks. I shut down the laptop and restarted it, and when I turned it back on, I could see several networks as well as the school's that I reconnected to. I have talked to other people who have been disconnected from school the same time as I have, which would be REASSURING, except for not being able to find other networks. Possibly though, now that I think about it, the other networks I can see might be school ones as well, just not the ones that students sign into, so those might have gone down at the same time as the main one did.

      Actually, I've been successful staying connected to my HOME network with turning off Windows Firewall. I got that advice after some online chatting with a Linksys rep.

      I didn't have a disconnect on this computer all weekend long. I didn't try the Asus. But I'm still worried because (a) I had the weird disconnect here at school (which may be benign), and (b) my wife's netbook had a couple disconnects from the home network.

      Now that I've talked myself through it a bit, it seems less worrisome. I'll monitor the netbook and try the Asus (all with Windows firewall off) and see if anything triggers.

      Thanks for the vote of confidence that there aren't any real problems, though!

      Tom
      I'm not the best at working through networking issues in a forums setting but it does sound like something might not be configured right.

      If it continues start a new topic in the Networking forum and I'm sure someone will have some good ideas.Thanks!

      2572.

      Solve : USB infected?

      Answer»

      Need your help on this one. USB infected with the Malware as mentioned below .The USB has a write protection which is not understood by me
      Ran a scan and here are the results

      Kaspersky Scan

      Object:
      f\winthb.exe
      Hoax.Win32.AutoHotKey.a

      Disinfection is not possible

      Cannot be deleted

      Skip (recommended)

      Add to exclusion

      These are the CHOICES that comes up.

      Downloaded the FLASH disinfector and ran the same. Need to get rid of this virus of if nothing came be done.Then show me a way to format the USB.Thank you for your timeFormat the USB? All RIGHT. (Note: you will lose everything on it)

      Download this HP formatting TOOL:
      http://files.filefront.com/SP27608exe/;9868201;/fileinfo.html

      Once INSTALLED, run it and format your USB Drive.WOW that was cool. Now my USB is clean. Thanks very muchGood job.

      2573.

      Solve : superantispyware information?

      Answer»

      on the main page , i clicked preferances , clicked repairs , and there are about 30 items in there that , when you click them it says they have been altered by malware but can be repaired and put back

      am i right or WRONG

      i cannot copy and paste the pageNot all of the repair features are available in the free version of SAS. They are to fix specific problems caused by malware. Only use them if you are 100% sure what they are for. As with any tool, you can cause damage to the PC. Even if the tool itself is safe running at the wrong time is risky.

      SUPERAntiSpyware Free and PROFESSIONAL Comparison

      SUPERAntiSpyware knowledgebasei will have a look at them and come back to you tomorrow

      did you have a look in repairs to see what i was taking about ok i had a look at your LINKS , i know what you mean , but still wonder why they are in there when they are part of programs , just trying to learn , could you explain how and why they are there , and that will be me

      thank you , harryEach one is specific and the title of it PRETTY much says it all. What I mean is they don't all work in the free version. They are all listed so you can see what's offered. ok evil , thats great thank you , i'll not mess around with them

      2574.

      Solve : virus crashed my computer help with using sata/usb adaptor?

      Answer»

      Ok, my computer crashed from a virus, it was suggested that I get a SATA to USB adaptor to extract the data on the hard drive prior to restoing the system. Well, when I hook up it up and look through the files I can not find any file with my DOCUMENTS. HELP!!!Do you mean all your documents are gone?well, I don't see a file that says documents, however I'm not sure how to ACCESS all the files. There are program files such as Micrsoft office ect. but no files of saved documents.Are you going to C:\Users\<username>\Documents?It just shows drive E: and recovery E: don't see C:Sorry, maybe not C. What drive is/was everything on?when it was working it was C: but when hooked up to the SATA adaptor and to my laptop it comes up as E:The best thing you can do is read this.
      Post the three logs here and wait for a malware removal specialist.

      Good luck with it. Ok let me start from the beginning. I recieved an email to join a FRIEND in yahoo...I opened it and downloaded it(yeah I know STUPID) it was a version of yahoo I have never seen before. Did not think much of it. Later when I went to go on my computer it was off. I turned it on and waited for it to boot....nothing completly black screen. What was suggested by a techie at a local company was to remove the hard drive from that computer and attach a sata to usb adaptor to extract the important data off of it before restoring it with the factory cd, as this would erase all my files. When hooking up this adaptor to my laptop, I could not find my documants anywhere. I am not a super computer techie so not sure where to locate these files. They are very important school work, home biz stuff etc. that's why I am so deperate for HELP!!!!!!!!!there is a problem with posting my logs, no logs to post. I removed my harddrive from my other computer and hooked it up to my laptop with the sata/usb adaptor, it shows PROGRAMS and such, but no files. Soooo...cannot post a log. If i wer to just restore my system will I loose all the data?

      2575.

      Solve : Need Help Dont Know What To Do?

      Answer»

      My computer has a virus.I know its a Trojan horse and it downloaded it self as a program called spyware guard 2008 my desktop was gone no ICONS and no task bar i was able to run programs through the task MANGER i did what the guide said and my icons and task bar are back so thats good i still want to make sure i GET ANYTHING that might b left out of the computer so if anybody can help with that id appreciate it. Thanks

      [attachment DELETED by admin]

      2576.

      Solve : help with virus/malware?

      Answer»

      Just one last question, I noticed on one of the logs I posted there was a comodo firewall file and a mcafee firewall file. I was using these (not at the same time) but I did uninstall. I do not see them in add/remove programs or under start menu. Could these still be on my machine despite uninstalling them and will this effect my current firewall's capability?

      Thanks again!!!What firewall are you using now?just windows firewallDownload the McAfee Consumer Product Removal Tool to your Desktop.
      Using McAfee Consumer Product Removal tool:

      • Double click the MCPR.exe
      • A Command Line window will be displayed, and then close automatically.
      • WAIT for a second Command Line window to be displayed.
        • Note: Do not double-click MCPR.exe again, you may have to wait up to 1 MINUTE for the next window to appear.
      • After the second window appears, the PROGRAM will begin the cleanup.
      • Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
      • Press Y on the keyboard.
      • Wait for the computer to restart.
      • All McAfee products are now removed from your computer.
      .
      ----------

      THIS IS NOT MEANT AS A STAND-ALONE UNINSTALLER, IT'S MADE TO DELETE LEFT-OVER FILES AND REGISTRY ENTRIES!

      Download, unzip and run the attached file to remove the Comodo leftovers.

      [attachment deleted by admin]McAfee SUCCESSFULLY downloaded ran removed and rebooted. I did not see an attached file for comodo removal. Thanks!Click on the attachment in the above post.



      [attachment deleted by admin]sorry...everything worked great!!! Thanks again. You are awesome and I appreciate your time!!!GLAD it worked.

      Let us know if anything else comes up.

      Safe surfing...
      2577.

      Solve : Msn Virus...?

      Answer»

      Done scans with my anti virus.
      Done scans with malwarebytes
      Done scans with spybot

      All programs detected something , which ive either quarantined or deleted.

      Its the usual symptoms MSN freezes up and my mouse cursor stops completely until i Ctrl Alt and delete , and kill msn from my process's.

      Got a log here. Just checking to see if theres anything in the log ive missed.

      Logfile of HijackThis v1.99.1
      Scan saved at 23:43:27, on 26/02/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\PnkBstrB.exe
      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Xfire\Xfire.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      C:\Documents and Settings\Tony\Desktop\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tiscali.co.uk/broadband
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.22\RivaTuner.exe" /S
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [cogad] "C:\Documents and Settings\Tony\Application Data\cogad\cogad.exe" 61A847B5BBF72810359A3E466188719AB689201 522886B092CBD44BD8689220221DD3257
      O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O17 - HKLM\System\CCS\Services\Tcpip\..\{6AEF9B5E-31C0-4AC1-ACA7-15915E2A8642}: NameServer = 212.139.132.9 212.139.132.8
      O17 - HKLM\System\CS1\Services\Tcpip\..\{6AEF9B5E-31C0-4AC1-ACA7-15915E2A8642}: NameServer = 212.139.132.9 212.139.132.8
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe


      There was a program evilfantasy TOLD another member about , it use's Cmd to remove virus's , can someone help with find that

      Thanks.

      Please looks at my log =)You still have some bad stuff on the computer.

      Disable Spybot's TeaTimer

      While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes. Please disable TeaTimer for now until you are clean.

      1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
      2. Run Spybot S&D
      3. Go to the Mode menu, and make sure Advanced Mode is selected.
      4. On the left hand side, choose Tools > Resident
      uncheck Resident TeaTimer and OK any prompt and Restart your computer.

      Note:
      If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

      If TeaTimer will not turn off then uninstall Spybot until we are done cleaning.

      ----------

      Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      - O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
      - O4 - HKCU\..\Run: [cogad] \"C:\Documents and Settings\Tony\Application Data\cogad\cogad.exe\" 61A847B5BBF72810359A3E466188719AB689201 522886B092CBD44BD8689220221DD3257


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.

      ----------

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Go to Start > Run and type notepad.exe then click OK

      Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

      Code: [Select]REGEDIT4

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
      "Alcmtr"=-
      "Windows UDP Control Center"=-

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "cogad"=-
      Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

      Make sure that you tell me if you RECEIVE a success message about adding the above to the registry. If you do not get a success message, it did not work.

      Delete the fixme.reg from the Desktop.

      ----------

      Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before PERFORMING a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.The reg entry was a success , i wasn't to sure about ending anti virus programs due to getting trojan warnings every 5 minutes. Im not sure if it worked or not ....

      ComboFix 09-02-01.01 - Tony 2009-02-27 0:10:54.1 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1645 [GMT 0:00]
      Running from: c:\documents and settings\Tony\Desktop\ComboFix.exe
      AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
      * Created a new restore point
      .
      - REDUCED FUNCTIONALITY MODE -
      .

      ((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
      .

      2009-02-26 23:24 . 2009-02-26 23:24d--------c:\program files\Malwarebytes' Anti-Malware
      2009-02-26 23:24 . 2009-02-26 23:24d--------c:\documents and settings\Tony\Application Data\Malwarebytes
      2009-02-26 23:24 . 2009-02-26 23:24d--------c:\documents and settings\All Users\Application Data\Malwarebytes
      2009-02-26 23:24 . 2009-01-14 16:1138,496--a------c:\windows\system32\drivers\mbamswissarmy.sys
      2009-02-26 23:24 . 2009-01-14 16:1115,504--a------c:\windows\system32\drivers\mbam.sys
      2009-02-26 22:56 . 2009-02-26 22:57d--------c:\program files\Spybot - Search & Destroy
      2009-02-26 22:56 . 2009-02-26 23:16d--------c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2009-02-26 22:50 . 2009-02-26 22:50d--------C:\VundoFix Backups
      2009-02-26 22:37 . 2009-02-26 22:37d--------c:\program files\Avira
      2009-02-26 22:37 . 2009-02-26 22:37d--------c:\documents and settings\All Users\Application Data\Avira
      2009-02-26 22:28 . 2009-02-26 22:284,096--a------C:\sinh.exe
      2009-02-26 10:48 . 2009-02-26 10:48d--------c:\windows\Sun
      2009-02-25 10:26 . 2009-02-25 10:26d--------c:\program files\LimeWire
      2009-02-25 10:26 . 2009-02-25 22:04d--------c:\documents and settings\Tony\Application Data\LimeWire
      2009-02-25 10:21 . 2009-02-25 10:21d--------c:\program files\iMesh Applications
      2009-02-25 10:21 . 2009-02-25 10:23d--------c:\documents and settings\Tony\Application Data\iMesh
      2009-02-25 10:21 . 2005-10-07 12:50483,328--a------c:\windows\system32\actskn45.ocx
      2009-02-25 05:44 . 2009-02-25 05:45d--------c:\program files\Yahoo!
      2009-02-25 05:44 . 2009-02-25 05:45d--------c:\documents and settings\All Users\Application Data\Yahoo!
      2009-02-25 05:26 . 2009-02-25 05:26d--------c:\program files\Common Files\Adobe AIR
      2009-02-25 05:26 . 2009-02-25 05:26d--------c:\program files\Common Files\Adobe
      2009-02-25 03:09 . 2009-02-25 03:09d--------C:\CFLog
      2009-02-25 03:08 . 2003-07-17 09:175,174--a------c:\windows\system32\nppt9x.vxd
      2009-02-25 03:08 . 2005-01-01 00:434,682--a------c:\windows\system32\npptNT2.sys
      2009-02-25 03:07 . 2009-02-25 03:07d--------c:\program files\Common Files\INCA Shared
      2009-02-25 03:05 . 2009-02-25 03:05d--------c:\program files\G4box
      2009-02-24 08:42 . 2009-02-24 08:42d--------C:\Games
      2009-02-22 05:09 . 2009-02-22 05:13d--------c:\windows\system32\Adobe
      2009-02-22 05:09 . 2009-01-16 18:34499,712--a------c:\windows\system32\msvcp71.dll
      2009-02-22 05:09 . 2009-01-16 18:34348,160---------c:\windows\system32\msvcr71.dll
      2009-02-22 04:50 . 2009-02-22 04:50410,984--a------c:\windows\system32\deploytk.dll
      2009-02-03 05:46 . 2009-02-03 06:00d--------c:\windows\system32\CatRoot_bak
      2009-02-03 05:42 . 2008-08-14 10:002,180,352-----c---c:\windows\system32\dllcache\ntoskrnl.exe
      2009-02-03 05:42 . 2008-08-14 09:582,136,064-----c---c:\windows\system32\dllcache\ntkrnlmp.exe
      2009-02-03 05:42 . 2008-08-14 09:222,057,728-----c---c:\windows\system32\dllcache\ntkrnlpa.exe
      2009-02-03 05:42 . 2008-08-14 09:222,015,744-----c---c:\windows\system32\dllcache\ntkrpamp.exe
      2009-02-03 05:41 . 2008-10-24 11:10453,632-----c---c:\windows\system32\dllcache\mrxsmb.sys
      2009-02-03 05:41 . 2008-06-13 13:10272,128---------c:\windows\system32\drivers\bthport.sys
      2009-02-03 05:41 . 2008-06-13 13:10272,128-----c---c:\windows\system32\dllcache\bthport.sys
      2009-02-03 05:33 . 2009-02-03 06:09d--h-----c:\windows\$hf_mig$
      2009-02-03 00:24 . 2009-02-03 00:24d--------c:\documents and settings\Tony\Application Data\vlc
      2009-02-03 00:23 . 2009-02-03 00:23d--------c:\program files\VideoLAN
      2009-02-02 17:27 . 2004-08-03 23:0826,496--a--c---c:\windows\system32\dllcache\usbstor.sys
      2009-02-02 17:18 . 2009-02-02 17:18d--------c:\program files\uTorrent
      2009-02-02 17:18 . 2009-02-26 06:28d--------c:\documents and settings\Tony\Application Data\uTorrent
      2009-02-02 16:11 . 2009-02-22 04:49d--------c:\program files\Java
      2009-02-02 16:11 . 2009-02-22 04:5073,728--a------c:\windows\system32\javacpl.cpl
      2009-02-02 16:10 . 2009-02-02 16:10d--------c:\program files\Common Files\Java
      2009-02-02 16:00 . 2009-02-02 16:0022,328--a------c:\documents and settings\Tony\Application Data\PnkBstrK.sys
      2009-02-02 15:59 . 2009-02-02 15:59d--------c:\windows\system32\LogFiles
      2009-02-02 15:59 . 2009-02-26 21:40188,848--a------c:\windows\system32\PnkBstrB.exe
      2009-02-02 15:59 . 2009-02-02 16:2870,968--a------c:\windows\system32\PnkBstrA.exe
      2009-02-02 05:32 . 2009-02-24 04:23d--------C:\World of Warcraft
      2009-02-02 05:31 . 2009-02-02 05:31d--------c:\documents and settings\All Users\Application Data\Blizzard
      2009-02-02 05:25 . 2009-02-02 10:46d--------c:\program files\Common Files\Blizzard Entertainment
      2009-02-02 05:20 . 2009-02-02 05:20d--------c:\program files\RivaTuner v2.22
      2009-02-02 05:19 . 2009-02-02 05:19d--------c:\documents and settings\Tony\Application Data\Apple Computer
      2009-02-02 05:19 . 2008-04-17 13:12107,368--a------c:\windows\system32\GEARAspi.dll
      2009-02-02 05:19 . 2008-04-17 13:1215,464--a------c:\windows\system32\drivers\GEARAspiWDM.sys
      2009-02-02 05:18 . 2009-02-02 05:18d--------c:\program files\QuickTime
      2009-02-02 05:18 . 2009-02-02 05:19d--------c:\program files\iTunes
      2009-02-02 05:18 . 2009-02-02 05:18d--------c:\program files\iPod
      2009-02-02 05:18 . 2009-02-02 05:18d--------c:\program files\Bonjour
      2009-02-02 05:18 . 2009-02-02 05:18d--------c:\program files\Apple Software Update
      2009-02-02 05:18 . 2009-02-02 05:18d--------c:\documents and settings\All Users\Application Data\Apple Computer
      2009-02-02 05:18 . 2009-02-02 05:19d--------c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
      2009-02-02 05:17 . 2009-02-02 05:17d--------c:\program files\Common Files\Apple
      2009-02-02 05:17 . 2009-02-02 05:17d---s----c:\documents and settings\Tony\UserData
      2009-02-02 05:17 . 2009-02-02 05:17d--------c:\documents and settings\All Users\Application Data\Apple
      2009-02-02 05:15 . 2009-02-02 05:15d--------c:\windows\system32\Lang
      2009-02-02 05:15 . 2009-02-02 05:15940,794--a------c:\windows\system32\LoopyMusic.wav
      2009-02-02 05:15 . 2009-02-02 05:15146,650--a------c:\windows\system32\BuzzingBee.wav
      2009-02-02 05:15 . 2004-08-03 23:1582,944--a------c:\windows\system32\drivers\wdmaud.sys
      2009-02-02 05:15 . 2004-08-03 23:1582,944--a--c---c:\windows\system32\dllcache\wdmaud.sys
      2009-02-02 05:15 . 2004-08-03 23:0752,864--a------c:\windows\system32\drivers\DMusic.sys
      2009-02-02 05:15 . 2004-08-03 23:0752,864--a--c---c:\windows\system32\dllcache\dmusic.sys
      2009-02-02 05:15 . 2004-08-03 23:076,400--a------c:\windows\system32\drivers\splitter.sys
      2009-02-02 05:15 . 2004-08-03 23:076,400--a--c---c:\windows\system32\dllcache\splitter.sys
      2009-02-02 05:13 . 2004-08-04 00:56130,048--a------c:\windows\system32\ksproxy.ax
      2009-02-02 05:13 . 2004-08-04 00:56130,048--a--c---c:\windows\system32\dllcache\ksproxy.ax
      2009-02-02 05:13 . 2004-08-03 23:0860,288--a------c:\windows\system32\drivers\drmk.sys
      2009-02-02 05:13 . 2004-08-03 23:0860,288--a--c---c:\windows\system32\dllcache\drmk.sys
      2009-02-02 05:13 . 2004-08-04 00:564,096--a------c:\windows\system32\ksuser.dll
      2009-02-02 05:13 . 2004-08-04 00:564,096--a--c---c:\windows\system32\dllcache\ksuser.dll
      2009-02-02 05:12 . 2009-02-02 05:12d--------c:\program files\Realtek
      2009-02-02 05:11 . 2009-01-22 16:53d--------c:\documents and settings\Tony\HD_Audio
      2009-02-02 05:10 . 2009-02-02 05:10d--------c:\documents and settings\Tony\Contacts
      2009-02-02 05:00 . 2009-02-02 05:19d----c---c:\windows\system32\DRVSTORE
      2009-02-02 05:00 . 2009-02-02 05:00d--------c:\program files\Intel
      2009-02-02 05:00 . 2009-02-02 05:00d--------C:\Intel
      2009-02-02 05:00 . 2009-02-02 05:00d--------c:\documents and settings\Tony\INFUpdate
      2009-02-02 05:00 . 2007-07-26 16:1553,248--a------c:\windows\system32\CSVer.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-02-26 21:40138,064----a-wc:\windows\system32\drivers\PnkBstrK.sys
      2009-02-26 01:36---------d-----wc:\documents and settings\Tony\Application Data\Xfire
      2009-02-23 23:38---------d-----wc:\program files\Xfire
      2009-02-02 17:12---------d--h--wc:\program files\InstallShield Installation Information
      2009-02-02 15:50---------d-----wc:\program files\Activision
      2009-02-02 05:12319,488----a-wc:\windows\HideWin.exe
      2009-02-02 04:53---------d-----wc:\program files\Lavalys
      2009-02-02 04:46---------d-----wc:\documents and settings\LocalService\Application Data\Xfire
      2009-02-02 04:44---------d-----wc:\program files\Realtek AC97
      2009-02-02 04:44---------d-----wc:\program files\Common Files\InstallShield
      2009-02-02 04:36---------d-----wc:\program files\Common Files\Wise Installation Wizard
      2009-02-02 04:36---------d-----wc:\program files\AGEIA Technologies
      2009-02-02 04:20---------d-----wc:\documents and settings\NetworkService\Application Data\Xfire
      2009-02-02 04:18---------d-----wc:\program files\Thomson
      2009-02-02 04:12---------d-----wc:\program files\microsoft frontpage
      2009-01-23 01:1742,320----a-wc:\windows\system32\xfcodec.dll
      2009-01-07 11:28453,152----a-wc:\windows\system32\NVUNINST.EXE
      2008-12-10 09:4570,936----a-wc:\windows\system32\PhysXLoader.dll
      2008-12-04 09:2824,344----a-wc:\windows\system32\PhysXDevice.dll
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
      "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-28 4363504]
      "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2007-06-11 901120]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
      "RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.22\RivaTuner.exe" [2008-12-29 2732032]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-22 136600]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
      "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
      "nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
      "RTHDCPL"="RTHDCPL.EXE" [2008-10-09 c:\windows\RTHDCPL.EXE]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

      c:\documents and settings\Tony\Start Menu\Programs\Startup\
      Xfire.lnk - c:\program files\Xfire\Xfire.exe [2009-01-23 2993488]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "VIDC.XFR1"= xfcodec.dll

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Xfire\\Xfire.exe"=
      "c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=
      "c:\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enGB-Win-Update-downloader.exe"=
      "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
      "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
      "c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
      "c:\\Program Files\\uTorrent\\uTorrent.exe"=
      "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
      .
      - - - - ORPHANS REMOVED - - - -

      HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe


      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.tiscali.co.uk/broadband
      uInternet Connection Wizard,ShellNext = hxxp://www.tiscali.co.uk/broadband
      TCP: {6AEF9B5E-31C0-4AC1-ACA7-15915E2A8642} = 212.139.132.9 212.139.132.8
      FF - ProfilePath - c:\documents and settings\Tony\Application Data\Mozilla\Firefox\Profiles\jv3zbyde.default\

      ---- FIREFOX POLICIES ----
      FF - user.js: yahoo.homepage.dontask - true.

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-02-27 00:11:07
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      Completion time: 2009-02-27 0:12:00
      ComboFix-quarantined-files.txt 2009-02-27 00:11:58

      Pre-Run: 83,605,630,976 bytes free
      Post-Run: 97,640,075,264 bytes free

      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

      202--- E O F ---2009-02-03 06:09:39
      Quote

      i wasn't to sure about ending anti virus programs due to getting trojan warnings every 5 minutes.

      They aren't doing much good if the malware is already on the system And with TeaTimer running it is sometimes impossible to remove a virus since it resets the registry in many instances. You should always turn off TeaTimer when scanning for or removing malware.

      Scan Suspicious File(s)

      Please go to VirusTotal.com
      (If more than one file needs scanned they must be done separately and logs posted for each one)

      1. Copy the file path in the below Code box:
      Code: [Select]C:\sinh.exe
      2. At the upload site, click once inside the window next to Browse.
      3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
      4. Next click Send File
      Your file will possibly be entered into a queue which normally takes less than a minute to clear.
      This will perform a scan across multiple different virus scanning engines.
      Important: Wait for all of the scanning engines to complete.
      5. Copy and then Paste the link to the results in the next reply.
      Here we go:

      File sinh.exe received on 02.02.2009 01:24:36 (CET)
      Current status: Loading ... QUEUED waiting scanning finished NOT FOUND STOPPED
      Result: 0/39 (0%)
      Loading server information...
      Your file is queued in position: ___.
      Estimated start time is between ___ and ___ .
      Do not close the window until scan is complete.
      The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
      If you are waiting for more than five minutes you have to resend your file.
      Your file is being scanned by VirusTotal in this moment,
      results will be shown as they're generated.
      Compact Compact
      Print results Print results
      Your file has expired or does not exists.
      Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

      You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
      Email:

      Antivirus Version Last Update Result
      a-squared4.0.0.932009.02.01-
      AhnLab-V35.0.0.22009.02.01-
      AntiVir7.9.0.702009.02.01-
      Authentium5.1.0.42009.02.01-
      Avast4.8.1281.02009.02.01-
      AVG8.0.0.2292009.02.01-
      BitDefender7.22009.02.02-
      CAT-QuickHeal10.002009.01.31-
      ClamAV0.94.12009.02.02-
      Comodo9572009.02.01-
      DrWeb4.44.0.091702009.02.02-
      eSafe7.0.17.02009.02.01-
      eTrust-Vet31.6.63352009.01.29-
      F-Prot4.4.4.562009.02.01-
      F-Secure8.0.14470.02009.02.02-
      Fortinet3.117.0.02009.02.01-
      GData192009.02.02-
      IkarusT3.1.1.45.02009.02.01-
      K7AntiVirus7.10.6122009.01.31-
      Kaspersky7.0.0.1252009.02.02-
      McAfee55132009.02.01-
      McAfee+Artemis55132009.02.01-
      Microsoft1.43062009.02.02-
      NOD3238162009.02.01-
      Norman6.00.022009.01.31-
      nProtect2009.1.8.02009.01.30-
      Panda9.5.1.22009.02.01-
      PCTools4.4.2.02009.02.01-
      Prevx1V22009.02.02-
      Rising21.14.61.002009.02.01-
      SecureWeb-Gateway6.7.62009.02.01-
      Sophos4.38.02009.02.01-
      Sunbelt3.2.1835.22009.01.16-
      Symantec102009.02.02-
      TheHacker6.3.1.5.2432009.02.01-
      TrendMicro8.700.0.10042009.01.30-
      VBA323.12.8.122009.02.01-
      ViRobot2009.1.31.15832009.01.31-
      VirusBuster4.5.11.02009.02.01-


      If thats not what you wanted ^^ Please tell me what information you did want.

      Tony:)

      Btw thanks for helping.

      Webwasher-Gateway - - BlockReason.0

      : /

      I looked on another page , and there was that....That's what I needed. How is the computer running now?I will reinstall msn , and take a look.

      I had no issue with it slowing down , as soon as i clicked the link , i only relised it was a exe until it said , Image will not load...

      Then i thought ah ****.....

      My mate sent it , so i assumed it was a trust worthy source , but turns out shes infected beyond belief ...

      I caught it all in time i hope.

      I will post back in 5 minutes.Ok well all seems ok now ^^

      Thats 4 hours i wont be getting back lol.....

      I will full scan with all the anti virus i have tonight , just to be on the safe side...

      Thanks for all the help , and by the way. What did the reg entry do?

      Just curious , and the items i delete in hijackthis , what sort of infections where they You might have your friend run these tools on their computer. Or have them come here and do the malware removal guide.

      http://downloads.malwareremoval.com/MsnVirRem.exe
      http://www.forospyware.com/Msncleaner/MsnCleaner_eng.zip

      Quote
      Just curious , and the items i delete in hijackthis , what sort of infections where they

      Alcmtr was just bloatware that slows down many computers.
      Windows UDP Control Center/fxstaller.exe A variant of the IRCBot family of worms and IRC backdoor Trojans http://www.bleepingcomputer.com/startups/Windows_UDP_Control_Center-24046.html
      cogad.exe Added by the Troj/Dloadr-CEP downloading Trojan http://www.bleepingcomputer.com/startups/cogad.exe-24485.html

      ----------

      Cleanup steps.

      Download OTCleanIt.exe and save it to your Desktop.
      • Double-click OTCleanIt.exe.
      • Click the CleanUp! button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes, if not delete it yourself.
      .
      ----------

      Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide or Windows Vista System Restore Guide
      2578.

      Solve : For evilfantasy--c.bell_08?

      Answer»

      Your thanks are plenty!!

      Let US know if anything else COMES up.

      Safe SURFING...

      2579.

      Solve : Are these programs enough??

      Answer»

      I was wondering if these programs installed on my computer are enough in fighting spyware ad-ware malware viruses ETC.. Ad-Aware by lavasoft free, Malwarebytes' ANTI-Malware, SpywareBlaster, Spybot - Search & Destroy AVG free, spyware terminator.Quote from: alyoob on February 02, 2009, 10:58:46 AM

      I was wondering if these programs installed on my computer are enough in fighting spyware ad-ware malware viruses etc.. Ad-Aware by lavasoft free, Malwarebytes' Anti-Malware, SpywareBlaster, Spybot - Search & Destroy Avg free, spyware terminator.


      Why so many anti-spyware and anti malware?

      Honestly, from my personal experience it is not the amount of software you install,( its good to have some protection,) but it is the users who are behind the computer.

      I don't know why you have so many antispyware, most antispyware companies have similar if not the same malware defintions installed into their database, their might be one or 2 that differ by just a little. If you get a coorperate, or buisness antimalware you have more protection because it has more malware data then for personal uses.

      So... what about your firewall? You can't have a virus scanner without a firewall.

      Also do any of those EVEN have REAL time protection.. no point in having multi cleaners if not one of them is real time protection.


      My security are: Comodo Security Suite, Webroot Spysweeper, Emisoft(A2 free) Thats all I need,
      2580.

      Solve : some1 says i am infected?

      Answer»

      yes im on firefox now thx. ok now i just got a bubble that said taking out memory and i tried to download ad-ware ae and said i dont have enough memory. i used defragmenter and said i have 63% storage not used my firewall has been deleted im messed right up. my log files for antivir personal.
      Avira AntiVir Personal
      Report file date: Monday, January 19, 2009 03:46

      Scanning for 1038808 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (plain) [5.1.2600]
      BOOT mode: Normally booted
      Username: SYSTEM
      COMPUTER name: SERVER

      Version information:
      BUILD.DAT : 8.2.0.337 16934 Bytes 11/18/2008 13:05:00
      AVSCAN.EXE : 8.1.4.10 315649 Bytes 11/18/2008 17:21:26
      AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 16:56:40
      LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 21:44:19
      LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 16:58:52
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 20:30:36
      ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 11/9/2008 01:57:13
      ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 11/16/2008 01:16:47
      ANTIVIR3.VDF : 7.1.0.97 45056 Bytes 11/17/2008 01:38:59
      Engineversion : 8.2.0.31
      AEVDF.DLL : 8.1.0.6 102772 Bytes 10/14/2008 19:05:56
      AESCRIPT.DLL : 8.1.1.15 332156 Bytes 11/11/2008 23:00:07
      AESCN.DLL : 8.1.1.5 123251 Bytes 11/8/2008 00:06:41
      AERDL.DLL : 8.1.1.3 438645 Bytes 11/4/2008 22:58:38
      AEPACK.DLL : 8.1.3.4 393591 Bytes 11/11/2008 18:41:39
      AEOFFICE.DLL : 8.1.0.30 196986 Bytes 11/8/2008 00:06:41
      AEHEUR.DLL : 8.1.0.71 1487222 Bytes 11/8/2008 00:06:41
      AEHELP.DLL : 8.1.1.3 119157 Bytes 11/8/2008 00:06:41
      AEGEN.DLL : 8.1.1.0 319859 Bytes 11/8/2008 00:06:41
      AEEMU.DLL : 8.1.0.9 393588 Bytes 10/14/2008 19:05:56
      AECORE.DLL : 8.1.4.1 172405 Bytes 11/8/2008 00:06:41
      AEBB.DLL : 8.1.0.3 53618 Bytes 10/14/2008 19:05:56
      AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 17:40:05
      AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 18:28:01
      AVREP.DLL : 8.0.0.2 98344 Bytes 7/31/2008 21:02:15
      AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 20:26:40
      AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 17:29:23
      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 21:27:49
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 02:28:02
      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 21:49:40
      NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 21:05:10
      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 22:48:07
      RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 22:34:37

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: C:,
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: Intelligent file selection
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: medium
      Start of the scan: Monday, January 19, 2009 03:46

      The scan of running processes will be started
      Scan process 'PokerStarsUpdate.exe' - '1' Module(s) have been scanned
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
      Scan process 'Kodak Software Updater.exe' - '1' Module(s) have been scanned
      Scan process 'EasyShare.exe' - '1' Module(s) have been scanned
      Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
      Scan process 'lxdnmsdmon.exe' - '1' Module(s) have been scanned
      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'lxdnmon.exe' - '1' Module(s) have been scanned
      Scan process 'jusched.exe' - '1' Module(s) have been scanned
      Scan process 'avgcc.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'tcpsvcs.exe' - '1' Module(s) have been scanned
      Scan process 'lxdncoms.exe' - '1' Module(s) have been scanned
      Scan process 'lxdnserv.exe' - '1' Module(s) have been scanned
      Scan process 'jqs.exe' - '1' Module(s) have been scanned
      Scan process 'avgemc.exe' - '1' Module(s) have been scanned
      Scan process 'avgupsvc.exe' - '1' Module(s) have been scanned
      Scan process 'avgamsvr.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      35 processes with 35 modules were scannedcont...
      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '60' files ).


      Starting the file scan:

      Begin scan in 'C:\'
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      C:\$VAULT$.AVG\00000001.FIL

      • Archive TYPE: HIDDEN

      --> FIL\\\?\C:\$VAULT$.AVG\00000001.FIL
      [DETECTION] Contains recognition PATTERN of the WORM/Lovsan.F.1 worm
      [NOTE] The file was moved to '49a46878.qua'!
      C:\Documents and Settings\server\Local Settings\Temp\62888679.exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
      [NOTE] The file was moved to '49ac6a72.qua'!
      C:\Documents and Settings\server\Local Settings\Temp\63252812.exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
      [NOTE] The file was moved to '49a66a7b.qua'!
      C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\colbact.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\es.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB833987$\sxs.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\browser.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
      [WARNING] The file could not be opened!
      C:\WINDOWS\Downloaded Program Files\start.INF
      [DETECTION] Is the TR/Dagonit.INF Trojan
      [NOTE] The file was moved to '49d57627.qua'!
      C:\WINDOWS\system32\components\flx1.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b4a.qua'!
      C:\WINDOWS\system32\components\flx10.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b51.qua'!
      C:\WINDOWS\system32\components\flx11.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b55.qua'!
      C:\WINDOWS\system32\components\flx12.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b58.qua'!
      C:\WINDOWS\system32\components\flx13.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b5b.qua'!
      C:\WINDOWS\system32\components\flx14.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b5e.qua'!
      C:\WINDOWS\system32\components\flx15.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b61.qua'!
      C:\WINDOWS\system32\components\flx16.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b63.qua'!
      C:\WINDOWS\system32\components\flx17.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b65.qua'!
      C:\WINDOWS\system32\components\flx18.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b67.qua'!
      C:\WINDOWS\system32\components\flx19.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b69.qua'!
      C:\WINDOWS\system32\components\flx2.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b6b.qua'!
      C:\WINDOWS\system32\components\flx20.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b6e.qua'!
      C:\WINDOWS\system32\components\flx21.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b6f.qua'!
      C:\WINDOWS\system32\components\flx22.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b72.qua'!
      C:\WINDOWS\system32\components\flx23.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b74.qua'!
      C:\WINDOWS\system32\components\flx24.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b76.qua'!
      C:\WINDOWS\system32\components\flx25.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b78.qua'!
      C:\WINDOWS\system32\components\flx26.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b7a.qua'!
      C:\WINDOWS\system32\components\flx27.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b7c.qua'!
      C:\WINDOWS\system32\components\flx28.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b7e.qua'!
      C:\WINDOWS\system32\components\flx29.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b80.qua'!
      C:\WINDOWS\system32\components\flx3.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b83.qua'!
      C:\WINDOWS\system32\components\flx30.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b85.qua'!
      C:\WINDOWS\system32\components\flx32.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b8b.qua'!
      C:\WINDOWS\system32\components\flx33.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b8c.qua'!
      C:\WINDOWS\system32\components\flx34.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '48864ecd.qua'!
      C:\WINDOWS\system32\components\flx35.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b8d.qua'!
      C:\WINDOWS\system32\components\flx36.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b8e.qua'!
      C:\WINDOWS\system32\components\flx37.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b8f.qua'!
      C:\WINDOWS\system32\components\flx38.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b90.qua'!
      C:\WINDOWS\system32\components\flx39.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '48864ed1.qua'!
      C:\WINDOWS\system32\components\flx4.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b92.qua'!
      C:\WINDOWS\system32\components\flx40.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '48864ed3.qua'!
      C:\WINDOWS\system32\components\flx41.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b93.qua'!
      C:\WINDOWS\system32\components\flx42.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b94.qua'!
      C:\WINDOWS\system32\components\flx43.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b95.qua'!
      C:\WINDOWS\system32\components\flx44.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b96.qua'!
      C:\WINDOWS\system32\components\flx45.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '48864ed7.qua'!
      C:\WINDOWS\system32\components\flx46.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b97.qua'!
      C:\WINDOWS\system32\components\flx47.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b98.qua'!
      C:\WINDOWS\system32\components\flx48.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b99.qua'!
      C:\WINDOWS\system32\components\flx49.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9a.qua'!
      C:\WINDOWS\system32\components\flx5.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9b.qua'!
      C:\WINDOWS\system32\components\flx57.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9c.qua'!
      C:\WINDOWS\system32\components\flx59.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9d.qua'!
      C:\WINDOWS\system32\components\flx61.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9e.qua'!
      C:\WINDOWS\system32\components\flx63.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7b9f.qua'!
      C:\WINDOWS\system32\components\flx65.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba0.qua'!
      C:\WINDOWS\system32\components\flx67.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba1.qua'!
      C:\WINDOWS\system32\components\flx69.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba2.qua'!
      C:\WINDOWS\system32\components\flx7.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba3.qua'!
      C:\WINDOWS\system32\components\flx70.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '48864ee4.qua'!
      C:\WINDOWS\system32\components\flx72.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba4.qua'!
      C:\WINDOWS\system32\components\flx73.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba5.qua'!
      C:\WINDOWS\system32\components\flx74.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba6.qua'!
      C:\WINDOWS\system32\components\flx8.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba8.qua'!
      C:\WINDOWS\system32\components\flx9.dll
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '49ec7ba9.qua'!


      End of the scan: Monday, January 19, 2009 05:14
      Used time: 1:27:53 Hour(s)

      The scan has been done completely.

      4121 Scanning directories
      199174 Files were scanned
      62 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      62 files were moved to quarantine
      0 files were renamed
      39 Files cannot be scanned
      199073 Files not concerned
      2170 Archives were scanned
      39 WARNINGS
      62 Notes

      my log for super anti spy...
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 01/20/2009 at 04:08 PM

      Application Version : 4.25.1012

      Core Rules Database Version : 3718
      Trace Rules Database Version: 1692

      Scan type : Quick Scan
      Total Scan Time : 00:22:31

      Memory items scanned : 603
      Memory threats detected : 0
      Registry items scanned : 400
      Registry threats detected : 16
      File items scanned : 4509
      File threats detected : 39

      Browser Hijacker.BestSafetyGuide
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{873eb32d-ae1a-4183-89bd-45a77f761be4}
      HKCR\CLSID\{873EB32D-AE1A-4183-89BD-45A77F761BE4}
      HKCR\CLSID\{873EB32D-AE1A-4183-89BD-45A77F761BE4}
      HKCR\CLSID\{873EB32D-AE1A-4183-89BD-45A77F761BE4}\InprocServer32
      HKCR\CLSID\{873EB32D-AE1A-4183-89BD-45A77F761BE4}\InprocServer32#ThreadingModel
      C:\WINDOWS\SYSTEM32\IXT0.DLL

      Unclassified.Unknown Origin
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#SystemCheck2
      HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}
      HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}
      HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}\InProcServer32
      C:\WINDOWS\SYSTEM32\VBSYS2.DLL

      Trojan.Homepage
      HKCR\CLSID\{8D83B16E-0DE1-452B-AC52-96EC0B34AA4B}
      HKCR\CLSID\{8D83B16E-0DE1-452B-AC52-96EC0B34AA4B}\InprocServer32
      HKCR\CLSID\{8D83B16E-0DE1-452B-AC52-96EC0B34AA4B}\InprocServer32#ThreadingModel
      HKCR\CLSID\{EDBF1BC8-39AB-48EB-A0A9-C75078EB7C8E}
      HKCR\CLSID\{EDBF1BC8-39AB-48EB-A0A9-C75078EB7C8E}\InprocServer32
      HKCR\CLSID\{EDBF1BC8-39AB-48EB-A0A9-C75078EB7C8E}\InprocServer32#ThreadingModel

      Unclassified.PC MightyMax
      HKU\S-1-5-21-1060284298-1078145449-854245398-1003\Software\PC MightyMax
      C:\Program Files\PC MightyMax\lic.conf
      C:\Program Files\PC MightyMax\lic.dat
      C:\Program Files\PC MightyMax\pcdocrx.conf
      C:\Program Files\PC MightyMax\tmp_res_x_101.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_102.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_103.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_104.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_105.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_106.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_107.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_108.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_109.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_110.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_111.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_112.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_113.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_114.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_115.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_116.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_117.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_118.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_119.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_120.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_121.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_122.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_123.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_124.tmp
      C:\Program Files\PC MightyMax\tmp_res_x_125.tmp
      C:\Program Files\PC MightyMax\undo
      C:\Program Files\PC MightyMax

      Adware.Tracking Cookie
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\server\Local Settings\Temp\Cookies\[emailprotected][2].txt

      Malware.SpywareQuake
      C:\WINDOWS\TEMP\SABD.EXE
      my log for malwarebytes...
      Malwarebytes' Anti-Malware 1.33
      Database version: 1673
      Windows 5.1.2600

      1/20/2009 5:09:22 PM
      mbam-log-2009-01-20 (17-09-22).txt

      Scan type: Quick Scan
      Objects scanned: 53871
      Time elapsed: 13 minute(s), 58 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 8
      Registry Values Infected: 1
      Registry Data Items Infected: 0
      Folders Infected: 3
      Files Infected: 6

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2bf41072-b2b1-21c1-b5c1-0305f4155515} (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193423} (Trojan.Clicker) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193429} (Trojan.Clicker) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-615111193427} (Trojan.Clicker) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1131-1111-1111-611111193428} (Trojan.Clicker) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{64311111-1111-1121-1111-111191113457} (Trojan.Clicker) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      C:\Documents and Settings\server\Application Data\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\Documents and Settings\server\Application Data\AntispywareBot\Log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\Documents and Settings\server\Application Data\AntispywareBot\Settings (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

      Files Infected:
      C:\Documents and Settings\server\Application Data\AntispywareBot\rs.dat (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\Documents and Settings\server\Application Data\AntispywareBot\Log\2009 Jan 19 - 09_21_42 PM_733.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\Documents and Settings\server\Application Data\AntispywareBot\Log\2009 Jan 19 - 09_58_08 PM_436.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\Documents and Settings\server\Application Data\AntispywareBot\Settings\ScanResults.pie (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\AntispywareBot Scheduled Scan.job (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\7_exception.nls (Trojan.Tibs) -> Quarantined and deleted successfully.
      i am now stuck on the hijack this wont let me copy past hiany1 can look at filesany1 help me Apologies for this long wait.

      We are currently a bit short on Malware Specialists.
      Because of this, they are mainly only looking at topics in the Computer Virus and Spyware Section with 0 replied.
      I suggest re-posting your problem, along with the logs. (attach them as text files).
      2581.

      Solve : Can't delete an infected write-protected file...???

      Answer»

      Hi-
      I have a Windows ME program w/a McAfee Virus Scan which detected an infected file.
      When hitting Delete-Quarantine-Clean buttons, a blurb box & Status says "Writed-Protected File, Can't Delete..Can't Quarantine...Can't Clean.
      My PC is on life support as it is, but I notice it has been crawling when I turn it on.
      I tried to highlight the file name & right-click Delete- Nothing.
      Does anyone out there have an answer to this dilemma?(particularly one that doesn't involve ASTRO-physics..)
      Thanks.
      try the following force-delete procedure.

      http://www.theeldergeek.com/delete_undeletable_file.htm

      if this generates an error message, reproduce the message complete with all the gibberish-y stuff.Hi-
      Will do. Gibberishy Stuff sounds LIKE street slang for Astro Physics!! No, thank u for a quick response.
      This thing had me talking to the computer "What else do u want from my life..."
      I will do that as soon as I GET home.
      Thx again
      Hi Again-HELP AGAIN!!

      I tried what 'squirrel' had mentioned with the Command Prompt & Task Mgr but didn't get far.. with the eldergeek.com DELETE_UNDELETABLE_FILE

      My PC has Windows ME & its called MS-DOS Prompt not Command Prompt but when I entered TaskMgr.exe to list my files, Windows did not "recognize" taskmgr.exe.

      Any one have any suggestions? How to get around this? Is it possible -like Command Prompt being called MS-DOS Prompt- Task Manager on Windows ME (or my PC,anyhow) might be under a different name?

      Also, the VirusScan lists the name of the file infected- ( C:_RESTORE/ARCHIVE/FS232.CAB ) Does anyone why my Search Files doesn't come up with this? I'm trying anything, including to find out what this file is.

      This is a drag. 1 file out of 36,000 is making my PC act weird. I just want to delete, quarantine it.

      Any Help Would Be Sorely Appreciatedit seems like its in your system restore

      did you turn the system restore off before you did all of the scans? and in safe MODE
      No, I didn't. I just thought it was time to do a check since the PC is running slower & weirder than usual. And bingo....withiin the first 1000 or so files I hit an infected file out of 36000 or so.

      I can tell you I ran the System Restore recently when I had a problem a couple of months ago. FYI, I notice the Virus Type is a 'Trojan' according to the Mcaffee VirusScan that detected it.

      Turn off System Restore & put in Safe Mode? What would that do while running the Scan? If it isn't detected then thats where it is? Is that what you're saying?



      it makes it so that only the important files are running during the scan so u can deltete the infected one

      turning off the system restore prevents the infections from coming back.

      if its a trojan than dl and update ewido and run it in sade mode

      http://www.ewido.net/en/download/

      post the results
      Here's 3 sure ways of deleting any locked file in Windows....
      1.Taskmanager
      1)bring up taskmanager...2)go to processes...3)right click on explorer,and in the context menu,SELECT END PROCESS...4)click on file,on top,and select New Task Run...5)in the new pop up window select browse,and browse to the file,right click on it and see if you can delete it...6)
      2.Unlocker
      If that doesnt work,download a small very usefull app,called 'Unlocker'...after installation,right click on that stubborn file,and select unlocker in the context menu...a window will pop up...at the bottom is a drop down window....select 'delete'...then select 'unlock all' on the right hand side...if that doesnt work then go thru steps 1 - 6 on top but this time use unlocker when you right click on the file,and do everything i mentioned on top concerning the 'unlocker' app....
      Hope this works for you..if it doesnt,i'll post anotherHold on a sec, if i'm not mistaken, this topic is two years old?

      The OP isn't even here anymore...

      2582.

      Solve : Stubborn Rootkit - Need Advice?

      Answer»

      I have Dell Celeron 1.7 PC w/ 512MB, 40GB HDD, running XP SP2. The PC is in pretty bad shape. I usually use the standalone scanner from Kaspersky (available in devbuilds) and Super Antispyware to clean up pretty much every infection on a PC. Not working this time.

      Kaspersky flagged a bunch of Hidden.Object.xxxx items that it couldn't delete, heal, or quarantine. So I downloaded Rootkit Revealer, Blacklight, RootKitty, PAR, & SAR. Rootkit Revealer showed 20+ items. Blacklight found 5 but didn't fix them. Haven't run RootKitty or PAR yet and SAR found 37 items, 1/2 couldn't be deleted or fixed, the other half it recommended not to fix.

      So . . I'm out of ideas. In the meantime I have used CCleaner to clean all user's accounts, prefetch, etc.. Turned off system restore and hibernation (to eliminate their stores), added Ad-Aware 2008, Counterspy V2 (which won't update) and a couple of other things.

      Super AS needed manual updating, it was blocked. Ad-Aware needed manual updating, it was blocked. Counterspy can't be manually updated as far as I can tell because it, too, is blocked. Hijack This won't even run.

      I've never seen anything so vicious. These are my best tools. For the record the spyware programs are addressing a search engine hijack, and a rooted out a mess of other spyware and trojans. I suspect the rootkits are allowing the trojans in and the search engine hijack isn't the result of spyware.

      There's too much on this PC to reformat so what I'm wondering is 1: any other ideas? and 2: Will an XP repair installation overwrite the hooked files in the install directory and the registry??

      I have done a LOT of work in Safe Mode and still others in Windows after using Code Stuff Starter to disable almost everything from starting with the PC (aside from essential Windows files). I'm seeing progress but not what I expected (especially given that those files and keys IDENTIFIED as rootkits are still in place)

      Thanks for any light you can shed.

      PoNot being a Malware Specialist...one should be along, hopefully soon...

      Have you tried any of the free online scans out there such as Trend Micro's HouseCall? The online scan takes a while to update and scan...but it may help. At least it could get you to a point where you'll be able to download, run and post a HijackThis log file.

      Trend Micro HouseCallNope - online functionality is sketchy at best right now. Housecall is on my list of tools to use but not in this case. Thanks for the reply.

      PoRestart in Safe Mode with Networking, and see, if you can update/run Superantispyware from there.

      While there, try:
      Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and FOLLOW the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click FINISH.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      Eventually, try to run HJT in Safe Mode.
      Internet activity in Safe Mode ain't great either. I did most everything Safe Mode before I had to run the Rootkit programs (Blacklight first and that prompts you to run in a standard Windows environment.)

      Funny that you mentioned the Malwarebytes program. I ran across it last night. I'm interested in trying it. Also going to try to hunt down the Ewido standalone scanner. I had a jump drive with tons of stuff configured to run (portable) and lost it so I've been scraping together what I can and installing it . . . what a waste of time.

      Anyway all programs but Counterspy were updated manually. I'll let you know what Malwarebytes does tonight. Also let you know what HJT finds but I've been using it since the Merijn days so I don't need to post.

      I DO need to know if a repair install of Windows will overwrite the registry and system hooks that are currently victims of the rootkits. Any ideas.

      Thanks for helping guys.

      MattRun the F-Secure online scan for Viruses, Spyware and RootKits:

      This scanner works with Internet Explorer only

      • Go to the F-Secure Online Virus Scanner
      • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
      • Allow the Active X control to be installed on your computer, then click the Accept button
      • Click Full System Scan and allow the components to download and the scan to complete.
      • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
      • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
      • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
      If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
      • When the cleaning option is presented, Uncheck Submit samples to F-Secure
      • Click Automatic cleaning
      • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
      • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post along with a fresh HijackThis log.
      Note:
      • This scan will only work with Internet Explorer
      • You must have administrator rights to run this scan
      • This scan can take over an hour so please be patient
      2583.

      Solve : virus/trojan keep coming back after been deleted by Nod32 & Spybot?

      Answer» GLAD it all WORKED out.

      Safe SURFING....
      2584.

      Solve : Keylogger Help?

      Answer»

      Hi, I FOUND a keylogger called elite keylogger. I know who sent it to me, but I would like proof. Does anyone know how I can find the logs that were sent or a way to figure out which email MESSAGE it was in? thanksTo get something installed through email, you had to perform some action, like opening an attachment. Keyloggers don't install by themselves.
      You can blame only yourself.
      What kind of security protection do you have on your computer?Elite Keylogger is a COMMERCIAL product.

      We will need much more information "if" we do help you remove it.

      Who's PC is this?
      How do you know it's there?
      Do you have administrator rights on the PC?If you have avast or a usb flash DRIVE that can launch programs install avast to it an it should remove it. Note virus scanner problems if more then one is installed on the pc. Spybot is another program that should remove it. Quote from: evilfantasy on June 19, 2008, 06:55:49 PM

      Elite Keylogger is a commercial product.

      Keyloggers, especially commercial one are notoriously hard to remove.

      We need to be sure this wasn't installed by a parent or employer before advising on it's removal.

      My first instinct is to SAY contact http://www.widestep.com/ and have them help you.
      2585.

      Solve : SPYWARE.CYBERLOG-X.SPYWARE?

      Answer»

      HOW CAN I GET THIS OFF MY DELL B130 LAPTOP RUNNING WINDOWS XP. i CANNOT GET INTO THE ADD OR REMOVE PROGRAM OR THE REGISTRY, OR COPY OR LOAD ANYTHING TO MY COMPUTERTurn CAPS off, please...

      PRINT these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by SELECTING "Check for Updates". (If you encounter any problems while downloading the updates, MANUALLY download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      PHYSICALLY DISCONNECT FROM THE INTERNET

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and REMOVAL is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RECONNECT TO THE INTERNET

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.Sorry for the caps. I downloaded the file that you instructed me to. I cannot get on the internet with the infected laptop. I tried to load it from a thumb drive on to the infected laptop but it will not let me. Quote

      I tried to load it from a thumb drive on to the infected laptop but it will not let me.
      Please, explain what exactly happens.
      Try Safe Mode.when I click on the file the hour glass comes up like its loading and nothing happens after that. When I try to drag the file to the desktop it will not drag. I have tried this in the normal mode and in the safe mode. I might have to try to reformat the hard drive but I want that to be my last option. Try Windows repair: http://www.michaelstevenstech.com/XPrepairinstall.htmOkay, I have gotten it to load by using the dos command prompts and COPYING the superantispyware.exe file to the c directory from the d drive.OK.
      2586.

      Solve : My computer randomly freezes up on me :(?

      Answer»

      still messed up, its guaranteed to freeze while i burn MOVIES only, every now and then it will freeze for the *censored* of it, i have a trojan remover i run that doesnt find anything but SPYBOT s&d finds the same stuff over and overTry burning at lower speed.still no luck, tried burning at the lowest speed/quality possible, this is the 2nd software i've used due to the freezing problem, thinking it ORIGINATED from the first dvd converter tool, so i KNOW it is because of the burner softwareIf I were you, I'd get another 512MB of RAM.

      2587.

      Solve : Restrictions on computer apeared out of nowhere?

      Answer»

      HI there,

      I was surfing the Net last night, my explorer crashed so bad that I NEEDED to restart. The restart went fine but once I wanted to change my preference on my desktop ( right clip on desktop and clic on preference) There is a box msg that pop up restraining me from opening the preference page.

      The box title is: Restrictions

      A big X in a red circle is next to this description : This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator.

      Then there is the ok botton.

      ( Whenever I close it, it reapear once )

      I noticed also that the control panel was gone from my start menu...

      I did all the steps asked prior to post and here the results of the scans...

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 06/22/2008 at 02:39 PM

      Application Version : 4.15.1000

      Core Rules Database Version : 3487
      Trace Rules Database Version: 1478

      Scan type : Complete Scan
      Total Scan Time : 00:29:39

      Memory items scanned : 396
      Memory threats detected : 0
      Registry items scanned : 3888
      Registry threats detected : 102
      File items scanned : 32411
      File threats detected : 20

      Unclassified.Unknown Origin
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

      Trojan.Unknown Origin
      c:\z_Drivers
      C:\WINDOWS\..\z_Drivers

      Trojan.MSDirect
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC#NextInstance
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#Service
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#Legacy
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#ConfigFlags
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#Class
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#ClassGUID
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DNLSVC\0000#DeviceDesc
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT#NextInstance
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#Service
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#Legacy
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#ConfigFlags
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#Class
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#ClassGUID
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#DeviceDesc
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000#Capabilities
      HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECT\0000\Control
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#Type
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#Start
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#ErrorControl
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#ImagePath
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#DisplayName
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc#ObjectName
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Security
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Security#Security
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Enum
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Enum#0
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Enum#Count
      HKLM\SYSTEM\CurrentControlSet\Services\dnlsvc\Enum#NextInstance
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect#Type
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect#Start
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect#ErrorControl
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect#ImagePath
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect#DisplayName
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Security
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Security#Security
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Enum
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Enum#0
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Enum#Count
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Enum#NextInstance
      HKLM\SYSTEM\CurrentControlSet\Services\msdirect\Enum#INITSTARTFAILED

      Trojan.SystemDriver
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#DriverLoad
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#DriverCheck
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#SystemDriverLoad
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost1
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost2
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost3
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost4
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#DriverLoad
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#DriverLoad
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#DriverCheck
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#DriverCheck
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#SystemDriverLoad
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#SystemDriverLoad
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#SystemDriver
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#SystemDriver
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#FDriver
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#FDriver
      HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#ADriver
      HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#ADriver
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#ADriver
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#CDriver [ c:\z_Drivers\svchost.exe ]
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#DDriver [ c:\z_Drivers\svchost.exe ]
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#FDriver
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#SystemDriver
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#alpha [ c:\z_Drivers\svchost.exe ]
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#beta [ c:\z_Drivers\svchost.exe ]
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#gamma [ c:\z_Drivers\svchost.exe ]

      Trojan.VideoCach/Gen
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\0
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\0\win32
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\FLAGS
      HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\HELPDIR
      HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
      HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid
      HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32
      HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib
      HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib#Version
      HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
      HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid
      HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32
      HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib
      HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib#Version

      Trojan.Unclassified/MSCompare
      HKCR\MsCmp1.BhoApp
      HKCR\MsCmp1.BhoApp\CLSID
      HKCR\MsCmp1.BhoApp\CurVer
      HKCR\MsCmp1.BhoApp.1
      HKCR\MsCmp1.BhoApp.1\CLSID
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare#DisplayName
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare#UninstallString
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare#DisplayIcon
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare#DisplayVersion
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mscompare#EstimatedSize

      Adware.Tracking Cookie
      C:\Documents and Settings\LocalService\Cookies\[emailprotected]*censored*-private[1].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt

      Trojan.Unclassified/MSCompare-Installer
      C:\SYSTEM VOLUME INFORMATION\_RESTORE{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP20\A0008739.EXE

      Trace.Known Threat Sources
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\B7K51QHK\go[1].htm
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OJ56YQU1\g_default[1].gif
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OJ56YQU1\sunnyvidall.wmv[1].jpg
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\03FXJEB2\red_btn[1].gif
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\03FXJEB2\Blonde_chick_swallowing_dick_large[1].jpg
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OJ56YQU1\terrisummersbgvid008.wmv[1].jpg




      Malwarebytes' Anti-Malware 1.18
      Database version: 880

      3:00:53 PM 22/06/2008
      mbam-log-6-22-2008 (15-00-53).txt

      Scan type: Quick Scan
      Objects scanned: 39735
      Time elapsed: 6 minute(s), 41 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 1
      Files Infected: 3

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      C:\Program Files\syscmd (Trojan.BHO) -> Quarantined and deleted successfully.

      Files Infected:
      C:\Program Files\syscmd\mscmp.inf (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\Program Files\syscmd\uninstall.bat (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\WINDOWS\inf\ultra.PNF (Malware.Trace) -> Quarantined and deleted successfully.



      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 3:13:38 PM, on 22/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Acer\eManager\anbmServ.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\keyhook.exe
      C:\Program Files\Arcade\PCMService.exe
      C:\Program Files\Launch Manager\QtZgAcer.EXE
      C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Windows Live\MESSENGER\MsnMsgr.Exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\LimeWire\LimeWire.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\Program Files\acer\eRecovery\Monitor.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
      F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
      O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207390382000
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=21871
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google UPDATER Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

      --
      End of file - 6431 bytes
      I'm going at sea for 5 days (work) on Monday, so if I'm not replying right away it means that I dont have access to this web site from work. If you could also send me the information on my work e-mail so I can try stuff when I'm sailling that would be great. heres my work email : email address removed due to security reasons1. Print this post out, since you won't have an access to it, at some point.

      2. Close all windows, except for HijackThis.

      3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

      - F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
      - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      - *O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      - *O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      - *O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
      - O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

      4. Click on Fix checked button.

      5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

      6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

      7. Delete following files/folders (if present):

      - shell.exe file from C:\WINDOWS

      8. Restart in Normal Mode.

      9. Post new HijackThis log.I noticed in Safe mode that I had an administrator accound and I dont recall setting up one... I had the choise between Administrator and Xartaf ( the only one supesed to be there.) It doesnt appear on the normal start up and I cant see it since I dont have access to control panel... I tought it might be usefull to let you know. and by the way Thx for you time it is very nice for you to do this!

      Here is the new scan.


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 4:20:20 PM, on 22/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\Program Files\AVG\AVG8\avgrsx.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Acer\eManager\anbmServ.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\keyhook.exe
      C:\Program Files\Arcade\PCMService.exe
      C:\Program Files\Launch Manager\QtZgAcer.EXE
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\acer\eRecovery\Monitor.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe
      C:\WINDOWS\system32\wuauclt.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
      O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207390382000
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=21871
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

      --
      End of file - 5514 bytes
      Your computer is clean

      1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
      Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
      Run CCleaner.

      2. Turn off System Restore:

      - Windows XP:
      1. Click Start.
      2. Right-click the My Computer icon, and then click Properties.
      3. Click the System Restore tab.
      4. Check "Turn off System Restore".
      5. Click Apply.
      6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
      7. Click OK.
      - Windows Vista:
      1. Click Start.
      2. Right-click the Computer icon, and then click Properties.
      3. Click on System Protection under the Tasks column on the left side
      4. Click on Continue on the "User Account Control" window that pops up
      5. Under the System Protection tab, find Available Disks
      6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
      7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
      8. Click OK

      3. Restart computer.

      4. Turn System Restore on.

      5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

      6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

      7. Let me know, how your computer is doing. Still no access to Control Panel?
      I cant get to the propreties of My computer. The restriction is still there... Should I try to go on Save mode again and try to figure out the hole administrator account that only shows there? Try to make it available to the normal mode... to awser your question I still dont have access to control panel.Download, and run Remove Restrictions Tool: http://www.raymond.cc/blog/archives/2007/06/28/restore-task-manager-regedit-and-folder-options-disabled-by-virus/The last program that you got me to install did the job perfectly. Now I have full access back.

      Thank you so much for your help and your time! You're very welcome
      Happy computing!

      2588.

      Solve : Malware Assistance??

      Answer»

      I apologize. I forgot, you're with Vista.
      Right click on AVG systray icon, click "Open AVG User Interface "Click on "Computer scanner" tab, then "SCAN history" button. You should SEE your latest scans there.
      Look under "Scan log information" column.Under the 'scan log information column' there are several 'scan was interrupted before completion's, but for the majority of scans this field is blank.Highlight the latest scan, and at the bottom, you'll see a link to save report.Scanlog attached

      [recovering disk space -- attachment deleted by admin]Well, it looks like AVG did pretty good job, so other scans came up clean...

      Your computer is clean

      1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
      Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
      Run CCleaner.

      2. Turn off System Restore:

      - Windows XP:
      1. Click Start.
      2. Right-click the My Computer icon, and then click Properties.
      3. Click the System Restore tab.
      4. Check "Turn off System Restore".
      5. Click Apply.
      6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
      7. Click OK.
      - Windows Vista:
      1. Click Start.
      2. Right-click the Computer icon, and then click Properties.
      3. Click on System Protection under the Tasks column on the left side
      4. Click on Continue on the "User Account Control" window that pops up
      5. Under the System Protection tab, find Available Disks
      6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
      7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
      8. Click OK

      3. Restart computer.

      4. Turn System Restore on.

      5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

      6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

      7. Let me know, how your computer is doing.
      I followed all of the steps in the previous post, and then ran an AVG scan which seems to have found all of the same threats again.

      New Scanlog attached.

      [recovering disk space -- attachment deleted by admin] Download SpywareBlaster - SECURE your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      *Using SpywareBlaster to protect your computer from Spyware and Malware
      *If you don't know what ActiveX controls are, see hereOn the 10th I installed SpywareBlaster and SpywareGuard, after uninstalling SpywareTerminator. I wasn't sure whether or not they could all run together. SpywareGuard didn't seem to be working correctly (Vista). So on the 12th I UNINSTALLED SpywareGuard and reinstalled SpywareTerminator. I thought I had SpywarBlaster set up correctly, and don't ever use IE unless I have to. I'm running all of the scans over again. At one time SpywareGuard was a good program but it has been abanded and not updated in years.

      Many of the web pages we visit use ActiveX controls, only you seem to be running in to a lot of really bad ones. I think that the web history is whats being deleted and the malware isn't actually being installed.If you look closely at the log, no actual infection happened. These are all warnings about ActiveX, as evil said.
      You may try Firefox, which doesn't use ActiveX.I use Firefox nearly exclusively and have for some time. I'm certain this machine is infected. Using Wireshark I captured IGMP packets going to multicast IP's with a malicious reputation (Trusted Source). It's no longer connected to the internet. After removing the same ActiveX for the second time, I got it a third time without even opening IE and only having excepted cookies in Firefox from a few familiar sites. Our scans do not indicate any infection.Ok, maybe not an infection, but there is an apparent vulnerability. I am now blocking cookies though and have switched to Avast. All scans have been clear. I wonder if these were false positives. Avast finds nothing. I may REINSTALL AVG to find out. Thanks for your assistance.Quote

      I wonder if these were false positives.
      Very possible.
      Quote
      Avast finds nothing. I may reinstall AVG to find out.
      I wouldn't do it. Current AVG 8.0 is having numbers of problems. Avast is an excellent AV program. Using it myself.
      2589.

      Solve : suspected virus help?

      Answer»

      HelloEverybody
      Help help help !!!
      I am running xp sp2 and having a problem with my internet acct.(extra charges for over usage) My ISP suggested using netstat command which generated a list of open tcp and vdp addresses. What the heck is this stuff? If its not good could anybody help me get rid of it?
      I have Norton a/v and ad- aware running and both are reporting no problems.
      I am running a wireless home network that was not secure until yesterday.
      Is this a virus ?? If so helpDownload HijackThis:
      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
      Click on Download HijackThis Installer
      Post HijackTHis log.Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 1:23:33 AM, on 13/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\UPHClean\uphclean.exe
      C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Windows Live\Family Safety\fssui.exe
      C:\Program Files\Pure Networks\Network Magic\nmapp.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Corel\Graphics8\Programs\MFIndexer.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
      C:\Program Files\Winter Fun Pack 2004 for Windows XP\WinterWallToy\WinterWalltoy.exe
      C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\WISPTIS.EXE
      C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wtccommunications.ca/mywtc/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.logitech.com/?BW=2&OS=05.01.2600&L=1033&LV=02.52.0021&LG=enu&PI=SP&CT=D
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [AttuneClientEngine] C:\PROGRA~1\Aveo\Attune\bin\attune_ce.exe
      O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
      O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - Global Startup: Logitech SetPoint.lnk = ?
      O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
      O4 - Global Startup: Winter Fun Wallpaper Changer.lnk = ?
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live FAVORITES - http://favorites.live.com/quickadd.aspx
      O8 - Extra context menu item: E&xport to Microsoft EXCEL - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
      O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

      --
      End of file - 10626 bytes
      thanks ever so much for all your help people

      mikroI'm afraid, I misread your post.
      You're charged for overusing your connection? Please explain, what KIND of limits your account has.
      ISP asked you to use netstat, probably to see, if maybe someone else is using your connection. Since your connection wasn't secure, it might have happened.

      BTW, what's your antivirus program? I can see some Norton services running, but antivirus seems to be inactive.
      What about firewall?Hi
      My connection allows me 2gb per month which has been great until the last two months that my kids have been home from school.They watch the odd u tube video but not enough to explain the usage I have been charged. Because the usage was still climbing I tried disabling the network cards on thier laptops and the usage is still increasing daily. Thus a call to my ISP got me the suggestion to use the netstat command. When I first called they said to secure the network and that there was over 100 IP addresses running on my network. I am using Norton Internet security set for automatic updates. Windows firewall is disabled and am running Norton firewall.All areas of Norton are showing secure with no problems.Quote

      there was over 100 IP addresses running on my network
      You said, that you secured your network since...Still same problem?Yes it seems to be still increasing. I am wondering if it is because of things set for automatic updates? I have no idea. I am now at 2.96gb up from 2.3 this morning
      What does netstat command say?Microsoft Windows XP [Version 5.1.2600]
      (C) Copyright 1985-2001 Microsoft Corp.

      C:\Documents and Settings\User>netstat -an

      Active Connections

      Proto Local Address Foreign Address State
      TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
      TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
      TCP 0.0.0.0:1196 0.0.0.0:0 LISTENING
      TCP 127.0.0.1:1059 0.0.0.0:0 LISTENING
      TCP 127.0.0.1:1067 0.0.0.0:0 LISTENING
      TCP 127.0.0.1:1907 127.0.0.1:1067 TIME_WAIT
      TCP 127.0.0.1:1912 127.0.0.1:1913 ESTABLISHED
      TCP 127.0.0.1:1913 127.0.0.1:1912 ESTABLISHED
      TCP 127.0.0.1:1914 127.0.0.1:1915 ESTABLISHED
      TCP 127.0.0.1:1915 127.0.0.1:1914 ESTABLISHED
      TCP 192.168.0.100:139 0.0.0.0:0 LISTENING
      TCP 192.168.0.100:1920 72.5.252.2:80 TIME_WAIT
      UDP 0.0.0.0:67 *:*
      UDP 0.0.0.0:68 *:*
      UDP 0.0.0.0:138 *:*
      UDP 0.0.0.0:445 *:*
      UDP 0.0.0.0:1043 *:*
      UDP 0.0.0.0:1085 *:*
      UDP 0.0.0.0:1127 *:*
      UDP 0.0.0.0:1144 *:*
      UDP 0.0.0.0:1145 *:*
      UDP 0.0.0.0:1146 *:*
      UDP 0.0.0.0:1147 *:*
      UDP 0.0.0.0:1148 *:*
      UDP 0.0.0.0:1196 *:*
      UDP 0.0.0.0:9370 *:*
      UDP 127.0.0.1:1084 *:*
      UDP 192.168.0.100:137 *:*
      UDP 192.168.0.100:138 *:*

      C:\Documents and Settings\User>It looks normal. The only established connection is your own COMPUTER (127.0.0.1).
      I guess, your kids are downloading stuff.Thanks very much for all your help.
      As I mentioned in an earlier post before I secured the network my isp said there was over 100 IP addresses open. I geuss you live and learn!
      Again thanks a million for all your time and help it is much appreciated
      Have a great daySame to you
      2590.

      Solve : winowl32.dll and file destroying?

      Answer»

      Hi, I wanna destory winowl23.dll because it's messing up my PC.

      I can't because it's being "used" by something, how can I stop it from being used so I can destroy it???

      HELP... I only just got this PC today! Wait a sec. You got computer today, and it's already messed up? Maybe you should go back to the store?
      Are you sure about that file spelling?
      What's EXACT error?I tried to DOWNLOAD something, I guess that's what it was... in any case.

      I believe it's causing my PC to boot up weirdly... and yes, it's called winowl32.dll


      All I want to know is how to destory a file... I don't care if it's being used or not! This is killing me!What was "something", and where from?

      Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      PHYSICALLY DISCONNECT FROM THE INTERNET

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control TAB.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be PATIENT while it scans your computer.
      * After the scan is complete, a Scan Summary BOX will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to REBOOT, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RECONNECT TO THE INTERNET

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      2591.

      Solve : Logs attached, need next step for malware fix?

      Answer»

      OK do you still get the error?

      Do you have your Windows install CD?HI--I'm going away out of the country until JAN 11, and I won't have access to this machine (no remote access either). SO, I'll pick up with this when I return! THANKS so far!!

      Have a happy new year!! oh and oops I didn't see your past post--
      No, unfortunately I don't have the Windows Install CD. I content my husband lost it.
      Otherwise, I'd have reinstalled a *long* time ago...
      I'd rather not upgrade to VISTA either, as I prefer XP for now, if I can help it...

      ok, my plane leaves soon, so I'm shutting down...

      Thanks again, and I'll post when I get back, to see if there's anything else I can do to get that windows security system firewall thing installed, and the Add/Remove Hardware option to come back again...

      cheers
      ginaHello,

      I'm back.

      Reminder of where I am: I did the CFScript above, and attached the log.
      I don't have my Windows XP installation CD. I hope that will not be a deal-breaker. (I really don't want to change to Vista...)

      The windows security alert "red X" icon still appears at the bottom, and when I click it, it still says,

      "Windows cannot find 'rundll32.exe'. Make sure you typed the name correctly..."

      Is there anything else I can do?

      Thanks again!Oh yeah, and to be clear, I should also mention this:

      I did *not* get as far as running the IE-only-based scan mentioned above.

      This is because I didn't get beyone the first step of removeing Avast, because I cannot access the Add/Remove Programs function via control panel.

      I didn't want to skip any steps...

      Thanks

      Do a system restore to before you ran ComboFix. Then run ComboFix again and post the log.I did a system restore to Dec 29. That was the only option. So, we may need to re-do several of the steps again...

      Here is the Combofix Log:

      ComboFix 09-01-10.01 - HP_Administrator 2009-01-10 11:30:26.2 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.456 [GMT -8:00]
      Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
      AV: avast! antivirus 4.8.1296 [VPS 090110-0] *On-access scanning disabled* (Updated)
      AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated)
      FW: Norton Internet Security 2006 *enabled*
      FW: Norton Internet Worm Protection *disabled*
      * Created a new restore point
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\windows\system32\java2.sys c:\windows\system32\snjava.dll
      c:\windows\system32\mfcans32.DLL
      c:\windows\system32\mfcuia32.dll
      c:\windows\system32\msrdo20.dll
      c:\windows\system32\rdocurs.dll

      .
      ((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
      .

      2009-01-10 10:46 . 2009-01-10 10:46d--------c:\program files\Java
      2009-01-10 10:45 . 2009-01-10 10:45d--------c:\documents and settings\HP_Administrator\Application Data\Symantec
      2009-01-10 10:45 . 2009-01-10 10:45d--------c:\documents and settings\All Users\Application Data\Symantec
      2009-01-10 09:26 . 2009-01-10 10:44d--------C:\ComboFix(2)
      2008-12-30 15:28 . 2008-12-30 15:28d--------C:\rsit
      2008-12-30 15:18 . 2009-01-10 10:44d--------c:\windows\system32\CatRoot2
      2008-12-30 14:44 . 2008-12-30 14:44d--------C:\_OTMoveIt
      2008-12-30 14:04 . 2008-12-30 14:04d--------c:\documents and settings\All Users\Application Data\NortonInstaller
      2008-12-29 23:53 . 2009-01-10 10:45d--------c:\program files\Java(2)
      2008-12-29 23:49 . 2009-01-10 10:48d--------c:\program files\SUPERAntiSpyware
      2008-12-29 23:49 . 2008-12-29 23:49d--------c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
      2008-12-29 22:45 . 2008-12-29 22:491,393--a------c:\windows\imsins.BAK
      2008-12-29 22:27 . 2008-09-04 09:151,106,944---------c:\windows\system32\dllcache\msxml3.dll
      2008-12-29 22:27 . 2008-10-24 03:21455,296---------c:\windows\system32\dllcache\mrxsmb.sys
      2008-12-29 17:09 . 2008-12-29 17:09d--------c:\program files\4U Computing
      2008-12-29 17:09 . 2005-04-18 11:212,564,096--a------c:\windows\system32\NCTAudioCompress3.dll
      2008-12-29 17:09 . 2005-04-14 19:072,260,992--a------c:\windows\system32\NCTVideoCompress.dll
      2008-12-29 17:09 . 2005-04-13 11:321,810,432--a------c:\windows\system32\NCTAudioCompress2.dll
      2008-12-29 17:09 . 2005-04-21 18:231,245,184--a------c:\windows\system32\NCTRMFile.dll
      2008-12-29 17:09 . 2005-04-18 19:01991,232--a------c:\windows\system32\NCTVideoCoreM.dll
      2008-12-29 17:09 . 2005-04-14 19:05294,912--a------c:\windows\system32\NCTAVIFile.dll
      2008-12-29 17:09 . 2005-04-21 17:15282,624--a------c:\windows\system32\NCTQuickTimeFile.dll
      2008-12-29 17:09 . 2003-05-22 00:50261,632--a------c:\windows\system32\mcdvd_32.dll
      2008-12-29 17:09 . 2005-04-14 19:06196,608--a------c:\windows\system32\NCTWMVFile.dll
      2008-12-29 17:09 . 2005-04-18 15:14139,264--a------c:\windows\system32\NCTVideoFile.dll
      2008-12-29 17:09 . 2005-03-03 17:18106,496--a------c:\windows\system32\NCTVideoCoreU.dll
      2008-12-29 02:21 . 2008-12-29 02:21d--------c:\program files\Trend Micro
      2008-12-29 02:05 . 2008-12-29 02:27664--a------c:\windows\system32\d3d9caps.dat
      2008-12-29 01:13 . 2008-10-16 14:0723,576--a------c:\windows\system32\wuapi.dll.mui
      2008-12-29 00:56 . 2008-12-29 01:02d--------c:\program files\SpywareBlaster
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\program files\Malwarebytes' Anti-Malware
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-12-29 00:30 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys
      2008-12-29 00:30 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys
      2008-12-28 14:07 . 2008-12-28 14:07d--------c:\program files\CCleaner
      2008-12-28 02:24 . 2008-12-28 02:24d--------c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDMwOTY3MTJ8_
      2008-12-28 02:18 . 2008-12-28 02:1882,944--a------c:\windows\system32\bgl.exe
      2008-12-28 02:07 . 2008-12-28 02:07d--------C:\VundoFix Backups
      2008-12-27 19:46 . 2008-12-27 19:4640,448--a------c:\windows\system32\k9261108.exe
      2008-12-10 13:04 . 2008-12-10 13:05d--------c:\windows\system32\Adobe

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M REPORT ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-01-10 18:45---------d-----wc:\program files\Common Files\Symantec Shared
      2008-12-30 23:11---------d-----wc:\documents and settings\HP_Administrator\Application Data\U3
      2008-12-30 22:13---------d---a-wc:\documents and settings\All Users\Application Data\TEMP
      2008-12-30 00:46---------d-----wc:\documents and settings\HP_Administrator\Application Data\NCH Swift Sound
      2008-12-29 08:55---------d-----wc:\program files\Common Files\Wise Installation Wizard
      2008-12-28 22:15---------d-----wc:\program files\WildGames
      2008-12-28 22:14---------d-----wc:\documents and settings\All Users\Application Data\WildTangent
      2008-12-28 10:27---------d-----wc:\program files\Alawar
      2008-12-28 00:0312,489,550----a-wc:\program files\PROCESSLIST.DB
      2008-12-28 00:031,107,211----a-wc:\program files\PROCESSLISTRELATED.DB
      2008-12-11 20:18---------d-----wc:\documents and settings\All Users\Application Data\BigFishGamesCache
      2008-12-04 09:4759,856----a-wc:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
      2008-11-27 20:41---------d-----wc:\program files\bfgclient
      2008-11-15 02:03---------d-----wc:\documents and settings\All Users\Application Data\AlawarWrapper
      2008-11-14 08:13---------d-----wc:\documents and settings\HP_Administrator\Application Data\PlayFirst
      2008-11-14 08:13---------d-----wc:\documents and settings\All Users\Application Data\PlayFirst
      2008-11-10 02:11---------d-----wc:\program files\Spybot - Search & Destroy
      2008-03-28 21:530----a-wc:\program files\temp01
      2008-02-20 18:00168----a-wc:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
      2007-10-05 13:39110----a-wc:\documents and settings\All Users\Application Data\MostFunGameId.bin
      2006-12-01 03:468----a-wc:\documents and settings\HP_Administrator\Application Data\usb.dat.bin
      2006-11-09 07:34774,144----a-wc:\program files\RngInterstitial.dll
      2008-09-07 08:03122,880----a-wc:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
      2008-11-11 20:2867,696----a-wc:\program files\mozilla firefox\components\jar50.dll
      2008-11-11 20:2854,376----a-wc:\program files\mozilla firefox\components\jsd3250.dll
      2008-11-11 20:2834,952----a-wc:\program files\mozilla firefox\components\myspell.dll
      2008-11-11 20:2846,720----a-wc:\program files\mozilla firefox\components\spellchk.dll
      2008-11-11 20:28172,144----a-wc:\program files\mozilla firefox\components\xpinstal.dll
      .

      ((((((((((((((((((((((((((((( [emailprotected]_23.44.12.71 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2009-01-10 19:49:244,096----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\_qol1q67.dll
      + 2009-01-10 19:49:233,072----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\crsofd0p.dll
      + 2009-01-10 19:49:2424,576----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\uepzthil.dll
      - 2008-11-10 02:26:58224,816----a-wc:\windows\system32\FNTCACHE.DAT
      + 2009-01-10 18:48:08224,816----a-wc:\windows\system32\FNTCACHE.DAT
      + 2009-01-10 18:47:001,793,884----a-wc:\windows\system32\Restore\rstrlog.dat
      + 2009-01-10 19:49:2016,384----atwc:\windows\Temp\Perflib_Perfdata_280.dat
      + 2009-01-10 19:44:1616,384----atwc:\windows\Temp\Perflib_Perfdata_640.dat
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-11 136600]
      "Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-13 663552]
      "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
      "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
      "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
      "HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
      "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-11 49152]
      "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-07 29744]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
      "DISCover"="c:\program files\DISC\DISCover.exe" [2007-10-30 1095256]
      "Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
      "CitiVAN"="c:\program files\Citi Virtual Account Numbers\CitiVAN.exe" [2004-08-12 192512]
      "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
      "SoundMan"="SOUNDMAN.EXE" [2005-09-21 c:\windows\SOUNDMAN.EXE]
      "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
      "AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]

      c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
      MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-08-28 147456]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
      Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Abacast\\Abaclient.exe"=
      "c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
      "c:\\Program Files\\DISC\\DISCover.exe"=
      "c:\\Program Files\\DISC\\DiscStreamHub.exe"=
      "c:\\Program Files\\HP Rhapsody\\rhapsody.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

      R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-22 111184]
      R3 NGSSLDrv;VPN Tunnel NGSSLDrv Adapter;c:\windows\system32\drivers\NGSSLDrv.sys [2007-05-10 17632]
      R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-08-22 20560]
      S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-10-07 29744]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad445336-5ba1-11dd-bb75-00173104f808}]
      \Shell\AutoRun\command - vmyphd.bat
      \Shell\explore\Command - vmyphd.bat
      \Shell\open\Command - vmyphd.bat
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.therainforestsite.com/
      uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
      IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

      c:\windows\Downloaded Program Files\stg_drm.ocx - O16 -: {149E45D8-163E-4189-86FC-45022AB2B6C9}
      file:///C:/Program%20Files/Big%20Island%20Blends/Images/stg_drm.ocx

      c:\windows\Downloaded Program Files\MLWebCacheCleaner.DLL - O16 -: {79D6214F-CFCE-480F-9901-27950E78F1E6}
      hxxps://vpn.mirabilismedica.com/MLWebCacheCleaner.cab
      c:\windows\Downloaded Program Files\MLWebCacheCleaner.inf

      c:\windows\Downloaded Program Files\GoBitGamesPlayer.dll - O16 -: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429}
      hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
      c:\windows\Downloaded Program Files\GoBitGamesPlayer.inf

      c:\windows\Downloaded Program Files\YYGInstantPlay.ocx - O16 -: {C49134CC-B5EF-458C-A442-E8DFE7B4645F}
      hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
      c:\windows\Downloaded Program Files\YYGInstantPlay.inf

      c:\windows\Downloaded Program Files\armhelper.ocx - O16 -: {CC450D71-CC90-424C-8638-1F2DBAC87A54}
      file:///C:/Program%20Files/Big%20Island%20Blends/Images/armhelper.ocx

      c:\windows\NGUninstallVPNTunnel.exe - c:\windows\ngssldrv.txt
      c:\windows\ngssldrv.sys
      c:\windows\Downloaded Program Files\ngvpntunnel.dll
      O16 -: {DD5E6739-FDD6-4542-8940-4A4B8AB5276E}
      hxxps://vpn.mirabilismedica.com/NGVPNTunnel.cab
      c:\windows\Downloaded Program Files\NGVPNTunnel.inf

      c:\windows\Downloaded Program Files\ParkingDashWeb.1.0.0.15.dll - O16 -: {F135A813-7152-4532-AC8D-28AC2136DFC7}
      hxxp://p.playfirst.com/play/game/parking-dash/parkingdash.1.0.0.15.cab
      c:\windows\Downloaded Program Files\ParkingDashWeb.1.0.0.15.inf
      FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\c9zkmlvt.default\
      FF - prefs.js: browser.search.selectedEngine - Google
      FF - prefs.js: browser.startup.homepage -
      FF - prefs.js: keyword.URL - hxxp://toolbar.vmn.net/en/error404-dns.php?lg=en&mkt=en&type=dns&tbo=toolbar__2evmn__2enet__2fen__2foptions__2ephp&q=
      FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
      FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-01-10 11:49:59
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_USERS\S-1-5-21-607517009-3822631778-399514384-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F5C45177-1380-6595-986F-3EE98D3B3274}*]
      @Allowed: (Read) (RestrictedCode)
      @Allowed: (Read) (RestrictedCode)
      "eajamganoc"=hex:66,61,64,61,6c,68,69,69,68,70,6b,63,00,fc
      "daeagppm"=hex:64,62,6c,6f,6f,6a,64,68,70,6e,6d,6c,6c,67,64,6a,66,67,6d,69,65,
      6f,6e,65,65,64,63,6e,66,69,6e,69,62,6c,64,64,6a,68,64,63,00,00
      "iabbgflfmhmicgngef"=hex:6b,61,6e,6e,6b,61,69,6c,64,6c,64,66,66,6a,6c,6c,6b,62,
      68,6b,68,61,00,9b
      "haloolnnmkmblnhe"=hex:6b,61,6e,6e,6b,61,69,6c,64,6c,64,66,66,6a,6c,6c,6b,62,
      68,6b,68,61,00,7f
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      c:\program files\Lavasoft\Ad-Aware\aawservice.exe
      c:\program files\Alwil Software\Avast4\aswUpdSv.exe
      c:\program files\Alwil Software\Avast4\ashServ.exe
      c:\windows\system32\LEXBCES.EXE
      c:\windows\system32\LEXPPS.EXE
      c:\windows\arservice.exe
      c:\windows\ehome\ehrecvr.exe
      c:\windows\ehome\ehSched.exe
      c:\program files\Common Files\LightScribe\LSSrvc.exe
      c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      c:\windows\ehome\mcrdsvc.exe
      c:\windows\system32\dllhost.exe
      c:\program files\Dell AIO Printer A940\dlbabmon.exe
      c:\windows\ehome\ehmsas.exe
      c:\windows\system32\msiexec.exe
      c:\windows\system32\wbem\unsecapp.exe
      c:\hp\KBD\kbd.exe
      c:\program files\Java\jre6\bin\jucheck.exe
      .
      **************************************************************************
      .
      Completion time: 2009-01-10 11:53:58 - machine was rebooted
      ComboFix-quarantined-files.txt 2009-01-10 19:53:33
      ComboFix2.txt 2008-12-31 00:23:34
      ComboFix3.txt 2008-12-30 07:45:28

      Pre-Run: 173,637,173,248 bytes free
      Post-Run: 173,627,486,208 bytes free

      261--- E O F ---2008-12-30 06:49:46
      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      File::
      c:\windows\system32\bgl.exe

      Registry::
      [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad445336-5ba1-11dd-bb75-00173104f808}]

      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while DRAGGING the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

      ----------

      Run this online scan.

      This scanner requires Internet Explorer

      Use the ESET Nod32 Online Scanner

      1. Check the box next to YES, I accept the Terms of Use.
      2. Click Start
      3. When asked, allow the activex control to install
      4. Click Start
      5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
      6. Click Scan
      7. Wait for the scan to finish
      8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.


      1. The ESET scan results: This scan took 1 hr 52 minutes, and produced a file called "debuglog.txt" with only 3 lines:

      # vers_standard_module=3756 (20090110)
      # vers_arch_module=1.064 (20080214)
      # vers_adv_heur_module=1.064 (20070717)

      2. the latest ComboFix log:
      ComboFix 09-01-10.01 - HP_Administrator 2009-01-10 12:25:34.3 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.499 [GMT -8:00]
      Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
      Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
      AV: avast! antivirus 4.8.1296 [VPS 090110-0] *On-access scanning disabled* (Updated)
      AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated)
      FW: Norton Internet Security 2006 *enabled*
      FW: Norton Internet Worm Protection *disabled*
      * Created a new restore point

      FILE ::
      c:\windows\system32\bgl.exe
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\windows\system32\bgl.exe
      c:\windows\system32\java2.sys c:\windows\system32\snjava.dll

      .
      ((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
      .

      2009-01-10 10:46 . 2009-01-10 10:46d--------c:\program files\Java
      2009-01-10 10:45 . 2009-01-10 10:45d--------c:\documents and settings\HP_Administrator\Application Data\Symantec
      2009-01-10 10:45 . 2009-01-10 10:45d--------c:\documents and settings\All Users\Application Data\Symantec
      2009-01-10 09:26 . 2009-01-10 10:44d--------C:\ComboFix(2)
      2008-12-30 15:28 . 2008-12-30 15:28d--------C:\rsit
      2008-12-30 15:18 . 2009-01-10 10:44d--------c:\windows\system32\CatRoot2
      2008-12-30 14:44 . 2008-12-30 14:44d--------C:\_OTMoveIt
      2008-12-30 14:04 . 2008-12-30 14:04d--------c:\documents and settings\All Users\Application Data\NortonInstaller
      2008-12-29 23:53 . 2009-01-10 10:45d--------c:\program files\Java(2)
      2008-12-29 23:49 . 2009-01-10 10:48d--------c:\program files\SUPERAntiSpyware
      2008-12-29 23:49 . 2008-12-29 23:49d--------c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
      2008-12-29 22:45 . 2008-12-29 22:491,393--a------c:\windows\imsins.BAK
      2008-12-29 22:27 . 2008-09-04 09:151,106,944---------c:\windows\system32\dllcache\msxml3.dll
      2008-12-29 22:27 . 2008-10-24 03:21455,296---------c:\windows\system32\dllcache\mrxsmb.sys
      2008-12-29 17:09 . 2008-12-29 17:09d--------c:\program files\4U Computing
      2008-12-29 17:09 . 2005-04-18 11:212,564,096--a------c:\windows\system32\NCTAudioCompress3.dll
      2008-12-29 17:09 . 2005-04-14 19:072,260,992--a------c:\windows\system32\NCTVideoCompress.dll
      2008-12-29 17:09 . 2005-04-13 11:321,810,432--a------c:\windows\system32\NCTAudioCompress2.dll
      2008-12-29 17:09 . 2005-04-21 18:231,245,184--a------c:\windows\system32\NCTRMFile.dll
      2008-12-29 17:09 . 2005-04-18 19:01991,232--a------c:\windows\system32\NCTVideoCoreM.dll
      2008-12-29 17:09 . 2005-04-14 19:05294,912--a------c:\windows\system32\NCTAVIFile.dll
      2008-12-29 17:09 . 2005-04-21 17:15282,624--a------c:\windows\system32\NCTQuickTimeFile.dll
      2008-12-29 17:09 . 2003-05-22 00:50261,632--a------c:\windows\system32\mcdvd_32.dll
      2008-12-29 17:09 . 2005-04-14 19:06196,608--a------c:\windows\system32\NCTWMVFile.dll
      2008-12-29 17:09 . 2005-04-18 15:14139,264--a------c:\windows\system32\NCTVideoFile.dll
      2008-12-29 17:09 . 2005-03-03 17:18106,496--a------c:\windows\system32\NCTVideoCoreU.dll
      2008-12-29 02:21 . 2008-12-29 02:21d--------c:\program files\Trend Micro
      2008-12-29 02:05 . 2008-12-29 02:27664--a------c:\windows\system32\d3d9caps.dat
      2008-12-29 01:13 . 2008-10-16 14:0723,576--a------c:\windows\system32\wuapi.dll.mui
      2008-12-29 00:56 . 2008-12-29 01:02d--------c:\program files\SpywareBlaster
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\program files\Malwarebytes' Anti-Malware
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
      2008-12-29 00:30 . 2008-12-29 00:30d--------c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-12-29 00:30 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys
      2008-12-29 00:30 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys
      2008-12-28 14:07 . 2008-12-28 14:07d--------c:\program files\CCleaner
      2008-12-28 02:24 . 2008-12-28 02:24d--------c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDMwOTY3MTJ8_
      2008-12-28 02:07 . 2008-12-28 02:07d--------C:\VundoFix Backups
      2008-12-27 19:46 . 2008-12-27 19:4640,448--a------c:\windows\system32\k9261108.exe
      2008-12-10 13:04 . 2008-12-10 13:05d--------c:\windows\system32\Adobe

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-01-10 18:45---------d-----wc:\program files\Common Files\Symantec Shared
      2008-12-30 23:11---------d-----wc:\documents and settings\HP_Administrator\Application Data\U3
      2008-12-30 22:13---------d---a-wc:\documents and settings\All Users\Application Data\TEMP
      2008-12-30 00:46---------d-----wc:\documents and settings\HP_Administrator\Application Data\NCH Swift Sound
      2008-12-29 08:55---------d-----wc:\program files\Common Files\Wise Installation Wizard
      2008-12-28 22:15---------d-----wc:\program files\WildGames
      2008-12-28 22:14---------d-----wc:\documents and settings\All Users\Application Data\WildTangent
      2008-12-28 10:27---------d-----wc:\program files\Alawar
      2008-12-28 00:0312,489,550----a-wc:\program files\PROCESSLIST.DB
      2008-12-28 00:031,107,211----a-wc:\program files\PROCESSLISTRELATED.DB
      2008-12-11 20:18---------d-----wc:\documents and settings\All Users\Application Data\BigFishGamesCache
      2008-12-04 09:4759,856----a-wc:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
      2008-11-27 20:41---------d-----wc:\program files\bfgclient
      2008-11-15 02:03---------d-----wc:\documents and settings\All Users\Application Data\AlawarWrapper
      2008-11-14 08:13---------d-----wc:\documents and settings\HP_Administrator\Application Data\PlayFirst
      2008-11-14 08:13---------d-----wc:\documents and settings\All Users\Application Data\PlayFirst
      2008-11-10 02:11---------d-----wc:\program files\Spybot - Search & Destroy
      2008-03-28 21:530----a-wc:\program files\temp01
      2008-02-20 18:00168----a-wc:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
      2007-10-05 13:39110----a-wc:\documents and settings\All Users\Application Data\MostFunGameId.bin
      2006-12-01 03:468----a-wc:\documents and settings\HP_Administrator\Application Data\usb.dat.bin
      2006-11-09 07:34774,144----a-wc:\program files\RngInterstitial.dll
      2008-09-07 08:03122,880----a-wc:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
      2008-11-11 20:2867,696----a-wc:\program files\mozilla firefox\components\jar50.dll
      2008-11-11 20:2854,376----a-wc:\program files\mozilla firefox\components\jsd3250.dll
      2008-11-11 20:2834,952----a-wc:\program files\mozilla firefox\components\myspell.dll
      2008-11-11 20:2846,720----a-wc:\program files\mozilla firefox\components\spellchk.dll
      2008-11-11 20:28172,144----a-wc:\program files\mozilla firefox\components\xpinstal.dll
      .

      ((((((((((((((((((((((((((((( [emailprotected]_23.44.12.71 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2009-01-10 19:49:244,096----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\_qol1q67.dll
      + 2009-01-10 19:49:233,072----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\crsofd0p.dll
      + 2009-01-10 19:49:2424,576----a-wc:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\3d0bfd8b\a6f03149\uepzthil.dll
      - 2008-11-10 02:26:58224,816----a-wc:\windows\system32\FNTCACHE.DAT
      + 2009-01-10 18:48:08224,816----a-wc:\windows\system32\FNTCACHE.DAT
      + 2009-01-10 18:47:001,793,884----a-wc:\windows\system32\Restore\rstrlog.dat
      + 2009-01-10 20:34:3916,384----atwc:\windows\Temp\Perflib_Perfdata_648.dat
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-11 136600]
      "Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-13 663552]
      "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
      "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
      "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
      "HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
      "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-11 49152]
      "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-07 29744]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
      "DISCover"="c:\program files\DISC\DISCover.exe" [2007-10-30 1095256]
      "Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
      "CitiVAN"="c:\program files\Citi Virtual Account Numbers\CitiVAN.exe" [2004-08-12 192512]
      "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
      "SoundMan"="SOUNDMAN.EXE" [2005-09-21 c:\windows\SOUNDMAN.EXE]
      "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
      "AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]

      c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
      MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-08-28 147456]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
      Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Abacast\\Abaclient.exe"=
      "c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
      "c:\\Program Files\\DISC\\DISCover.exe"=
      "c:\\Program Files\\DISC\\DiscStreamHub.exe"=
      "c:\\Program Files\\HP Rhapsody\\rhapsody.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

      R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-22 111184]
      R3 NGSSLDrv;VPN Tunnel NGSSLDrv Adapter;c:\windows\system32\drivers\NGSSLDrv.sys [2007-05-10 17632]
      R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-08-22 20560]
      S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-10-07 29744]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.therainforestsite.com/
      uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
      IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

      c:\windows\Downloaded Program Files\stg_drm.ocx - O16 -: {149E45D8-163E-4189-86FC-45022AB2B6C9}
      file:///C:/Program%20Files/Big%20Island%20Blends/Images/stg_drm.ocx

      c:\windows\Downloaded Program Files\MLWebCacheCleaner.DLL - O16 -: {79D6214F-CFCE-480F-9901-27950E78F1E6}
      hxxps://vpn.mirabilismedica.com/MLWebCacheCleaner.cab
      c:\windows\Downloaded Program Files\MLWebCacheCleaner.inf

      c:\windows\Downloaded Program Files\GoBitGamesPlayer.dll - O16 -: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429}
      hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
      c:\windows\Downloaded Program Files\GoBitGamesPlayer.inf

      c:\windows\Downloaded Program Files\YYGInstantPlay.ocx - O16 -: {C49134CC-B5EF-458C-A442-E8DFE7B4645F}
      hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
      c:\windows\Downloaded Program Files\YYGInstantPlay.inf

      c:\windows\Downloaded Program Files\armhelper.ocx - O16 -: {CC450D71-CC90-424C-8638-1F2DBAC87A54}
      file:///C:/Program%20Files/Big%20Island%20Blends/Images/armhelper.ocx

      c:\windows\NGUninstallVPNTunnel.exe - c:\windows\ngssldrv.txt
      c:\windows\ngssldrv.sys
      c:\windows\Downloaded Program Files\ngvpntunnel.dll
      O16 -: {DD5E6739-FDD6-4542-8940-4A4B8AB5276E}
      hxxps://vpn.mirabilismedica.com/NGVPNTunnel.cab
      c:\windows\Downloaded Program Files\NGVPNTunnel.inf

      c:\windows\Downloaded Program Files\ParkingDashWeb.1.0.0.15.dll - O16 -: {F135A813-7152-4532-AC8D-28AC2136DFC7}
      hxxp://p.playfirst.com/play/game/parking-dash/parkingdash.1.0.0.15.cab
      c:\windows\Downloaded Program Files\ParkingDashWeb.1.0.0.15.inf
      FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\c9zkmlvt.default\
      FF - prefs.js: browser.search.selectedEngine - Google
      FF - prefs.js: browser.startup.homepage -
      FF - prefs.js: keyword.URL - hxxp://toolbar.vmn.net/en/error404-dns.php?lg=en&mkt=en&type=dns&tbo=toolbar__2evmn__2enet__2fen__2foptions__2ephp&q=
      FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
      FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-01-10 12:39:33
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_USERS\S-1-5-21-607517009-3822631778-399514384-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F5C45177-1380-6595-986F-3EE98D3B3274}*]
      @Allowed: (Read) (RestrictedCode)
      @Allowed: (Read) (RestrictedCode)
      "eajamganoc"=hex:66,61,64,61,6c,68,69,69,68,70,6b,63,00,fc
      "daeagppm"=hex:64,62,6c,6f,6f,6a,64,68,70,6e,6d,6c,6c,67,64,6a,66,67,6d,69,65,
      6f,6e,65,65,64,63,6e,66,69,6e,69,62,6c,64,64,6a,68,64,63,00,00
      "iabbgflfmhmicgngef"=hex:6b,61,6e,6e,6b,61,69,6c,64,6c,64,66,66,6a,6c,6c,6b,62,
      68,6b,68,61,00,9b
      "haloolnnmkmblnhe"=hex:6b,61,6e,6e,6b,61,69,6c,64,6c,64,66,66,6a,6c,6c,6b,62,
      68,6b,68,61,00,7f
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      c:\program files\Lavasoft\Ad-Aware\aawservice.exe
      c:\program files\Alwil Software\Avast4\aswUpdSv.exe
      c:\program files\Alwil Software\Avast4\ashServ.exe
      c:\windows\system32\LEXBCES.EXE
      c:\windows\system32\LEXPPS.EXE
      c:\windows\arservice.exe
      c:\windows\ehome\ehrecvr.exe
      c:\windows\ehome\ehSched.exe
      c:\program files\Common Files\LightScribe\LSSrvc.exe
      c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      c:\windows\ehome\mcrdsvc.exe
      c:\program files\Alwil Software\Avast4\ashMaiSv.exe
      c:\program files\Alwil Software\Avast4\ashWebSv.exe
      c:\windows\system32\dllhost.exe
      c:\program files\Dell AIO Printer A940\dlbabmon.exe
      c:\windows\ehome\ehmsas.exe
      c:\windows\system32\msiexec.exe
      c:\program files\DISC\DiscStreamHub.exe
      c:\windows\system32\wbem\unsecapp.exe
      .
      **************************************************************************
      .
      Completion time: 2009-01-10 12:44:28 - machine was rebooted
      ComboFix-quarantined-files.txt 2009-01-10 20:43:48
      ComboFix2.txt 2009-01-10 19:53:59
      ComboFix3.txt 2008-12-31 00:23:34
      ComboFix4.txt 2008-12-30 07:45:28

      Pre-Run: 173,603,606,528 bytes free
      Post-Run: 173,586,448,384 bytes free

      257--- E O F ---2008-12-30 06:49:46

      To completely remove Norton/Symantec go to add remove programs and uninstall anything with Norton, Symantec or Live Update in the name.

      Download the Norton Removal Tool (SymNRT) to your Desktop.

      Once downloaded please close ALL open browsers, also save any work because this may require a restart.

      • Go to your desktop and double click on the removal tool and then click Setup.
      • Once open Click Next
      • Accept the license agreement and click Next
      • Type in the letters/numbers that you see into the text box then click Next.
      • Then click Next and the tool will start running.
      • Once finished restart the PC and run the tool again to ensure everything has been removed.
      • Delete Nortonremoval tool from your Desktop.
      .
      ----------

      How is the computer running now?

      ,whaddya know, I think it worked
      I don't seem to have the problem with accessing the control panel anymore, and the "red X" doesn't appear at the bottom, and the SuperAntiSpyware and Malwarebytes scans come up clean...

      Anything else I need to do??

      Also, how can I make sure a paypal donation goes to you?!

      thanks
        Glad it worked. We can clean up now.

        • Click START then RUN
        • Now type Combofix /u in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.
        • The above procedure will:
        • Delete the following:
        • ComboFix and its associated files and folders.
        • Reset the clock settings.
        • HIDE file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        ----------

        Download
      ATF Cleaner by Atribune to your Desktop.

      Alternate download link

      Note: Vista users must use Run As Administrator
      • Under Main: Select Files to Delete choose: Select All.
      • Click the Empty Selected button.
      • If you use Firefox browser click Firefox at the top and choose: Select All
      • Click the Empty Selected button.
        If you would like to keep your saved passwords click No at the prompt.
      • If you use Opera browser click Opera at the top and choose: Select All
      • Click the Empty Selected button.
        If you would like to keep your saved passwords click No at the prompt.
      • Click Exit on the Main menu to close the program.
      Note that your system will run slower for a reboot or two after having used this tool so don't panic.

      ----------

      Download OTCleanIt.exe and save it to your Desktop.
      • Double-click OTCleanIt.exe.
      • Click the CleanUp! button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes, if not delete it yourself.
      Important: Restart the computer before continuing.

      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.THis is great, can't thank you enough! Excellent resources at the end, too.
      I wish everyone would use those!
      (And I wish malware writing would be illegal...)

      ANyway, thanks and be on the lookout for a donation--I wish I could afford more.

      It is illegal, but since they are usually in countries that the US, Europe, Austrailia, Canada and so on don't have any legal resources in they get away with it very easily.

      Glad it all worked!

      Safe surfing...
      2592.

      Solve : Desperately need help! PC is infected with something Nasty!?

      Answer»

      Hello, I am very happy I found this site. I have tried everything I can think of and cannot get RID of this thing. This all started after Xmas. My Gf's daughter got one of those cheap china made MP4 players for Xmas. When we installed the AVI converter that came on it ONTO my GF's computer. I noticed the computer started to be sluggish and act funny. I found out I did not have access to TASK MANAGER or REGEDIT. I then decided, Okay i'll just format. I did a quick format and had task manager back. HOWEVER, by the time I was done loading all of my programs, ( yes I do all of windows updates ) This thing had some how gotten me again. NO taskmanager or regedit. It said Task manager has been disabled by the administrator! I AM THE ADMINISTRATOR!! I've been building pc's since 98 and have NEVER had this happen. I then decided OKAY ill just do a FULL format this time. I then did a full format and loaded everything sequentially like I always do, and guess what? somehow this thing had gotten me AGAIN!!!!!! SO now I have no idea where this thing comes from or if I ever REALLY got rid of it in the first place. Could this thing be getting me Via Internet Explorer? because on this computer, thats is what I am using. I cannot run a virus scan with anti vir because when I click on the button, nothing happens. This virus will not let it run but, when I reboot the anti Vir GUARD itself shows a Sality.32 virus. I cannot go into safe mode because when I do that it flashes a blue error screen at me but its so quick I cant read it. It then proceeds to boot normally. Every TOOL that I use to try to get to this virus gets corrupted within a matter of 30 minutes or so to where the tool will not even run. SO without further delay, I only have so much hair left!! Here are some logs for you guys. and TY


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 1:25:10 PM, on 1/11/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Rainlendar2\Rainlendar2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\AIM6\aim6.exe
      C:\Program Files\Portrait Displays\ImageTune\dthtml.exe
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\Program Files\AIM6\aolsoftware.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Portrait Displays\ImageTune\dtsslsrv.exe
      C:\Program Files\Portrait Displays\ImageTune\DTSRVC.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\WINMINE.EXE
      C:\WINDOWS\explorer.exe
      C:\DOCUME~1\topaz01\LOCALS~1\Temp\icou.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
      O4 - Global Startup: ImageTune.lnk = C:\Program Files\Portrait Displays\ImageTune\dthtml.exe
      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231562677031
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Portrait Displays\ImageTune\dtsslsrv.exe
      O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\ImageTune\DTSRVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

      --
      End of file - 5451 bytes
      ComboFix 09-01-10.03 - topaz01 2009-01-11 13:32:39.3 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.824 [GMT -5:00]
      Running from: c:\documents and settings\topaz01\Desktop\ComboFix.exe
      AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
      * Created a new restore point

      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .

      ((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
      .

      2009-01-11 01:47 . 2009-01-11 01:47d--------c:\program files\Trend Micro
      2009-01-11 01:14 . 2009-01-11 01:21250--a------c:\windows\gmer.ini
      2009-01-11 01:03 . 2009-01-11 01:03d--------c:\program files\Digital Support
      2009-01-11 01:01 . 2009-01-11 01:01d--------c:\program files\Avira
      2009-01-11 01:01 . 2009-01-11 01:01d--------c:\documents and settings\All Users\Application Data\Avira
      2009-01-11 00:35 . 2009-01-11 00:35d--------c:\documents and settings\topaz01\Application Data\Digital Support
      2009-01-11 00:08 . 2009-01-11 01:30d--------c:\program files\Malwarebytes' Anti-Malware
      2009-01-11 00:08 . 2009-01-11 00:08d--------c:\documents and settings\topaz01\Application Data\Malwarebytes
      2009-01-11 00:08 . 2009-01-11 00:08d--------c:\documents and settings\All Users\Application Data\Malwarebytes
      2009-01-11 00:08 . 2009-01-04 18:3938,496--a------c:\windows\system32\drivers\mbamswissarmy.sys
      2009-01-11 00:08 . 2009-01-04 18:3915,504--a------c:\windows\system32\drivers\mbam.sys
      2009-01-10 23:58 . 2009-01-10 23:58d--------c:\documents and settings\topaz01\Application Data\Windows Search
      2009-01-10 23:29 . 2009-01-10 23:29d--------c:\windows\system32\Lang
      2009-01-10 23:29 . 2009-01-10 23:29940,794--a------c:\windows\system32\LoopyMusic.wav
      2009-01-10 23:29 . 2009-01-10 23:29146,650--a------c:\windows\system32\BuzzingBee.wav
      2009-01-10 23:29 . 2009-01-10 23:2960,416--a------c:\windows\ALCFDRTM.VER
      2009-01-10 23:29 . 2009-01-10 23:2960,416--a------c:\windows\ALCFDRTM.EXE
      2009-01-10 23:25 . 2009-01-10 23:25d--------c:\program files\Windows Defender
      2009-01-10 23:13 . 2009-01-10 23:13d--------c:\program files\Lavasoft
      2009-01-10 23:09 . 2003-06-25 16:05335,992--a------c:\windows\system32\TweakUI.exe
      2009-01-10 23:09 . 2002-06-21 15:09160,217--a------c:\windows\system32\PowerToysLicense.rtf
      2009-01-10 22:56 . 2009-01-10 22:56d--------c:\program files\Safer Networking
      2009-01-10 14:06 . 2009-01-10 14:06d--------c:\documents and settings\topaz01\Application Data\Safer Networking
      2009-01-10 14:00 . 2009-01-10 14:01d--------c:\documents and settings\topaz01\Application Data\MalwareRemovalBot
      2009-01-10 13:46 . 2009-01-10 23:13d--------c:\documents and settings\All Users\Application Data\Lavasoft
      2009-01-10 13:45 . 2009-01-10 13:45d--------c:\program files\Ventrilo
      2009-01-10 13:45 . 2009-01-10 13:45d--------c:\program files\Rainlendar2
      2009-01-10 13:45 . 2009-01-10 23:13d--------c:\program files\Common Files\Wise Installation Wizard
      2009-01-10 13:45 . 2009-01-11 10:50d--------c:\documents and settings\topaz01\.rainlendar2
      2009-01-10 13:45 . 2009-01-10 13:45262--a------c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
      2009-01-10 13:42 . 2009-01-11 01:05d--------c:\documents and settings\topaz01\Tracing
      2009-01-10 13:41 . 2009-01-10 13:41d--------c:\program files\Windows Live SkyDrive
      2009-01-10 13:41 . 2009-01-10 13:41d--------c:\program files\Windows Live
      2009-01-10 13:41 . 2009-01-10 13:41d--------c:\program files\Microsoft
      2009-01-10 13:38 . 2009-01-10 13:38d--------c:\program files\Common Files\Windows Live
      2009-01-10 13:35 . 2009-01-10 13:35d--------c:\documents and settings\topaz01\Application Data\acccore
      2009-01-10 13:34 . 2009-01-10 13:34d--------c:\program files\Common Files\AOL
      2009-01-10 13:34 . 2009-01-10 13:34d--------c:\program files\AIM6
      2009-01-10 13:34 . 2009-01-10 15:20d--------c:\documents and settings\All Users\Application Data\Viewpoint
      2009-01-10 13:34 . 2009-01-10 13:35d--------c:\documents and settings\All Users\Application Data\AOL OCP
      2009-01-10 13:34 . 2009-01-10 13:34d--------c:\documents and settings\All Users\Application Data\AOL
      2009-01-10 13:34 . 2009-01-10 13:34d--------c:\documents and settings\All Users\Application Data\acccore
      2009-01-10 13:34 . 2009-01-10 13:34462--ah-----C:\IPH.PH
      2009-01-10 13:33 . 2009-01-10 13:33d--------c:\program files\*censored* NFO Viewer
      2009-01-10 10:31 . 2009-01-11 10:41d--------c:\program files\World of Warcraft
      2009-01-10 10:31 . 2009-01-10 11:29d--------c:\program files\Common Files\Blizzard Entertainment
      2009-01-10 10:30 . 2009-01-10 10:30d--------c:\documents and settings\All Users\Application Data\Blizzard
      2009-01-10 04:42 . 2008-10-16 14:06268,648--a------c:\windows\system32\mucltui.dll
      2009-01-10 04:42 . 2008-10-16 14:0627,496--a------c:\windows\system32\mucltui.dll.mui
      2009-01-10 00:53 . 2009-01-10 13:24d--------c:\program files\Common Files\LightScribe
      2009-01-10 00:53 . 2005-04-20 06:322,916,352---------c:\windows\UNNMP.exe
      2009-01-10 00:53 . 2006-05-23 11:3047,894---------c:\windows\UNNMP.cfg
      2009-01-10 00:52 . 2009-01-10 00:52d--------c:\program files\Common Files\Nero
      2009-01-10 00:52 . 2006-01-12 16:40225,280--a------c:\windows\system32\NeroCheck.exe
      2009-01-10 00:51 . 2009-01-10 00:51d--------c:\program files\Common Files\Ahead
      2009-01-10 00:51 . 2009-01-10 00:53d--------c:\program files\Ahead
      2009-01-10 00:51 . 2009-01-10 00:51d--------c:\documents and settings\All Users\Application Data\Ahead
      2009-01-10 00:51 . 2005-07-29 10:122,977,792---------c:\windows\UNNeroVision.exe
      2009-01-10 00:51 . 2004-07-26 17:161,568,768---------c:\windows\system32\ImagX7.dll
      2009-01-10 00:51 . 2004-07-26 17:16476,320---------c:\windows\system32\ImagXpr7.dll
      2009-01-10 00:51 . 2004-07-26 17:16471,040---------c:\windows\system32\ImagXRA7.dll
      2009-01-10 00:51 . 2004-07-09 09:43364,544---------c:\windows\system32\TwnLib4.dll
      2009-01-10 00:51 . 2004-07-26 17:16262,144---------c:\windows\system32\ImagXR7.dll
      2009-01-10 00:51 . 2006-05-23 11:30179,288---------c:\windows\UNNeroVision.cfg
      2009-01-10 00:51 . 2000-06-26 11:45106,496--a------c:\windows\system32\TwnLib20.dll
      2009-01-10 00:51 . 2001-06-26 08:1538,912---------c:\windows\system32\picn20.dll
      2009-01-10 00:51 . 2001-03-08 19:3024,064---------c:\windows\system32\msxml3a.dll
      2009-01-10 00:49 . 2009-01-10 00:49d--------c:\documents and settings\topaz01\Application Data\DisplayTune
      2009-01-10 00:47 . 2009-01-10 00:47d--------c:\program files\Portrait Displays
      2009-01-10 00:47 . 2005-03-04 15:3711,776--a------c:\windows\system32\drivers\pdiddcci.sys
      2009-01-10 00:47 . 2005-03-04 15:348,960--a------c:\windows\system32\drivers\PdiPorts.sys
      2009-01-10 00:41 . 2007-03-12 16:423,495,784--a------c:\windows\system32\d3dx9_33.dll
      2009-01-10 00:39 . 2009-01-10 00:39d--------c:\windows\nview
      2009-01-10 00:39 . 2008-01-03 17:26360,448--a------c:\windows\system32\nvudisp.exe
      2009-01-10 00:39 . 2009-01-11 01:05160,827--a------c:\windows\system32\nvapps.xml
      2009-01-10 00:39 . 2008-01-03 17:2617,737--a------c:\windows\system32\nvdisp.nvu
      2009-01-10 00:38 . 2009-01-10 01:00d--------c:\documents and settings\topaz01\Application Data\DivX
      2009-01-10 00:37 . 2009-01-10 13:23d--------c:\program files\DivX
      2009-01-10 00:36 . 2009-01-10 00:36d--------c:\program files\Common Files\Adobe
      2009-01-10 00:35 . 2008-04-13 13:4526,368--a--c---c:\windows\system32\dllcache\usbstor.sys
      2009-01-10 00:18 . 2009-01-10 00:18d--------c:\windows\system32\GroupPolicy
      2009-01-10 00:18 . 2009-01-10 00:18d--------c:\program files\Windows Media Connect 2
      2009-01-10 00:18 . 2009-01-10 00:18d--------c:\program files\Windows Desktop Search
      2009-01-10 00:18 . 2009-01-10 00:18d--------c:\program files\Microsoft Silverlight
      2009-01-10 00:18 . 2009-01-10 00:18d--------c:\documents and settings\topaz01\Application Data\Windows Desktop Search
      2009-01-10 00:18 . 2008-03-07 12:02192,000-----c---c:\windows\system32\dllcache\offfilt.dll
      2009-01-10 00:18 . 2008-03-07 12:0298,304-----c---c:\windows\system32\dllcache\nlhtml.dll
      2009-01-10 00:18 . 2008-03-07 12:0229,696-----c---c:\windows\system32\dllcache\mimefilt.dll
      2009-01-10 00:17 . 2009-01-10 13:45d--------c:\windows\system32\LogFiles
      2009-01-10 00:17 . 2009-01-10 00:17d--------c:\windows\system32\drivers\UMDF
      2009-01-10 00:15 . 2009-01-10 00:15d--------c:\windows\system32\URTTemp
      2009-01-10 00:04 . 2008-10-16 15:386,066,176-----c---c:\windows\system32\dllcache\ieframe.dll
      2009-01-10 00:04 . 2007-04-17 04:322,455,488-----c---c:\windows\system32\dllcache\ieapfltr.dat
      2009-01-10 00:04 . 2007-03-08 00:10991,232-----c---c:\windows\system32\dllcache\ieframe.dll.mui
      2009-01-10 00:04 . 2008-10-16 15:38459,264-----c---c:\windows\system32\dllcache\msfeeds.dll
      2009-01-10 00:04 . 2008-10-16 15:38383,488-----c---c:\windows\system32\dllcache\ieapfltr.dll
      2009-01-10 00:04 . 2008-10-16 15:38267,776-----c---c:\windows\system32\dllcache\iertutil.dll
      2009-01-10 00:04 . 2008-10-16 15:3863,488-----c---c:\windows\system32\dllcache\icardie.dll
      2009-01-10 00:04 . 2008-10-16 15:3852,224-----c---c:\windows\system32\dllcache\msfeedsbs.dll
      2009-01-10 00:04 . 2008-10-16 08:1113,824-----c---c:\windows\system32\dllcache\ieudinit.exe
      2009-01-10 00:01 . 2008-08-14 05:112,189,184-----c---c:\windows\system32\dllcache\ntoskrnl.exe
      2009-01-10 00:01 . 2008-08-14 05:092,145,280-----c---c:\windows\system32\dllcache\ntkrnlmp.exe
      2009-01-10 00:01 . 2008-08-14 04:332,066,048-----c---c:\windows\system32\dllcache\ntkrnlpa.exe
      2009-01-10 00:01 . 2008-08-14 04:332,023,936-----c---c:\windows\system32\dllcache\ntkrpamp.exe
      2009-01-10 00:01 . 2008-09-15 07:121,846,400-----c---c:\windows\system32\dllcache\win32k.sys
      2009-01-10 00:01 . 2008-09-04 12:151,106,944-----c---c:\windows\system32\dllcache\msxml3.dll
      2009-01-10 00:01 . 2008-10-24 06:21455,296-----c---c:\windows\system32\dllcache\mrxsmb.sys
      2009-01-10 00:01 . 2008-10-15 11:34337,408-----c---c:\windows\system32\dllcache\netapi32.dll
      2009-01-10 00:01 . 2008-09-08 05:41333,824-----c---c:\windows\system32\dllcache\srv.sys
      2009-01-10 00:01 . 2008-05-01 09:33331,776-----c---c:\windows\system32\dllcache\msadce.dll
      2009-01-10 00:01 . 2008-08-14 05:04138,496-----c---c:\windows\system32\dllcache\afd.sys
      2009-01-10 00:00 . 2008-04-11 14:04691,712-----c---c:\windows\system32\dllcache\inetcomm.dll
      2009-01-10 00:00 . 2008-06-13 06:05272,128-----c---c:\windows\system32\dllcache\bthport.sys
      2009-01-10 00:00 . 2008-05-08 09:02203,136-----c---c:\windows\system32\dllcache\rmcast.sys

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-01-10 05:47---------d--h--wc:\program files\InstallShield Installation Information
      2009-01-10 04:39---------d-----wc:\program files\Realtek Sound Manager
      2009-01-10 04:39---------d-----wc:\program files\AvRack
      2009-01-10 04:38---------d-----wc:\program files\Common Files\InstallShield
      2009-01-10 04:33---------d-----wc:\program files\microsoft frontpage
      2008-12-11 00:3386,016----a-wc:\windows\system32\dpl100.dll
      2008-12-11 00:33200,704----a-wc:\windows\system32\dtu100.dll
      2008-12-09 02:28593,920----a-wc:\windows\system32\dpuGUI11.dll
      2008-12-09 02:2857,344----a-wc:\windows\system32\dpv11.dll
      2008-12-09 02:28344,064----a-wc:\windows\system32\dpus11.dll
      2008-12-09 02:28294,912----a-wc:\windows\system32\dpu11.dll
      2008-12-03 03:3749,480----a-wc:\windows\system32\sirenacm.dll
      2008-11-06 16:37524,288----a-wc:\windows\system32\DivXsm.exe
      2008-11-06 16:373,596,288----a-wc:\windows\system32\qt-dx331.dll
      2008-11-06 16:37129,784------wc:\windows\system32\pxafs.dll
      2008-11-06 16:37120,056------wc:\windows\system32\pxcpyi64.exe
      2008-11-06 16:37118,520------wc:\windows\system32\pxinsi64.exe
      2008-11-06 16:35200,704----a-wc:\windows\system32\ssldivx.dll
      2008-11-06 16:351,044,480----a-wc:\windows\system32\libdivx.dll
      2008-11-06 16:33823,296----a-wc:\windows\system32\divx_xx0c.dll
      2008-11-06 16:33823,296----a-wc:\windows\system32\divx_xx07.dll
      2008-11-06 16:33815,104----a-wc:\windows\system32\divx_xx0a.dll
      2008-11-06 16:33802,816----a-wc:\windows\system32\divx_xx11.dll
      2008-11-06 16:33684,032----a-wc:\windows\system32\DivX.dll
      2008-11-06 16:3312,288----a-wc:\windows\system32\DivXWMPExtType.dll
      2008-10-23 12:36286,720----a-wc:\windows\system32\gdi32.dll
      2008-10-16 20:38826,368----a-wc:\windows\system32\wininet.dll
      2008-10-16 19:13202,776----a-wc:\windows\system32\wuweb.dll
      2008-10-16 19:131,809,944----a-wc:\windows\system32\wuaueng.dll
      2008-10-16 19:12561,688----a-wc:\windows\system32\wuapi.dll
      2008-10-16 19:12323,608----a-wc:\windows\system32\wucltui.dll
      2008-10-16 19:0992,696----a-wc:\windows\system32\cdm.dll
      2008-10-16 19:0951,224----a-wc:\windows\system32\wuauclt.exe
      2008-10-16 19:0943,544----a-wc:\windows\system32\wups2.dll
      2008-10-16 19:0834,328----a-wc:\windows\system32\wups.dll
      2008-10-16 19:07208,744----a-wc:\windows\system32\muweb.dll
      .

      ((((((((((((((((((((((((((((( [emailprotected]_ 1.39.33.45 )))))))))))))))))))))))))))))))))))))))))
      .I take it you didn't install the AVI converter again, after each format?I forgot to mention that, no I did not.

      2593.

      Solve : rogue Spyware Guard 2008 pop-up - pls help?

      Answer»

      Hello Team
      I've had a nasty pop-up named Spyware Guard 2008 since Ney YEAR. RESTORE points failed.. tried downloading few progs to remove (advance syst. care & revo un-installer etc..), ALSO have tried manually following random advice... my startup font have changed and now i am really STUCK as it keeps coming back; I noticed that i although i have internet connections i am unable to open important webistes relating to computer repair or downloading anti-virus/anti-spyware software ... pls help... thanks in advance ok as you can tell i'm a real beginner sorry about this!! a bit more info... I have managed to download Hijack This, have a log not sure if it helps. It seems now i need to download virus definitions for Norton or AVG to scan and fix, but there is a connection error everytime i go to any definition downloads. also I cannot access www://windowsupdate.microsoft.com/ ... pleeeaase can you helpI had this problem about a week ago and seemed to get rid of it by using Super Anti-Spyware. Not sure if it will work for you though.

      2594.

      Solve : Help with Spyware?

      Answer»

      I have run CCcleaner, AVG Free, Super ANTISPYWARE, and Mailwarebyte's Anti-Malware, but I can't SEEM to get rid of this pop up. I tried opening the logs, but every time I do, everything freezes up.

      The problem I am having is a Webcam portal to Cams.com keeps popping up at random and sets itself to be at the front of everything. It stays there for about 5 MINUTES before closing itself.

      Any ideas what I can do?

      Here are Super Anti SPYWARE and Malwarebytes logs as well as the link and page source of the pop up. Also now added Combofix log.

      [attachment deleted by admin]

      2595.

      Solve : DLL error?

      Answer»

      Every time that my computer starts up i get an error message saying that the file containing M3PLUGIN.DLL cannot be located. I FOLLOWED the steps listed on this site of how to diagnose the problem and the results are in the attached logs. I am CURRENTLY running Windows Vista basic 6.0. My computer is a desktop from dell and has 2.0 GB RAM. i also have an Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.4GHz. This issue started occurring about 2 months ago. It could have come from any unprotected website as i am on the internet daily. What should i do from here?

      [attachment deleted by admin]Sorry for the long wait. We are VERY backed-up right now! If you still require assistance, please post new logs and we'll see what we can do.I have attached the new updates but the last time that i restarted my computer the dll error did not show up. I'm not sure that the PROGRAMS didn't take care of it on their own. You can still look though because i don't know.

      [attachment deleted by admin]are they updated?Yes they are updated.

      Look at the name of this files - the date. Quote from: tylerisdabest on January 10, 2009, 12:46:40 PM

      are they updated?
      If you don't have anything useful to say, you're better off saying nothing at all.



      jh6004,
      The original error you were getting was related to a MyWebSearch infection, which appears to have been removed successfully. You NEED to get yourself a decent firewall such as ZoneAlarm or Comodo, but aside from that, you look clean now. The error shouldn't come up, but if your symptoms start again, let me know and we can run more scans.Alright, thanks for the HELP!
      2596.

      Solve : isass.exe, should i delete and how?

      Answer»

      hi there
      i've found isass.exe in my running processes, not sure what to do with it.

      the COMPUTER performance wise.. is running slow. but it is a old computer handed down to me. and my knowledge of computers is not great - so i'm not sure how fast it should be runing anyway.. i'll only be using it for web browsing. so my only concern is that it is secure for me to use. but any help would be appreciated

      my computer:
      windows xp home edition
      1.80GHz 224MB ram

      running ZoneAlarm and AVG free edition, up to date (nothing bad detected so far)

      --------------------------------------------------------

      Logfile of HijackThis v1.99.1
      Scan saved at 23:49:04, on 13/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0013)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Apps\ActivBoard\nhksrv.exe
      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      C:\WINDOWS\system32\slserv.exe
      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
      C:\WINDOWS\System32\khooker.exe
      C:\Apps\ActivBoard\MMKeybd.exe
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\apps\ActivSurf\4448364\Program\backweb-4448364.exe
      C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
      C:\Apps\ActivBoard\TrayMon.exe
      C:\Apps\ActivBoard\OSD.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
      C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\taskmgr.exe
      C:\Program Files\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
      O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
      O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
      O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
      O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
      O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
      O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
      O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - Global Startup: Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
      O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
      O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
      O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O14 - IERESET.INF: START_PAGE_URL=www.packardbell.co.uk/center
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



      thank you for your time

      **edit**
      not sure it's called Isass.exe or Lsass.exe, hard to tellQuote

      not sure it's called Isass.exe or Lsass.exe, hard to tell
      This is very important, because isass.exe is OPTIX PRO trojan, while lsass.exe is legit Windows file.
      We'll sort it out.

      You used outdated HJT version, so let's do it again...

      Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll SEE "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      thanks broni
      have not gone through those steps yet, have been a bit busy

      but i just came back becuase i had an idea to use my web browser and search the word 'Lsass.exe' on this page

      and Lsass apears in my HJT log
      so i'm guessing it's all legit and fine like you say

      although i don't understand HJT logs, so i was just wondering if there was anything there that shouldn't be there
      the computer is new to me like i say.
      but it used(before i reformated) to have a lot of problems and was infected with a virus or two.
      i'm guessing all is fine now?

      sorry for sounding a bit like a time waster. it's just this computer is on a network with anouther so was just wondering if this one was STILL had it's virus.
      if someone doesn't mind giving my HJT log a quick look over that would be good, if not no prob.

      P.S. are the logs just a matter of copying and pasting each part into a search engine? or is there more to it? i understand the running processes part, but not the rest of it. would be better if could do it..

      thanksI can't comment, or ADVICE, unless I see those three logs.Hi there, I wish everyone a happy new year.

      I am experiencing something rather very strange, and I was wondering if anyone can help me. I really do not know what to do. I have windows XP. and I am experiencing the virus (virus.win32.xorer.ee) which has three files which are critical. (Isass.exe) + (smss.exe) + (ckvol.dll). I can not install or run any anti-virus programs. My PC wont let me. I can not run in safe mode. I can not delete those items. so basically, this thing is in total control of my PC. So please. if anyone can help me here i would really aperciate it. Thank you.crazysoccerboy
      Please, start your own topic.
      2597.

      Solve : i got a serous malware problem?

      Answer»

      i got a problem

      i thout my infeton was gone... my dad said he FIXED... he did but i got 124 adwares and vundos (mostly adware.mywebserch) i think spybot did not pick up all of those(i think it just picked up the major dowloader and dagourus malware). but when i whent to scan with malware byets i got 124. (i think all of the TROJANS are like not replecated or something) but plese help

      i have my hijakthis and malaware bytes logs

      i need to KNOW whats safe to quarentine

      [attachment DELETED by ADMIN]

      2598.

      Solve : Multiple Sypware/Malware?

      Answer»

      This might be a challenging problem....

      A few weeks ago my computer started giving random pop-ups and blocked my Virus protection updates (Norton). Upon further examination, I discovered multiple malwares: It started with Prunnet.exe and Gadcom.exe. I think I got rid of those but my Task manager is still showing crssc.exe and iexplore.exe (although I am not using Internet Explorer). I am unable to install any new anti-virus software (especially HijackThis, that will not even start the installation process) and my computer has problems starting up (sometimes it takes a few manual restarts to get to the main screen).

      I am very inexperienced and afraid that I am causing more issues by trying to fix things myself. I would greatly appreciate if there is anyone that could help me.


      Thank you!!!!

      D. try posting a hijack this logQuote from: DejanK on January 09, 2009, 10:45:57 AM

      I am unable to install any new anti-virus software (especially HijackThis, that will not even start the installation process.

      What part of that did you NOT get?oh srry didnot read full

      heres another idea

      do you have a frend that has a computer

      if so

      get a jump drive or a cd go to him and get on his computer get hijack this and install onto jumpdrive or cd

      then tell if worksI managed to install AVG, it fixed most problems. This is the HJT LOG, how does it look?

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:11:30 PM, on 1/9/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\PROGRA~1\SYMANT~1\VPTray.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\DellSupport\DSAgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
      c:\Program Files\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      c:\Program Files\Symantec AntiVirus\SavRoam.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wscript.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.comcast.net/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = copy.its.yale.edu:8080
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\SYMANT~1\VPTray.exe
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKUS\S-1-5-19\..\Run: [fimininane] Rundll32.exe "C:\WINDOWS\system32\dowurumi.dll",s (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [fimininane] Rundll32.exe "C:\WINDOWS\system32\dowurumi.dll",s (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
      O4 - Global Startup: Microsoft FIND Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O4 - Global Startup: VPN Client.lnk = ?
      O8 - Extra context menu item: &Windows Live Search - RES://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
      O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
      O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/stanford/support/plugins/ebraryRdr.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
      O17 - HKLM\System\CCS\Services\Tcpip\..\{1EB54B59-2114-49C1-8FDF-AD2A7BA36631}: Domain = stanford.edu
      O17 - HKLM\System\CS2\Services\Tcpip\..\{1EB54B59-2114-49C1-8FDF-AD2A7BA36631}: Domain = stanford.edu
      O17 - HKLM\System\CS3\Services\Tcpip\..\{1EB54B59-2114-49C1-8FDF-AD2A7BA36631}: Domain = stanford.edu
      O17 - HKLM\System\CS4\Services\Tcpip\..\{1EB54B59-2114-49C1-8FDF-AD2A7BA36631}: Domain = stanford.edu
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Ati HotKey Poller - UNKNOWN owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - c:\Program Files\Symantec AntiVirus\DefWatch.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: SAVRoam (SavRoam) - symantec - c:\Program Files\Symantec AntiVirus\SavRoam.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: Symantec AntiVirus - Symantec Corporation - c:\Program Files\Symantec AntiVirus\Rtvscan.exe

      --
      End of file - 10150 bytes


      Thank you for your help!!!


      2599.

      Solve : Friends suck?

      Answer»

      A friend of mine tried to download a keygen for call of duty: world at war, and gave me one nasty virus. AVG PRO can do nothing about it, nor could any of the programs you recommended. Upon boot-up, it gives me the following error:
      The instruction at "0x00401000" referenced memory at "0x00401000", the memory could not be "written"
      Click on OK to terminate the program
      lick on CANCEL to debug the program
      So clearly it's INFECTING my RAM as well. Later I usually get a similar message concerning "0x00000000". It's ALSO spreading through my DRIVERS file every reboot.
      Attached are my logs for HJT, SAS, and MBAM, as requested. I'm unable to open Task Manager or My Computer. It's also started messing with my daemon tools and PRESENTS an error that the virtual SCI drives could not be found, which never happened before the virus (unrelated MAYBE, but i doubt it.). Also, when SAS tried to remove the problems, the computer did an automatic reboot in the middle of the action. I believe it was during the removal of the malware in the RAM.
      Please, anything you guys could do would be greatly appreciated. Thanks for your time and consideration,
      Eddie Key

      [attachment deleted by admin]

      2600.

      Solve : EEEEK. Help???

      Answer»

      Hello! I desperately need some computer help as I'm a 3rd year university student and my laptop just recently suffered a heart attack.

      I was browsing some music websites, left to have a shower, came back, and this program called Rapid Antivirus had magically installed itself on my laptop. It kept flashing nasty popups and saying my computer was being ATTACKED by various things... I did a Spyware scan, and it turns out the Rapid Antivirus was a trojan virus and I had about 4 or 5 on there from this one program thingy. I deleted them all from my regedit, going by the files LABELLED as tainted from my AVG scanner, and then, as my AVG told me to do, I closed down explorer.exe in my task manager.

      Then... POOOOF... KABOOM. I had to restart my laptop cause nothing was showing on my desktop. After restarting it, nothing... and I mean like nothing, worked. I could no longer access the internet, I can't do a system restore (each time it tells me to restart my computer because it cannot do it at this time.) I cannot copy/paste any files or use the 'sent to' option, I can't open picture documents, change icons on my desktop, and a number of programs are unusable. In control panel, I can't change a number of things or access programs such as Help & Support or error scanners. I get errors with a number of things that I do.

      After a while, I get a message saying my computer has encountered a problem and needs to shutdown in 00:59 seconds. When it is shutting down, it says Explorer.exe is unresponsive and needs to quit. If I don't get that message, often my screen may just freeze up altogether and leave me wailing. I have TRIED RUNNING it on safemode too, but the same problems PRESIST.

      ?!?!?!?!

      Really, if this problem is totally unfixable, I would really just love to know how to be able to copy/paste and send-to again so that I can transfer my important documents to a mini disk and just use the default system restoration by pressing F11 on startup that deletes everything off my computer to return it to the manufacture condition. :'<

      PLEASE HELP ME. Thank you very much for ANY insights. I am currently on a computer at work, and reaaaally can't afford to buy a new laptop. (Also I'm pretty sure I don't have Windows XP to reinstall on my computer, but again, I have important files that I want to rescue from certain ruin!)