 
                 
                InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2751. | Solve : Online spyware support website?? | 
| Answer» Hello Friends | |
| 2752. | Solve : problems with computer? | 
| Answer» and as for the superantispyware one, when I tried to open the log, it brought up a log of an old QUICK scan i did. | |
| 2753. | Solve : Need Serious / Urgent Help? | 
| Answer» OK My Problem is the following two screenshots: | |
| 2754. | Solve : Cannot Unhide folders/files? | 
| Answer» I dont know whether its a vrus related issue or not, but i think so, thats why i am posting it here..... Those files ar the system files in C Drive like..... My Recent Documents, Local SettingsHow do you access them?Do you have a security program installed that protects hidden files? Post a HijackThis log so we can see what might be blocking the access.Logfile of Trend MICRO HijackThis v2.0.2 Scan saved at 1:08:08 PM, on 1/2/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\WINDOWS\system32\calc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = about:blank O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{1317FC6D-753C-4489-8002-B6A82E37BA35}: NameServer = 202.54.12.164,202.54.29.5 O17 - HKLM\System\CS1\Services\Tcpip\..\{1317FC6D-753C-4489-8002-B6A82E37BA35}: NameServer = 202.54.12.164,202.54.29.5 O17 - HKLM\System\CS2\Services\Tcpip\..\{1317FC6D-753C-4489-8002-B6A82E37BA35}: NameServer = 202.54.12.164,202.54.29.5 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: LightScribeService Direct Disc LABELING Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- End of file - 6177 bytes I don't see anything all that noteworthy, but I don't see a firewall on your computer. Which version of McAfee are you using? Also, you skipped this question... Quote from: patio on January 01, 2008, 10:45:16 AM Are you logged on as Administrator ? ? | |
| 2755. | Solve : O17 Entries in my HJT log!!? | 
| Answer» Before punching a big hole in my LCD monitor, I decided to take a look at my HJT log. Will fix the BHO and Toolbar.They are just "COSMETIC" fixes. You won't see any difference. Do you want me to check your startups (O4s)?No, most of the O4 entries are valid, except for IOBit SmartDefrag. I heard that it had some uninstall problems, but I'm not having any problems. Thank you for the help.I know, they are valid, but number of them are not needed as startups. The more startups you have the slower your computer is.OK, check the O4s.OK.Open HJT, and checkmark following items: - O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe - O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp (you don't defrag every day, do you?) - O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe - O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime - O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" If you don't use more then one language in MS Office, disable CTFMON.EXE from starting: http://support.microsoft.com/default.aspx?scid=kb;en-us;282599, and fix also these: - O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') - O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') - O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') - O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') Remember, by fixing the above entries, you don't remove/uninstall any programs. Thank you so much. I don't defrag daily, but when I had IOBit SmartDefrag installed (uninstalled ALREADY) it always defragmented at startup.Then, you don't need that entry anyway. | |
| 2756. | Solve : help with a virus? | 
| Answer» Open HijackThis and select Do a system scan only then place a check mark next to: 
 2) Please run Killbox. 3) Select "Delete on Reboot" 4) Open the text file with these instructions in it, and copy the file name in the quote box below to the clipboard by highlighting them and pressing Control-C: Quote C:\WINDOWS\System32\tellcoma.exe 5) Return to Killbox, go to the File menu, and choose "Paste from Clipboard" 6) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot PROMPT Click "No" at the Pending Operations prompt If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click HERE to download and run missingfilesetup.exe Then try Killbox again.. Let the system reboot. Post a new HijackThis log. when i CLICKED "delete file" i got "pending file name operations registry data has been removed by external process" and then it doesnt reboot by itselfReboot the computer. After rebooting, open up Killbox again, click File -> Logs -> Actions History Log Copy and paste the contents of kb.log and post it in your next reply. If that doesn't work go to Start > Run and type: (or copy and paste) notepad systemdrive%\!Killbox\Logs\kb.log Copy and paste the contents of kb.log and post it in your next reply. Also run a new hijackthis scan and post the log.kill box & hjt logs attached [file cleanup - saving space - ATTACHMENT deleted by admin]This is definitely a NASTY one. They are renamed to something else now. Open HijackThis and select Do a system scan only then place a check mark next to: O4 - HKUS\S-1-5-18\..\Run: [Microsoft Config 32] msconfigx32.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Microsoft Config 32] msconfigx32.exe (User 'Default user') Close all windows except for HijackThis and click Fix checked Exit Hijackthis. Open Killbox. Click the button that says All Files Copy the files in the quote box below. Quote C:\WINDOWS\System32\tellcoma.exe In Killbox click File > Paste from clipboard Check the box to Replace On Reboot, then check the box under it Use Dummy. Then click the red X and allow reboot. Post the Killbox log i the next post along with a new hijackthis log please. i cant seem to get the new kb log?....i got to kb..click files...click logs then i click actions history log but it comes up with the previous kb log.. am i doing something wrong?Did it seem like it worked this time? what do you mean?Did killbox work with no errors? Post a new hijackthis log please.it came up with the same message as before --------- hjt log attched [file cleanup - saving space - attachment deleted by admin]I have asked on the errors and it seems this is not uncommon for killbox to report this. The log is finally clean. How is the computer now? Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. Please download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. 1. Double click OTMoveIt2.exe to launch it. 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 4. When finished exit out of OTMoveIt2 Download and install CleanUp! Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: 
 I'll let you know if any of the symptoms appear again!! thanks so much for this!! Im sorry if i ve bee a pain ^^ thank you thank you!! btw..how COME i have a antivirus on my pc but it still doesnt help instead we have to go through all thses steps?Quote thanks so much for this!! Im sorry if i ve bee a pain ^^ No problem, glad you stuck it out also. Quote how come i have a antivirus on my pc but it still doesnt help instead we have to go through all thses steps? Not sure how it got there. All it takes is one click and all sorts of stuff can get in. Antivirus can't always stop some of the well written virus out there. Quote I'll let you know if any of the symptoms appear again!! Absolutely, we will be here. Quote I think everything is ok now! Good, I hope it stays that way. To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Safe surfing........ | |
| 2757. | Solve : Very Annoying Computer Problem. Please help me.? | 
| Answer» Yeah with a XP install disc you can WIPE the drive clean.Quote the multiple svchost.exe's are STILL running. This is normal. Try to locate that Windows CD.Alright, well then I guess that virus just won't LEAVE. Thank you everyone who helped me. Have a Happy New Year. I'll just wipe the hard-drive.Keep us posted.Wow, I finally found that CD. Well, everything is working in tip-top SHAPE. Thank you every for your help.I'm glad. Did you USE CD? | |
| 2758. | Solve : scanning problem in zone alarm internet security suite 7? | 
| Answer» zonealarm internet security suite 7 have many specialization. 2 of them are antivirus and anti spyware. when i scan my PC for antivirus and spyware both of them scan the virus and spyware. but 1month ago since my antivirus detect a virus after that no virus but anti spyware is the one that can detect or scan a spyware. is this a cause of a problem in my antivirus? or this is POSSIBLE to happen.1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/ i'll do this when i can use the IEYou can't?i can use IE. but for a while im using mozilla cause i am having problem with IE to connect in internet. That's fine. Using Firefox, you may run Panda's ActiveScan: http://www.pandasoftware.com/activescan/com/activescan_principal.htm 1. Once you are on the Panda site click the "Scan your PC" button 2. A new window will open... * Enter your Country * Enter your State/Province * Enter your Valid Email * Select either Home User or Company * Select the "I do not want to receive marketing information from Panda Software..." 3. Click the big "FREE Online Scan" button 4. If it wants to install an ActiveX component allow it 5. It will start downloading the files it requires for the scan (Note: It will take a few minutes so be patient) 6. Click on "Local Disks" to start the scan 7. When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can view later. Post its log | |
| 2759. | Solve : Need help with a virus, fast!? | 
| Answer» I booted my PC like normal, started up all fine then a second later everyting blanks, taskbar, start menu, etc. then it pops up with an un-exitable full screen webpage containing images and such i'd rather not have on my computer screen (pornography) . I quickly shut it down and booted of my spare hard drive and did two full system scans one on norton and one on avg antivirus both found nothing. I checked again and it's still happening I need help fast please! 1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/ | |
| 2760. | Solve : advertisment by adssite annoying pop ups analyse hijack log? | 
| Answer» I have been experiencing pop ups from adssite and they have been annoying I have tryed everything to get rid of it can anyone help me. Here is my hijack log | |
| 2761. | Solve : BSOD! Im having the BSOD come up whenever I try to put comp in sleep mode!? | 
| Answer» Power down and re-boot. | |
| 2762. | Solve : My computer has very little connectivity, nothing can connect to it.? | 
| Answer» WELL, we CLEANED few things during this procedure. Oh, don't forget to UPDATE your Java. | |
| 2763. | Solve : LOP Spyware won't go away !? | 
| Answer» OK about nod, I can see it. | |
| 2764. | Solve : Pop ups Searchthetrend.com Problems!!? | 
| Answer» My Laptop is infected with something and it is driving me nuts!  I have RAN the Hijack log and didn't see anything unusual . When I get on line I get the pop up searchthetrend.com and its getting worse because the computer is really slow now and I can barely do anything | |
| 2765. | Solve : Can somebody give me some help......please!!? | 
| Answer» Hi, My pc (or should I say my AVG) is reporting 2 bugs. I have tried everything I can think of to try to fix them without any success. 
 
 
 Let us know how things are now. Exit Hijackthis. EDIT Sorry Broni we crossed up. He has ran the removal steps already.OK. I'm gonna remove my post, then.Hi, Many thanks for your reply. I have done as you requested, but I an still getting the virus alert. The AVG anti virus is still popping complaining about the "dsoundh.dll" and I noticed in the latest Hijackthis file that the "02-BHO:(no name)...........C:\Windows\system32\dsoundh.dll" is still present. Should I have run this in safe mode ? I have attached the latest hijackthis file "hijackthis2" Thanks for you help. Brian [file cleanup - saving space - attachment deleted by admin] Copy this file path C:\WINDOWS\system32\dsoundh.dll (highlight and press ctrl+C) Go to www.viruschief.com PASTE the file path in the window under Quick Scan: (press ctrl+V on the keyboard to paste) Click Scan. You will see a message: ENG: It can take up to 1 minute before your scan starts, please wait! GER: Es kann bis zu einer Minute dauern bis Ihr Scan startet, bitte warten! Once the scan is complete, copy the text in the window under BB Code and paste it into the next post.Hi Sorry am I doing something wrong, each time I click on scan the page refreshes with "Upload/Formular error!" Run HijackThis and try to fix the entry again. If needed do it in Safe Mode. Let me know how it went.Ran hijack thisand tried to fix the "c:\windows\system32\dsoundh.dll", but the file is still there when I run the next hijackthis. file attached. [file cleanup - saving space - attachment deleted by admin]Please download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows: 
 Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot. 
 After running Dr Web the popup warning has stopped and the file C:\windows\system32\dsoundh.dll no longer exists. I am hoping that this has fixed the problem. Thank you very much for your help, I would not have been able to fix it by my self. I have attached the Drweb & a hijack this log. I will run through my normal AVG scans just to make sure that every thing is o.k. Thanks again, Brian [file cleanup - saving space - attachment deleted by admin]Looks good. This is a good time to clear your infected system restore points and establish a new clean restore point: 
 To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Let us know if anything else comes up. | |
| 2766. | Solve : trojan.win32.agent.akk? | 
| Answer» I begin receiving the following message recently: | |
| 2767. | Solve : 3 keyloggers found? | 
| Answer» Hello all: | |
| 2768. | Solve : Help with infected computer? | 
| Answer» Open HJT, and checkmark following entries: Is the memory install hard on a laptop?Not at all. In many cases, you don't even need a screwdriver. Turn your laptop up side down, and you may see some sliding door bays (depending, of course on laptop model). Make sure, you buy not only RIGHT type of RAM, but also right size, because usually the space is tight.Broni, I would like to thank you for all your help... I am going to pick up a 1GB memory stick today for her laptop. My desktop seems to be running great now thanks to you. I have even noticed a better performance in her laptop this morning too. I am sure the extra memory will talk care of the rest! I have not been keeping up with technology for several years since I built my desktop. I am just wondering how MUCH out of date it really is. As you know it is a Pentium 4 3.2Ghz with 1GB of Ram, 120 GB Hard Drive, and a Radeon 9800 Pro Video Card. It runs really smooth now and as fast as I need it to. I know things have changed a lot in the last 4 years or so with hardware. My question is that I have a Dell Inspiron 5150 3.06 GHz HT with 512 MB of Ram, 64 MB Ge-force FX Go5200 Video Card, and a 40GB Hard Drive... It did run really smooth up until 2 months ago when it seemed like something with the screen was shutting it down. Looks like it will cost a couple hundred $'s to send it to dell and have it fixed. I payed a pretty penny for it around 4 years ago but I know things have changed a lot and come down in price allot also. Is it really worth having it repaired you think and am I really that far out of date with my desktop hardware? It seems like money was always going out the door for this stuff when I was younger and was just wondering in your professional opinion what my best options are for what I have right now. Again thank you for everything!!!! It means a lot to me and you are the best!!!! JeremyThat Dell unit may be worth resuscitating...DLoad and run Everest Home and post the Computer Summary portion of the report and we'll take a looksee...Hi, here it is..... [file cleanup - saving space - attachment deleted by admin]In my opinion: - you need to install Service Pack 2 on it - your RAM says 256MB, not 512MB, so I'd add something here (another 256MB, or just 1GB) - 64MB of video sucks little bit, but what can you do with laptop (I can see, that 64MB is the top, you can get) - hard drive 40GB? you still have almost 30GB free, so you should be OkHi all, I just wanted to post a link to what I found out about my Dell laptop. It seems the 5150 had a defect from Dell which was causing the shutdown problem i was having. I did the posted fix I found this weekend and it is WORKING great now. Thank you for all your help as all of my pc's are now up and running great Thanks again, Jeremy http://www.hardwareanalysis.com/content/topic/43678/Good to know. Thanks for posting back. | |
| 2769. | Solve : creat anti virus? | 
| Answer» ;Dhi joeloffelsienes ......... Before you embark on reinventing the wheel, perhaps you could tell us if your computer is infected with some type of nasty and what anti virus are you currently using. yes i notice in our network... i am using kasperskey...i dont know if the pc's her were infected... then some of our pc here were repair, i dont that was a virus... one thing i am confuse cuz every morning i came in my office my officemate who are my friends in yahoo messenger were angry with me... they say that stop sending virus to me.... can u help me bout these? thankxxxxxx....the 1st thing you must do is to download avira http://www.free-av.com/ update and run full SCAN in safe mode. and don't forgot to uninstall the current anti virus you don't need to uninstall your current av if you don't want to just do some online virus scans LIKE housecall edwido online scan etc and make sure your av is up to date and scan with it in safe mode | |
| 2770. | Solve : DLLs identified as infections? | 
| Answer» We should establish a geographically correct central meeting place for those people who actually want to reward us for our efforts...Any ideas ? ?Since people on this board are from all over the world, I think MY place will work. It's always half-way from SOMEWHERE...LOL | |
| 2771. | Solve : CID Pop-ups ??? | 
| Answer» I have these pop-ups coming up and ALL of them start with "CiD:" some nasty sites. Some not. They come up sometimes even when nothing is open.  
 Click Yes at the prompt. It will open a text file. Please copy the entire contents of that page and paste it here. Third... Download lop.zip Unzip it to your desktop. Go into the new lop folder and double-click lop.bat It will run and when done, a Notepad will open. Copy the contents of the Notepad and paste it here. Finally... Scan with HijackThis once again and post a new log here. To clarify, we need the following from you... 1. An ESET log. 2. A NoLop! log. 3. A StartupList log. 4. A lop.bat log. 5. A new complete HijackThis log. I know it seems like a lot, but these five logs will help us with the removal of your infections.Quote A new complete HijackThis logYou ran HJT before Superantispyware.Quote from: CBMatt on January 07, 2008, 06:35:21 PM You appear to have a Lop infection....a tip ....once someone mentions CiD ... it's definitely a LOP infection. Do the "NoLop" thing, remove/uninstall Messenger Plus 3! and that infection should go. (as to any other malware ... well, that's something else ) OJThanks for all the help guys. I really appreciate it. I TRIED doing the SUPERAnti-spyware and all that ..and I probably didnt do it all right. But I just DL'ed AVG Anti-virus and Spyware and scanned and it found 2 trojans and a bunch of infected files so it took care of it. I also went into my "add/remove programs" and there was a "CiD" thing in there so I deleted that too. Havent had a pop-up since. Thnx again!I'm glad you're not getting ANYMORE pop-ups, but I feel obligated to STRONGLY urge you to complete the rest of the instructions. Lop isn't the sort of infection to typically go away so easily. It's one that likes to linger. Just because you're not seeing any symptoms, that doesn't necessarily mean you're all clear. | |
| 2772. | Solve : Re: CID Pop-ups ??? | 
| Answer» Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. 
 --------------------\\ Lop S&D 4.2.5-0 XP/Vista Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : AMD Athlon(tm)64 X2 Dual Core Processor 4400+ ) BIOS : BIOS Date: 10/26/06 18:30:08 Ver: 08.00.12 USER : Andy ( Administrator ) BOOT : Normal boot Antivirus : AVG Anti-Virus Free 8.0 (Activated) C:\ (Local Disk) - NTFS - Total:74 Go (Free:9 Go) D:\ (CD or DVD) E:\ (Local Disk) - NTFS - Total:232 Go (Free:177 Go) J:\ (CD or DVD) "C:\Lop SD" ( MAJ : 19-12-2008|23:40 ) Option : [2] ( Thu 04/30/2009|17:48 ) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\INTERNET SPAM SUPPORT AUDIO\BLUE INFO.dat Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\INTERNET SPAM SUPPORT AUDIO\BLUE INFO.exe Deleted! - C:\WINDOWS\Tasks\8069061C808AB104.job Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\INTERNET SPAM SUPPORT AUDIO Deleted! - C:\Program Files\signba~1 - [ Hosts file ] .. Restored! \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Listing folders in APPLIC~1 [04/13/2009|11:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {7972B2E5-3E09-4E5E-81B7-FE5819D6772F} [10/31/2008|10:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {D5ABFFAD-D592-4F98-B02B-587125B4801F} [12/27/2008|12:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ acccore [01/09/2009|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe [07/20/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ahead [12/27/2008|12:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AIM Toolbar [12/27/2008|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL [12/27/2008|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP [07/11/2008|11:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple [07/11/2008|11:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer [03/02/2009|12:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Autodesk [01/31/2009|09:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avg8 [10/31/2008|09:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVS4YOU [02/06/2009|11:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BUFFERZONE [07/20/2008|11:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink [02/06/2009|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DassaultSystemes [10/31/2008|10:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DriverScanner [01/09/2009|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FLEXnet [04/27/2009|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FloodLightGames [11/27/2008|09:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google [04/30/2009|11:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google Updater [11/27/2008|12:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IM [11/27/2008|12:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IncrediMail [08/27/2008|09:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield [12/11/2008|01:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InterAction studios [12/11/2008|02:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ iWin Games [07/11/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft [08/27/2008|07:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LightScribe [03/26/2009|10:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LogiShrd [03/26/2009|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech [12/28/2008|05:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Macrovision [04/30/2009|03:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes [03/14/2009|01:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft [11/12/2008|04:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NeoEdge Networks [07/20/2008|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nero [07/20/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles [08/03/2008|01:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Drivers HeadQuarters [04/27/2009|03:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PlayFirst [04/27/2009|03:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ RealArcade [08/27/2008|09:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio [08/27/2008|09:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic [10/29/2008|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SonyPicturesGames [04/15/2009|01:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy [04/30/2009|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com [04/28/2009|06:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP [07/29/2008|03:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia [07/11/2008|11:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage [02/10/2009|02:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! [01/19/2009|03:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion [12/27/2008|12:57] C:\DOCUME~1\Andy\APPLIC~1\ acccore [01/10/2009|09:07] C:\DOCUME~1\Andy\APPLIC~1\ Adobe [01/15/2009|04:09] C:\DOCUME~1\Andy\APPLIC~1\ Ahead [08/06/2008|08:22] C:\DOCUME~1\Andy\APPLIC~1\ Apple Computer [07/12/2008|01:33] C:\DOCUME~1\Andy\APPLIC~1\ Auslogics [03/02/2009|12:47] C:\DOCUME~1\Andy\APPLIC~1\ Autodesk [10/31/2008|09:34] C:\DOCUME~1\Andy\APPLIC~1\ AVS4YOU [07/11/2008|11:50] C:\DOCUME~1\Andy\APPLIC~1\ Camtech [01/03/2009|08:50] C:\DOCUME~1\Andy\APPLIC~1\ com.adobe.mauby.4875E02D9FB21EE389F73B8 D1702B320485DF8CE.1 [07/21/2008|12:23] C:\DOCUME~1\Andy\APPLIC~1\ CyberLink [02/06/2009|11:52] C:\DOCUME~1\Andy\APPLIC~1\ DassaultSystemes [07/30/2008|06:57] C:\DOCUME~1\Andy\APPLIC~1\ DivX [03/16/2009|10:56] C:\DOCUME~1\Andy\APPLIC~1\ dvdcss [02/06/2009|11:52] C:\DOCUME~1\Andy\APPLIC~1\ EDrawings [04/27/2009|12:32] C:\DOCUME~1\Andy\APPLIC~1\ FloodLightGames [07/22/2008|10:12] C:\DOCUME~1\Andy\APPLIC~1\ Google [01/01/2009|10:31] C:\DOCUME~1\Andy\APPLIC~1\ Help [07/11/2008|10:04] C:\DOCUME~1\Andy\APPLIC~1\ Identities [03/26/2009|10:16] C:\DOCUME~1\Andy\APPLIC~1\ InstallShield [04/15/2009|12:32] C:\DOCUME~1\Andy\APPLIC~1\ Joost [03/26/2009|10:17] C:\DOCUME~1\Andy\APPLIC~1\ Logitech [11/12/2008|04:15] C:\DOCUME~1\Andy\APPLIC~1\ Macromedia [04/30/2009|03:04] C:\DOCUME~1\Andy\APPLIC~1\ Malwarebytes [10/31/2008|09:45] C:\DOCUME~1\Andy\APPLIC~1\ Media Player Classic [01/18/2009|12:36] C:\DOCUME~1\Andy\APPLIC~1\ Microsoft [10/17/2008|10:32] C:\DOCUME~1\Andy\APPLIC~1\ Move Networks [07/11/2008|11:37] C:\DOCUME~1\Andy\APPLIC~1\ Mozilla [04/30/2009|05:36] C:\DOCUME~1\Andy\APPLIC~1\ OpenOffice.org2 [04/27/2009|03:48] C:\DOCUME~1\Andy\APPLIC~1\ PlayFirst [03/20/2009|12:41] C:\DOCUME~1\Andy\APPLIC~1\ Roxio [07/11/2008|11:19] C:\DOCUME~1\Andy\APPLIC~1\ Sun [04/30/2009|12:28] C:\DOCUME~1\Andy\APPLIC~1\ SUPERAntiSpyware.com [04/22/2009|10:19] C:\DOCUME~1\Andy\APPLIC~1\ U3 [10/31/2008|10:05] C:\DOCUME~1\Andy\APPLIC~1\ Uniblue [04/13/2009|02:31] C:\DOCUME~1\Andy\APPLIC~1\ vlc [12/06/2008|10:54] C:\DOCUME~1\Andy\APPLIC~1\ Vso [10/30/2008|09:42] C:\DOCUME~1\Andy\APPLIC~1\ Yahoo! [07/11/2008|09:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft [01/18/2009|12:36] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft [08/27/2008|09:28] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio [01/18/2009|12:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [04/27/2009 11:48 PM][--a------] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [04/30/2009 05:20 PM][--a------] C:\WINDOWS\tasks\Google Software Updater.job [04/30/2009 01:40 AM][--a------] C:\WINDOWS\tasks\Norton Security Scan for Andy.job [04/30/2009 05:22 PM][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job [04/30/2009 05:19 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT [08/04/2004 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [01/09/2009|10:24] C:\Program Files\ Adobe [12/27/2008|12:57] C:\Program Files\ AIM Toolbar [12/27/2008|12:57] C:\Program Files\ AIM6 [07/11/2008|10:56] C:\Program Files\ Analog Devices [04/13/2009|11:43] C:\Program Files\ Angle Interactive [03/02/2009|12:47] C:\Program Files\ AnswerWorks 4.0 [07/11/2008|11:40] C:\Program Files\ Apple Software Update [07/23/2008|10:09] C:\Program Files\ Ares [07/11/2008|11:49] C:\Program Files\ Auslogics [03/02/2009|12:00] C:\Program Files\ AutoCAD 2004 [03/02/2009|12:49] C:\Program Files\ Autodesk [07/11/2008|11:11] C:\Program Files\ AVG [01/18/2009|12:07] C:\Program Files\ AVS4YOU [07/11/2008|11:41] C:\Program Files\ Bonjour [07/11/2008|11:50] C:\Program Files\ Camtech [07/11/2008|11:43] C:\Program Files\ CCleaner [04/30/2009|02:51] C:\Program Files\ Common Files [07/11/2008|09:55] C:\Program Files\ ComPlus Applications [07/20/2008|11:07] C:\Program Files\ CyberLink [11/02/2008|11:53] C:\Program Files\ DIFX [04/12/2009|04:48] C:\Program Files\ DivX [01/14/2009|09:17] C:\Program Files\ dvd43 [11/19/2008|03:43] C:\Program Files\ DVDFab 5 [01/03/2009|08:42] C:\Program Files\ ElcomSoft [04/30/2009|12:12] C:\Program Files\ EsetOnlineScanner [11/27/2008|09:40] C:\Program Files\ Google [03/26/2009|10:16] C:\Program Files\ InstallShield Installation Information [03/27/2009|09:52] C:\Program Files\ Intel Desktop Board [08/27/2008|09:28] C:\Program Files\ InterActual [04/30/2009|09:15] C:\Program Files\ Internet Explorer [07/11/2008|11:50] C:\Program Files\ IObit [07/11/2008|11:41] C:\Program Files\ iPod [07/11/2008|11:41] C:\Program Files\ iTunes [04/30/2009|03:41] C:\Program Files\ Java [07/20/2008|11:31] C:\Program Files\ Joost [11/09/2008|12:01] C:\Program Files\ JoshMadison [04/13/2009|11:42] C:\Program Files\ Lavasoft [03/26/2009|10:16] C:\Program Files\ Logitech [11/02/2008|11:55] C:\Program Files\ LogWorks3 [04/30/2009|03:03] C:\Program Files\ Malwarebytes' Anti-Malware [08/14/2008|07:43] C:\Program Files\ Messenger [03/14/2009|01:48] C:\Program Files\ Microsoft [07/11/2008|09:58] C:\Program Files\ microsoft frontpage [12/27/2008|02:01] C:\Program Files\ Microsoft Office [04/21/2009|03:47] C:\Program Files\ Microsoft Silverlight [07/11/2008|10:41] C:\Program Files\ Movie Maker [04/29/2009|08:06] C:\Program Files\ Mozilla Firefox [04/30/2009|09:18] C:\Program Files\ MSBuild [11/09/2008|10:10] C:\Program Files\ MSECache [03/14/2009|01:47] C:\Program Files\ MSN [07/11/2008|09:55] C:\Program Files\ MSN Gaming Zone [07/21/2008|08:40] C:\Program Files\ MSXML 4.0 [07/12/2008|07:45] C:\Program Files\ Nero [08/24/2008|01:09] C:\Program Files\ NETGEAR [07/11/2008|10:40] C:\Program Files\ NetMeeting [04/30/2009|05:19] C:\Program Files\ NoAdware [04/29/2009|10:00] C:\Program Files\ Norton Security Scan [04/28/2009|06:14] C:\Program Files\ Oberon Media [07/11/2008|09:55] C:\Program Files\ Online Services [11/02/2008|11:52] C:\Program Files\ OpenECU [07/11/2008|11:42] C:\Program Files\ OpenOffice.org 2.4 [07/11/2008|10:40] C:\Program Files\ Outlook Express [12/27/2008|12:48] C:\Program Files\ OU-VPN [03/26/2009|09:56] C:\Program Files\ PC Drivers HeadQuarters [07/11/2008|11:40] C:\Program Files\ QuickTime [04/27/2009|04:51] C:\Program Files\ RealArcade [04/30/2009|09:18] C:\Program Files\ Reference Assemblies [11/02/2008|11:49] C:\Program Files\ RomRaider [08/27/2008|09:06] C:\Program Files\ Roxio [08/27/2008|09:05] C:\Program Files\ SightSpeed [07/11/2008|11:44] C:\Program Files\ Spybot - Search & Destroy [08/04/2008|07:49] C:\Program Files\ Super DVD Creator 8.5 [04/30/2009|12:28] C:\Program Files\ SUPERAntiSpyware [08/05/2008|11:19] C:\Program Files\ SystemRequirementsLab [04/30/2009|03:58] C:\Program Files\ Trend Micro [07/21/2008|11:15] C:\Program Files\ TVAnts [10/31/2008|10:05] C:\Program Files\ Uniblue [03/27/2009|09:54] C:\Program Files\ Unibrain [12/27/2008|02:06] C:\Program Files\ Uninstall Information [10/31/2008|12:22] C:\Program Files\ VideoLAN [04/30/2009|05:48] C:\Program Files\ Viewpoint [07/11/2008|11:54] C:\Program Files\ Windows Defender [07/12/2008|12:45] C:\Program Files\ Windows Media Connect 2 [07/12/2008|12:45] C:\Program Files\ Windows Media Player [07/11/2008|10:40] C:\Program Files\ Windows NT [07/11/2008|09:57] C:\Program Files\ WindowsUpdate [08/29/2008|07:39] C:\Program Files\ WMPCI54G WLAN Monitor [07/11/2008|09:58] C:\Program Files\ xerox [08/27/2008|09:05] C:\Program Files\ Xingtone [10/31/2008|09:44] C:\Program Files\ XP Codec Pack [04/13/2009|01:10] C:\Program Files\ XtalViD-Codec [04/13/2009|02:21] C:\Program Files\ Xvid [04/13/2009|12:51] C:\Program Files\ Xvid Decoder [02/10/2009|02:27] C:\Program Files\ Yahoo! --------------------\\ Listing Folders in C:\Program Files\Common Files [01/09/2009|10:27] C:\Program Files\Common Files\ Adobe [07/19/2008|09:14] C:\Program Files\Common Files\ Adobe AIR [07/29/2008|03:48] C:\Program Files\Common Files\ Ahead [12/27/2008|12:56] C:\Program Files\Common Files\ AOL [07/11/2008|11:40] C:\Program Files\Common Files\ Apple [03/02/2009|12:51] C:\Program Files\Common Files\ Autodesk Shared [01/18/2009|12:07] C:\Program Files\Common Files\ AVSMedia [12/27/2008|02:02] C:\Program Files\Common Files\ Designer [12/27/2008|12:48] C:\Program Files\Common Files\ Deterministic Networks [04/12/2009|04:47] C:\Program Files\Common Files\ DivX Shared [08/27/2008|08:55] C:\Program Files\Common Files\ InstallShield [07/11/2008|11:20] C:\Program Files\Common Files\ Java [07/19/2008|11:05] C:\Program Files\Common Files\ LightScribe [03/27/2009|09:43] C:\Program Files\Common Files\ Logitech [03/02/2009|12:00] C:\Program Files\Common Files\ Macrovision Shared [12/27/2008|02:02] C:\Program Files\Common Files\ Microsoft Shared [07/11/2008|09:56] C:\Program Files\Common Files\ MSSoap [07/11/2008|04:48] C:\Program Files\Common Files\ ODBC [08/27/2008|08:55] C:\Program Files\Common Files\ Roxio Shared [07/11/2008|09:56] C:\Program Files\Common Files\ Services [08/27/2008|08:55] C:\Program Files\Common Files\ SightSpeed [12/27/2008|12:57] C:\Program Files\Common Files\ Software Update Utility [02/06/2009|11:42] C:\Program Files\Common Files\ SolidWorks Shared [08/27/2008|09:06] C:\Program Files\Common Files\ Sonic Shared [07/11/2008|04:48] C:\Program Files\Common Files\ SpeechEngines [08/27/2008|09:06] C:\Program Files\Common Files\ SureThing Shared [04/26/2009|10:01] C:\Program Files\Common Files\ Symantec Shared [07/11/2008|10:40] C:\Program Files\Common Files\ System [04/30/2009|12:27] C:\Program Files\Common Files\ Wise Installation Wizard --------------------\\ Process ( 62 Processes ) ... OK ! --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders No Lop folder found ! --------------------\\ Searching within the Registry ..... OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-30 17:49:18 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Searching for other infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\Andy\My Documents\My Pictures\heads crack.jpg [F:5][D:2]-> C:\DOCUME~1\Andy\LOCALS~1\Temp [F:24][D:0]-> C:\DOCUME~1\Andy\Cookies [F:193][D:7]-> C:\DOCUME~1\Andy\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - Thu 04/30/2009|16:23 - Option : [1] 2 - "C:\Lop SD\LopR_2.txt" - Thu 04/30/2009|17:50 - Option : [2] --------------------\\ Scan completed at 17:50:28 ok now what ?? when can i just BLOW this thing (computer) up ?? or is their hope for it yet ?? It's looking better so far. Hopefully we can finish up in a few more steps. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix Also let me know if you are still getting the popups and how the computer is running.you are such a blessing thank you i will let you know not sure if i still want to kill the computer or the boyfriend just yet The computer didn't do it by itself... i know but who ever is doing the downloading of the code stuff i m fixing to put a Knot on his head ha ha any way i have the 2 logs here tComboFix 09-04-30.05 - Andy 04/30/2009 18:41.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1418 [GMT -5:00] Running from: c:\documents and settings\Andy\Desktop\ComboFix.exe1.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) . ((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 ))))))))))))))))))))))))))))))) . 2009-04-30 22:08 . 2009-04-30 22:08--------d-----wC:\_OTMoveIt 2009-04-30 21:19 . 2009-04-30 22:50--------d-----wC:\Lop SD 2009-04-30 20:49 . 2009-04-30 20:58--------d-----wc:\program files\Trend Micro 2009-04-30 20:04 . 2009-04-30 20:04--------d-----wc:\documents and settings\Andy\Application Data\Malwarebytes 2009-04-30 20:03 . 2009-04-06 20:3215504----a-wc:\windows\system32\drivers\mbam.sys 2009-04-30 20:03 . 2009-04-06 20:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys 2009-04-30 20:03 . 2009-04-30 20:03--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes 2009-04-30 20:03 . 2009-04-30 20:03--------d-----wc:\program files\Malwarebytes' Anti-Malware 2009-04-30 19:41 . 2009-04-30 22:19--------d-----wc:\program files\NoAdware 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\program files\SUPERAntiSpyware 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\documents and settings\Andy\Application Data\SUPERAntiSpyware.com 2009-04-30 17:27 . 2009-04-30 17:27--------d-----wc:\program files\Common Files\Wise Installation Wizard 2009-04-30 15:31 . 2009-04-30 17:12--------d-----wc:\program files\EsetOnlineScanner 2009-04-30 14:19 . 2009-04-30 14:19--------d-----wc:\windows\system32\XPSViewer 2009-04-30 14:18 . 2009-04-30 14:18--------d-----wc:\program files\MSBuild 2009-04-30 14:18 . 2009-04-30 14:18--------d-----wc:\program files\Reference Assemblies 2009-04-30 14:18 . 2008-07-06 12:06117760------wc:\windows\system32\prntvpt.dll 2009-04-30 14:18 . 2008-07-06 12:0689088-c----wc:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-30 14:18 . 2008-07-06 10:50597504-c----wc:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-30 14:18 . 2008-07-06 12:06575488-c----wc:\windows\system32\dllcache\xpsshhdr.dll 2009-04-30 14:18 . 2008-07-06 12:06575488------wc:\windows\system32\xpsshhdr.dll 2009-04-30 14:18 . 2008-07-06 12:061676288-c----wc:\windows\system32\dllcache\xpssvcs.dll 2009-04-30 14:18 . 2008-07-06 12:061676288------wc:\windows\system32\xpssvcs.dll 2009-04-30 14:18 . 2009-04-30 14:21--------d-----wc:\windows\SxsCaPendDel 2009-04-27 20:48 . 2009-04-27 20:48--------d-----wc:\documents and settings\Andy\Application Data\PlayFirst 2009-04-27 20:48 . 2009-04-27 20:48--------d-----wc:\documents and settings\All Users\Application Data\PlayFirst 2009-04-27 20:47 . 2009-04-27 21:51--------d-----wC:\My Games 2009-04-27 20:47 . 2009-04-27 20:47--------d-----wc:\documents and settings\All Users\Application Data\RealArcade 2009-04-27 20:47 . 2009-04-27 20:47--------d-----wC:\users 2009-04-27 20:46 . 2009-04-27 21:51--------d-----wc:\program files\RealArcade 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\All Users\Application Data\FloodLightGames 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\Andy\Saved Games 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\Andy\Application Data\FloodLightGames 2009-04-21 04:48 . 2009-04-21 04:48--------d-sh--wc:\documents and settings\NetworkService\IETldCache 2009-04-20 04:28 . 2009-04-20 04:28--------d-sh--wc:\documents and settings\Andy\IECompatCache 2009-04-20 04:22 . 2009-04-20 04:22--------d-sh--wc:\documents and settings\Andy\PrivacIE 2009-04-20 04:19 . 2009-04-20 04:19--------d-sh--wc:\documents and settings\LocalService\IETldCache 2009-04-20 04:19 . 2009-04-20 04:19--------d-sh--wc:\documents and settings\Andy\IETldCache 2009-04-20 04:18 . 2009-04-20 04:18--------d-----wc:\windows\ie8updates 2009-04-20 04:16 . 2009-04-20 04:16--------dc-h--wc:\windows\ie8 2009-04-20 04:14 . 2009-02-28 04:55105984-c----wc:\windows\system32\dllcache\iecompat.dll 2009-04-16 17:04 . 2009-03-06 14:22284160-c----wc:\windows\system32\dllcache\pdh.dll 2009-04-16 17:04 . 2009-02-09 12:10401408-c----wc:\windows\system32\dllcache\rpcss.dll 2009-04-16 17:04 . 2009-02-06 11:11110592-c----wc:\windows\system32\dllcache\services.exe 2009-04-16 17:04 . 2009-02-09 12:10473600-c----wc:\windows\system32\dllcache\fastprox.dll 2009-04-16 17:04 . 2009-02-06 10:10227840-c----wc:\windows\system32\dllcache\wmiprvse.exe 2009-04-16 17:04 . 2009-02-09 12:10453120-c----wc:\windows\system32\dllcache\wmiprvsd.dll 2009-04-16 17:04 . 2009-02-09 12:10729088-c----wc:\windows\system32\dllcache\lsasrv.dll 2009-04-16 17:04 . 2009-02-09 12:10617472-c----wc:\windows\system32\dllcache\advapi32.dll 2009-04-16 17:04 . 2009-02-09 12:10714752-c----wc:\windows\system32\dllcache\ntdll.dll 2009-04-16 17:04 . 2008-05-03 11:552560------wc:\windows\system32\xpsp4res.dll 2009-04-16 17:04 . 2008-04-21 12:08215552-c----wc:\windows\system32\dllcache\wordpad.exe 2009-04-15 05:32 . 2009-04-15 05:32--------d-----wc:\documents and settings\Andy\Application Data\Joost 2009-04-15 05:32 . 2009-04-15 05:32--------d-----wc:\documents and settings\Andy\Local Settings\Application Data\Joost 2009-04-14 12:23 . 2009-03-09 19:0615688----a-wc:\windows\system32\lsdelete.exe 2009-04-14 04:48 . 2009-04-28 04:4864160----a-wc:\windows\system32\drivers\Lbd.sys 2009-04-14 04:43 . 2009-04-30 22:15--------d-----wC:\ProgramData 2009-04-14 04:43 . 2009-04-14 04:43--------d-----wc:\program files\Angle Interactive 2009-04-14 04:42 . 2009-04-14 04:42--------dc-h--wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-04-14 04:42 . 2009-04-14 04:42--------d-----wc:\program files\Lavasoft 2009-04-13 07:38 . 2009-04-13 07:38--------d-----wc:\windows\system32\help 2009-04-13 07:21 . 2008-12-05 02:42815104----a-wc:\windows\system32\xvidcore.dll 2009-04-13 07:21 . 2008-12-05 02:46180224----a-wc:\windows\system32\xvidvfw.dll 2009-04-13 07:21 . 2009-04-13 07:21--------d-----wc:\program files\Xvid 2009-04-13 07:07 . 2009-04-13 07:31--------d-----wc:\documents and settings\Andy\Application Data\vlc 2009-04-13 06:08 . 2009-04-13 06:10--------d-----wc:\program files\XtalViD-Codec 2009-04-13 05:45 . 2009-04-13 05:51--------d-----wc:\program files\Xvid Decoder 2009-04-12 21:47 . 2009-04-12 21:47--------d-----wc:\program files\Common Files\DivX Shared 2009-04-10 16:39 . 2009-04-28 23:14--------d-----wc:\program files\Oberon Media . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-30 22:48 . 2008-12-27 17:57--------d-----wc:\program files\Viewpoint 2009-04-30 22:22 . 2008-07-12 04:5467848----a-wc:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-30 20:41 . 2008-07-12 04:20--------d-----wc:\program files\Java 2009-04-30 03:00 . 2009-02-15 14:52--------d-----wc:\program files\Norton Security Scan 2009-04-27 03:01 . 2009-02-15 14:52--------d-----wc:\program files\Common Files\Symantec Shared 2009-04-21 20:47 . 2008-08-04 04:34--------d-----wc:\program files\Microsoft Silverlight 2009-04-12 21:48 . 2008-07-30 11:49--------d-----wc:\program files\DivX 2009-03-28 02:54 . 2009-03-28 02:54--------d-----wc:\program files\Unibrain 2009-03-28 02:52 . 2009-03-28 02:52--------d-----wc:\program files\Intel Desktop Board 2009-03-28 02:43 . 2009-03-27 03:16--------d-----wc:\program files\Common Files\Logitech 2009-03-27 03:17 . 2009-03-27 03:170---ha-wc:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-03-27 03:17 . 2009-03-27 03:170---ha-wc:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-03-27 03:16 . 2009-03-27 03:16--------d-----wc:\program files\Logitech 2009-03-27 03:16 . 2008-07-12 03:56--------d--h--wc:\program files\InstallShield Installation Information 2009-03-27 02:56 . 2009-03-27 02:56--------d-----wc:\program files\PC Drivers HeadQuarters 2009-03-14 06:48 . 2009-03-14 06:48--------d-----wc:\program files\Microsoft 2009-03-14 06:47 . 2009-01-18 03:28410984----a-wc:\windows\system32\deploytk.dll 2009-03-08 09:34 . 2004-08-04 12:00914944----a-wc:\windows\system32\wininet.dll 2009-03-08 09:34 . 2004-08-04 12:0043008----a-wc:\windows\system32\licmgr10.dll 2009-03-08 09:33 . 2004-08-04 12:0018944----a-wc:\windows\system32\corpol.dll 2009-03-08 09:33 . 2004-08-04 12:00420352----a-wc:\windows\system32\vbscript.dll 2009-03-08 09:32 . 2004-08-04 12:0072704----a-wc:\windows\system32\admparse.dll 2009-03-08 09:32 . 2004-08-04 12:0071680----a-wc:\windows\system32\iesetup.dll 2009-03-08 09:31 . 2004-08-04 12:0034816----a-wc:\windows\system32\imgutil.dll 2009-03-08 09:31 . 2004-08-04 12:0048128----a-wc:\windows\system32\mshtmler.dll 2009-03-08 09:31 . 2004-08-04 12:0045568----a-wc:\windows\system32\mshta.exe 2009-03-08 09:22 . 2004-08-04 12:00156160----a-wc:\windows\system32\msls31.dll 2009-03-06 14:22 . 2004-08-04 12:00284160----a-wc:\windows\system32\pdh.dll 2009-03-02 05:51 . 2008-12-27 19:05--------d-----wc:\program files\Common Files\Autodesk Shared 2009-03-02 05:49 . 2008-12-27 19:05--------d-----wc:\program files\Autodesk 2009-03-02 05:47 . 2008-12-28 09:42--------d-----wc:\program files\AnswerWorks 4.0 2009-03-02 05:00 . 2008-12-28 09:41--------d-----wc:\program files\AutoCAD 2004 2009-03-02 05:00 . 2009-01-08 04:58--------d-----wc:\program files\Common Files\Macrovision Shared 2009-02-24 19:34 . 2009-02-24 19:3490112----a-wc:\windows\system32\dpl100.dll 2009-02-24 19:34 . 2009-02-24 19:34823296----a-wc:\windows\system32\divx_xx0c.dll 2009-02-24 19:34 . 2009-02-24 19:34823296----a-wc:\windows\system32\divx_xx07.dll 2009-02-24 19:34 . 2009-02-24 19:34815104----a-wc:\windows\system32\divx_xx0a.dll 2009-02-24 19:34 . 2009-02-24 19:34802816----a-wc:\windows\system32\divx_xx11.dll 2009-02-24 19:34 . 2009-02-24 19:34684032----a-wc:\windows\system32\DivX.dll 2009-02-17 04:17 . 2008-07-12 03:52453152----a-wc:\windows\system32\NVUNINST.EXE 2009-02-09 12:10 . 2004-08-04 12:00729088----a-wc:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2004-08-04 12:00714752----a-wc:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2004-08-04 12:00617472----a-wc:\windows\system32\advapi32.dll 2009-02-09 12:10 . 2004-08-04 12:00401408----a-wc:\windows\system32\rpcss.dll 2009-02-09 11:13 . 2004-08-04 12:001846784----a-wc:\windows\system32\win32k.sys 2009-02-06 11:11 . 2004-08-04 12:00110592----a-wc:\windows\system32\services.exe 2009-02-06 11:06 . 2004-08-04 12:002145280----a-wc:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2004-08-04 12:0035328----a-wc:\windows\system32\sc.exe 2009-02-06 10:32 . 2004-08-03 22:592023936----a-wc:\windows\system32\ntkrnlpa.exe 2009-02-03 19:59 . 2004-08-04 12:0056832----a-wc:\windows\system32\secur32.dll 2009-01-31 14:19 . 2009-01-18 17:3810520----a-wc:\windows\system32\avgrsstx.dll 2009-01-31 14:19 . 2009-01-18 17:38325128----a-wc:\windows\system32\drivers\avgldx86.sys 2009-01-31 14:18 . 2009-01-18 17:38107272----a-wc:\windows\system32\drivers\avgtdix.sys 2009-02-24 19:34 . 2009-02-24 19:341044480----a-wc:\program files\mozilla firefox\plugins\libdivx.dll 2009-02-24 19:34 . 2009-02-24 19:34200704----a-wc:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((( [emailprotected]_23.16.36 ))))))))))))))))))))))))))))))))))))))))) . + 2009-04-30 23:30 . 2009-04-30 23:3016384 c:\windows\Temp\Perflib_Perfdata_148.dat + 2008-07-11 21:48 . 2009-04-30 23:30259840 c:\windows\system32\FNTCACHE.DAT - 2008-07-11 21:48 . 2009-04-30 14:21259840 c:\windows\system32\FNTCACHE.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading POINTS )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "LightScribe Control PANEL"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-28 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-07-12 925696] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-03 116040] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-09 289064] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 221184] "DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400] "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 1116920] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376] "dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-11-18 827904] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-14 148888] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-28 516440] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-27 692224] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 17:05356352----a-wc:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-01-31 14:1910520----a-wc:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^The University of Oklahoma OU-VPN Client.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\The University of Oklahoma OU-VPN Client.lnk backup=c:\windows\pss\The University of Oklahoma OU-VPN Client.lnkCommon Startup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"= R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-28 953168] R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2002-04-11 16194] R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [2009-04-27 101936] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-28 64160] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-01-31 325128] S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-01-31 107272] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944] S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-31 903960] S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264] S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656] S2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\DRIVERS\ubsbm.sys [2005-07-27 14080] S2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\DRIVERS\ubumapi.sys [2005-07-27 36352] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-04-28 7408] S3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\DRIVERS\ubohci.sys [2005-07-27 77056] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K] \Shell\AutoRun\command - K:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8c6579c-598d-11dd-8679-0016b6531647}] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-04-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:48] 2009-04-30 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-23 23:00] 2009-04-30 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20] 2009-04-30 c:\windows\Tasks\Norton Security Scan for Andy.job - c:\program files\Norton Security Scan\Nss.exe [2008-09-19 01:20] . . ------- Supplementary Scan ------- . uLocal Page = \blank.htm uStart Page = hxxp://www.cnn.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2xnqv335.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - prefs.js: browser.search.selectedEngine - FireSearch FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-30 18:43 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1040) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(3584) c:\windows\system32\nview.dll c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll c:\program files\Common Files\Ahead\Lib\MFC71U.DLL c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-04-30 18:44 ComboFix-quarantined-files.txt 2009-04-30 23:44 ComboFix2.txt 2009-04-30 23:17 Pre-Run: 9,526,657,024 bytes free Post-Run: 9,523,359,744 bytes free 296--- E O F ---2009-04-30 17:51 hey are ok bu the way the computer is running great at the moment no pop ups so far ComboFix 09-04-30.05 - Andy 04/30/2009 18:41.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1418 [GMT -5:00] Running from: c:\documents and settings\Andy\Desktop\ComboFix.exe1.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) . ((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 ))))))))))))))))))))))))))))))) . 2009-04-30 22:08 . 2009-04-30 22:08--------d-----wC:\_OTMoveIt 2009-04-30 21:19 . 2009-04-30 22:50--------d-----wC:\Lop SD 2009-04-30 20:49 . 2009-04-30 20:58--------d-----wc:\program files\Trend Micro 2009-04-30 20:04 . 2009-04-30 20:04--------d-----wc:\documents and settings\Andy\Application Data\Malwarebytes 2009-04-30 20:03 . 2009-04-06 20:3215504----a-wc:\windows\system32\drivers\mbam.sys 2009-04-30 20:03 . 2009-04-06 20:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys 2009-04-30 20:03 . 2009-04-30 20:03--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes 2009-04-30 20:03 . 2009-04-30 20:03--------d-----wc:\program files\Malwarebytes' Anti-Malware 2009-04-30 19:41 . 2009-04-30 22:19--------d-----wc:\program files\NoAdware 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\program files\SUPERAntiSpyware 2009-04-30 17:28 . 2009-04-30 17:28--------d-----wc:\documents and settings\Andy\Application Data\SUPERAntiSpyware.com 2009-04-30 17:27 . 2009-04-30 17:27--------d-----wc:\program files\Common Files\Wise Installation Wizard 2009-04-30 15:31 . 2009-04-30 17:12--------d-----wc:\program files\EsetOnlineScanner 2009-04-30 14:19 . 2009-04-30 14:19--------d-----wc:\windows\system32\XPSViewer 2009-04-30 14:18 . 2009-04-30 14:18--------d-----wc:\program files\MSBuild 2009-04-30 14:18 . 2009-04-30 14:18--------d-----wc:\program files\Reference Assemblies 2009-04-30 14:18 . 2008-07-06 12:06117760------wc:\windows\system32\prntvpt.dll 2009-04-30 14:18 . 2008-07-06 12:0689088-c----wc:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-30 14:18 . 2008-07-06 10:50597504-c----wc:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-30 14:18 . 2008-07-06 12:06575488-c----wc:\windows\system32\dllcache\xpsshhdr.dll 2009-04-30 14:18 . 2008-07-06 12:06575488------wc:\windows\system32\xpsshhdr.dll 2009-04-30 14:18 . 2008-07-06 12:061676288-c----wc:\windows\system32\dllcache\xpssvcs.dll 2009-04-30 14:18 . 2008-07-06 12:061676288------wc:\windows\system32\xpssvcs.dll 2009-04-30 14:18 . 2009-04-30 14:21--------d-----wc:\windows\SxsCaPendDel 2009-04-27 20:48 . 2009-04-27 20:48--------d-----wc:\documents and settings\Andy\Application Data\PlayFirst 2009-04-27 20:48 . 2009-04-27 20:48--------d-----wc:\documents and settings\All Users\Application Data\PlayFirst 2009-04-27 20:47 . 2009-04-27 21:51--------d-----wC:\My Games 2009-04-27 20:47 . 2009-04-27 20:47--------d-----wc:\documents and settings\All Users\Application Data\RealArcade 2009-04-27 20:47 . 2009-04-27 20:47--------d-----wC:\users 2009-04-27 20:46 . 2009-04-27 21:51--------d-----wc:\program files\RealArcade 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\All Users\Application Data\FloodLightGames 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\Andy\Saved Games 2009-04-27 17:32 . 2009-04-27 17:32--------d-----wc:\documents and settings\Andy\Application Data\FloodLightGames 2009-04-21 04:48 . 2009-04-21 04:48--------d-sh--wc:\documents and settings\NetworkService\IETldCache 2009-04-20 04:28 . 2009-04-20 04:28--------d-sh--wc:\documents and settings\Andy\IECompatCache 2009-04-20 04:22 . 2009-04-20 04:22--------d-sh--wc:\documents and settings\Andy\PrivacIE 2009-04-20 04:19 . 2009-04-20 04:19--------d-sh--wc:\documents and settings\LocalService\IETldCache 2009-04-20 04:19 . 2009-04-20 04:19--------d-sh--wc:\documents and settings\Andy\IETldCache 2009-04-20 04:18 . 2009-04-20 04:18--------d-----wc:\windows\ie8updates 2009-04-20 04:16 . 2009-04-20 04:16--------dc-h--wc:\windows\ie8 2009-04-20 04:14 . 2009-02-28 04:55105984-c----wc:\windows\system32\dllcache\iecompat.dll 2009-04-16 17:04 . 2009-03-06 14:22284160-c----wc:\windows\system32\dllcache\pdh.dll 2009-04-16 17:04 . 2009-02-09 12:10401408-c----wc:\windows\system32\dllcache\rpcss.dll 2009-04-16 17:04 . 2009-02-06 11:11110592-c----wc:\windows\system32\dllcache\services.exe 2009-04-16 17:04 . 2009-02-09 12:10473600-c----wc:\windows\system32\dllcache\fastprox.dll 2009-04-16 17:04 . 2009-02-06 10:10227840-c----wc:\windows\system32\dllcache\wmiprvse.exe 2009-04-16 17:04 . 2009-02-09 12:10453120-c----wc:\windows\system32\dllcache\wmiprvsd.dll 2009-04-16 17:04 . 2009-02-09 12:10729088-c----wc:\windows\system32\dllcache\lsasrv.dll 2009-04-16 17:04 . 2009-02-09 12:10617472-c----wc:\windows\system32\dllcache\advapi32.dll 2009-04-16 17:04 . 2009-02-09 12:10714752-c----wc:\windows\system32\dllcache\ntdll.dll 2009-04-16 17:04 . 2008-05-03 11:552560------wc:\windows\system32\xpsp4res.dll 2009-04-16 17:04 . 2008-04-21 12:08215552-c----wc:\windows\system32\dllcache\wordpad.exe 2009-04-15 05:32 . 2009-04-15 05:32--------d-----wc:\documents and settings\Andy\Application Data\Joost 2009-04-15 05:32 . 2009-04-15 05:32--------d-----wc:\documents and settings\Andy\Local Settings\Application Data\Joost 2009-04-14 12:23 . 2009-03-09 19:0615688----a-wc:\windows\system32\lsdelete.exe 2009-04-14 04:48 . 2009-04-28 04:4864160----a-wc:\windows\system32\drivers\Lbd.sys 2009-04-14 04:43 . 2009-04-30 22:15--------d-----wC:\ProgramData 2009-04-14 04:43 . 2009-04-14 04:43--------d-----wc:\program files\Angle Interactive 2009-04-14 04:42 . 2009-04-14 04:42--------dc-h--wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-04-14 04:42 . 2009-04-14 04:42--------d-----wc:\program files\Lavasoft 2009-04-13 07:38 . 2009-04-13 07:38--------d-----wc:\windows\system32\help 2009-04-13 07:21 . 2008-12-05 02:42815104----a-wc:\windows\system32\xvidcore.dll 2009-04-13 07:21 . 2008-12-05 02:46180224----a-wc:\windows\system32\xvidvfw.dll 2009-04-13 07:21 . 2009-04-13 07:21--------d-----wc:\program files\Xvid 2009-04-13 07:07 . 2009-04-13 07:31--------d-----wc:\documents and settings\Andy\Application Data\vlc 2009-04-13 06:08 . 2009-04-13 06:10--------d-----wc:\program files\XtalViD-Codec 2009-04-13 05:45 . 2009-04-13 05:51--------d-----wc:\program files\Xvid Decoder 2009-04-12 21:47 . 2009-04-12 21:47--------d-----wc:\program files\Common Files\DivX Shared 2009-04-10 16:39 . 2009-04-28 23:14--------d-----wc:\program files\Oberon Media . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-30 22:48 . 2008-12-27 17:57--------d-----wc:\program files\Viewpoint 2009-04-30 22:22 . 2008-07-12 04:5467848----a-wc:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-30 20:41 . 2008-07-12 04:20--------d-----wc:\program files\Java 2009-04-30 03:00 . 2009-02-15 14:52--------d-----wc:\program files\Norton Security Scan 2009-04-27 03:01 . 2009-02-15 14:52--------d-----wc:\program files\Common Files\Symantec Shared 2009-04-21 20:47 . 2008-08-04 04:34--------d-----wc:\program files\Microsoft Silverlight 2009-04-12 21:48 . 2008-07-30 11:49--------d-----wc:\program files\DivX 2009-03-28 02:54 . 2009-03-28 02:54--------d-----wc:\program files\Unibrain 2009-03-28 02:52 . 2009-03-28 02:52--------d-----wc:\program files\Intel Desktop Board 2009-03-28 02:43 . 2009-03-27 03:16--------d-----wc:\program files\Common Files\Logitech 2009-03-27 03:17 . 2009-03-27 03:170---ha-wc:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-03-27 03:17 . 2009-03-27 03:170---ha-wc:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-03-27 03:16 . 2009-03-27 03:16--------d-----wc:\program files\Logitech 2009-03-27 03:16 . 2008-07-12 03:56--------d--h--wc:\program files\InstallShield Installation Information 2009-03-27 02:56 . 2009-03-27 02:56--------d-----wc:\program files\PC Drivers HeadQuarters 2009-03-14 06:48 . 2009-03-14 06:48--------d-----wc:\program files\Microsoft 2009-03-14 06:47 . 2009-01-18 03:28410984----a-wc:\windows\system32\deploytk.dll 2009-03-08 09:34 . 2004-08-04 12:00914944----a-wc:\windows\system32\wininet.dll 2009-03-08 09:34 . 2004-08-04 12:0043008----a-wc:\windows\system32\licmgr10.dll 2009-03-08 09:33 . 2004-08-04 12:0018944----a-wc:\windows\system32\corpol.dll 2009-03-08 09:33 . 2004-08-04 12:00420352----a-wc:\windows\system32\vbscript.dll 2009-03-08 09:32 . 2004-08-04 12:0072704----a-wc:\windows\system32\admparse.dll 2009-03-08 09:32 . 2004-08-04 12:0071680----a-wc:\windows\system32\iesetup.dll 2009-03-08 09:31 . 2004-08-04 12:0034816----a-wc:\windows\system32\imgutil.dll 2009-03-08 09:31 . 2004-08-04 12:0048128----a-wc:\windows\system32\mshtmler.dll 2009-03-08 09:31 . 2004-08-04 12:0045568----a-wc:\windows\system32\mshta.exe 2009-03-08 09:22 . 2004-08-04 12:00156160----a-wc:\windows\system32\msls31.dll 2009-03-06 14:22 . 2004-08-04 12:00284160----a-wc:\windows\system32\pdh.dll 2009-03-02 05:51 . 2008-12-27 19:05--------d-----wc:\program files\Common Files\Autodesk Shared 2009-03-02 05:49 . 2008-12-27 19:05--------d-----wc:\program files\Autodesk 2009-03-02 05:47 . 2008-12-28 09:42--------d-----wc:\program files\AnswerWorks 4.0 2009-03-02 05:00 . 2008-12-28 09:41--------d-----wc:\program files\AutoCAD 2004 2009-03-02 05:00 . 2009-01-08 04:58--------d-----wc:\program files\Common Files\Macrovision Shared 2009-02-24 19:34 . 2009-02-24 19:3490112----a-wc:\windows\system32\dpl100.dll 2009-02-24 19:34 . 2009-02-24 19:34823296----a-wc:\windows\system32\divx_xx0c.dll 2009-02-24 19:34 . 2009-02-24 19:34823296----a-wc:\windows\system32\divx_xx07.dll 2009-02-24 19:34 . 2009-02-24 19:34815104----a-wc:\windows\system32\divx_xx0a.dll 2009-02-24 19:34 . 2009-02-24 19:34802816----a-wc:\windows\system32\divx_xx11.dll 2009-02-24 19:34 . 2009-02-24 19:34684032----a-wc:\windows\system32\DivX.dll 2009-02-17 04:17 . 2008-07-12 03:52453152----a-wc:\windows\system32\NVUNINST.EXE 2009-02-09 12:10 . 2004-08-04 12:00729088----a-wc:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2004-08-04 12:00714752----a-wc:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2004-08-04 12:00617472----a-wc:\windows\system32\advapi32.dll 2009-02-09 12:10 . 2004-08-04 12:00401408----a-wc:\windows\system32\rpcss.dll 2009-02-09 11:13 . 2004-08-04 12:001846784----a-wc:\windows\system32\win32k.sys 2009-02-06 11:11 . 2004-08-04 12:00110592----a-wc:\windows\system32\services.exe 2009-02-06 11:06 . 2004-08-04 12:002145280----a-wc:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2004-08-04 12:0035328----a-wc:\windows\system32\sc.exe 2009-02-06 10:32 . 2004-08-03 22:592023936----a-wc:\windows\system32\ntkrnlpa.exe 2009-02-03 19:59 . 2004-08-04 12:0056832----a-wc:\windows\system32\secur32.dll 2009-01-31 14:19 . 2009-01-18 17:3810520----a-wc:\windows\system32\avgrsstx.dll 2009-01-31 14:19 . 2009-01-18 17:38325128----a-wc:\windows\system32\drivers\avgldx86.sys 2009-01-31 14:18 . 2009-01-18 17:38107272----a-wc:\windows\system32\drivers\avgtdix.sys 2009-02-24 19:34 . 2009-02-24 19:341044480----a-wc:\program files\mozilla firefox\plugins\libdivx.dll 2009-02-24 19:34 . 2009-02-24 19:34200704----a-wc:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((( [emailprotected]_23.16.36 ))))))))))))))))))))))))))))))))))))))))) . + 2009-04-30 23:30 . 2009-04-30 23:3016384 c:\windows\Temp\Perflib_Perfdata_148.dat + 2008-07-11 21:48 . 2009-04-30 23:30259840 c:\windows\system32\FNTCACHE.DAT - 2008-07-11 21:48 . 2009-04-30 14:21259840 c:\windows\system32\FNTCACHE.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-28 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-07-12 925696] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-03 116040] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-09 289064] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 221184] "DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400] "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 1116920] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376] "dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-11-18 827904] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-14 148888] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-28 516440] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-27 692224] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 17:05356352----a-wc:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-01-31 14:1910520----a-wc:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^The University of Oklahoma OU-VPN Client.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\The University of Oklahoma OU-VPN Client.lnk backup=c:\windows\pss\The University of Oklahoma OU-VPN Client.lnkCommon Startup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"= R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-28 953168] R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2002-04-11 16194] R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [2009-04-27 101936] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-28 64160] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-01-31 325128] S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-01-31 107272] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944] S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-31 903960] S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264] S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656] S2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\DRIVERS\ubsbm.sys [2005-07-27 14080] S2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\DRIVERS\ubumapi.sys [2005-07-27 36352] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-04-28 7408] S3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\DRIVERS\ubohci.sys [2005-07-27 77056] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K] \Shell\AutoRun\command - K:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8c6579c-598d-11dd-8679-0016b6531647}] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-04-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:48] 2009-04-30 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-23 23:00] 2009-04-30 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20] 2009-04-30 c:\windows\Tasks\Norton Security Scan for Andy.job - c:\program files\Norton Security Scan\Nss.exe [2008-09-19 01:20] . . ------- Supplementary Scan ------- . uLocal Page = \blank.htm uStart Page = hxxp://www.cnn.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2xnqv335.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - prefs.js: browser.search.selectedEngine - FireSearch FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-30 18:43 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1040) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(3584) c:\windows\system32\nview.dll c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll c:\program files\Common Files\Ahead\Lib\MFC71U.DLL c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-04-30 18:44 ComboFix-quarantined-files.txt 2009-04-30 23:44 ComboFix2.txt 2009-04-30 23:17 Pre-Run: 9,526,657,024 bytes free Post-Run: 9,523,359,744 bytes free 296--- E O F ---2009-04-30 17:51 thank you so much for your time and effort 
 Click START then RUN Now type C:\Lop SD\Uninstal.exe in the runbox. Then click OK. ---------- 
 
 ---------- Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator 
 Note that your system will run slower for a reboot or two after having used this tool so don't panic. ---------- Download OTCleanIt.exe and save it to your Desktop. 
 Important: Restart the computer before continuing. ---------- How is everything now? doing great thank you so very Much I have one Free SUPERAntiSpyware Professional Edition Lifetime Key I am giving away. If you are interested then visit my blog here: http://evilfantasy.wordpress.com/2009/04/28/free-superantispyware-pro-giveaway/ ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Thank you once again the computer seems to be running Great now | |
| 2773. | Solve : Malware Removal 5 Step Program? | 
| Answer» I have followed all the steps in the Malware REMOVAL thread and here are my reports. | |
| 2774. | Solve : How many anti-whatever programs do you run?? | 
| Answer» The reason I ask is because I'll run Ad-Aware and it'll find like 18 infected files. Then I'll run Panda and it'll find 256 infected files. Should I just run Panda and forget ad-Aware or is it best to run as MANY different programs as possible to get as much junk out of my COMPUTER as possible?Most likely, Panda is detecting Tracking Cookies. It's common for a computer to end up with lots of those. Ad Aware is probably finding the same STUFF.......nothing to get your nickers in a twist over | |
| 2775. | Solve : another iexplore? | 
| Answer» 1) Avast! Home Free Edition 2) AVG Free Edition 3) Avira AntiVir PERSONAL iexplore is behaving itself again. The machine seems much more efficient and I have UPDATED everything I can find. Thank you, again and again for all your wisdom. Now I think I will go GET a life! triciaYour welcome. Safe SURFING... | |
| 2776. | Solve : Its back..? | 
| Answer» yeah tea TIMER is off.  
 ---------- Download Alternate download link Note: Vista users must use Run As Administrator 
 Note that your system will run slower for a reboot or two after having used this tool so don't panic. ---------- Download OTCleanIt.exe and save it to your Desktop. 
 Important: Restart the computer before continuing. ---------- How is the computer running now? It brought a friend. Ive been ou of time so I havent run the scans. But something got mad and meaner than ever. Basic problems: Cant get on the internet (Says refusing to connect to the proxy server) THere is a thing in the network settings, apart from my connections, that says gateway connections. Its not MINE and when I click on it, my computer crashes to BSoD. When I COULD get online, every link I clicked went to a random search site. Eff my efffing computer. | |
| 2777. | Solve : forgot my logs to add? | 
| Answer» HI hope someone can HELP me.for about a month now my system running xp sp3 boots very very slow. also when i GO to open my browser (firefox) or my email program (thunderbird) they also take awhile to open but only on the FIRST try then they are fine till i shut down and restart.also i have ran my AVG and also stopzilla.they found a few things and took care of them. but i still have the same problem.can you point me in another direction to fix this problem.i have also ran chksdk and cleaned up the temp files. and did a defrag.not sure what else to try [attachment deleted by admin] | |
| 2778. | Solve : My pc has issues please help!? | 
| Answer» i will get that log on here asap thank you so much. im downloading combofix right now. Yes my browsers are all working now.here is the CF log R3 EraserUtilRebootDrv;EraserUtilRebootDrv; R3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184] R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2007-04-23 227328] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944] S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832] S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896] S2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\DRIVERS\nmsgopro.sys [2006-09-28 28672] S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424] S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2006-12-16 5504] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632] S3 PAC207;Basic Webcam;c:\windows\system32\DRIVERS\PFC027.SYS [2008-02-13 618112] --- Other Services/Drivers In Memory --- *NewlyCreated* - SASDIFSV *NewlyCreated* - SASKUTIL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2009-04-29 c:\windows\Tasks\User_Feed_Synchronization-{8DA8332C-7F4D-4621-AA07-FDDFF2794959}.job - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45] . - - - - ORPHANS REMOVED - - - - HKCU-Run-reSetup.exe - c:\users\John\Desktop\RESETU~2.EXE HKCU-Run-Eraser - c:\eraser\eraser.exe HKCU-Run-BellesBeautyBoutiqueSetup.exe - c:\users\John\Desktop\BELLES~2.EXE HKCU-Run-cec4f502 - c:\programdata\tumuwaku\tumuwaku.dll HKCU-Run-CPMcdf7c69e - c:\programdata\tosofove\tosofove.dll HKCU-Run-huyevetabi - c:\programdata\zuvirumu\zuvirumu.dll . ------- Supplementary Scan ------- . mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://www.shockwave.com/content/ghostfrenzy/sis/axhost.cab FF - ProfilePath - c:\users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ghopffb4.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - prefs.js: network.proxy.type - 4 FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll FF - plugin: c:\users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ghopffb4.default\extensions\[emailprotected]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll FF - plugin: c:\users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ghopffb4.default\extensions\[emailprotected]\plugins\npmozax.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-29 22:26 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\users\John\AppData\Roaming\GTek\GTUpdate\AUpdate\NMSSupport\DB\{1330EA23-8648-4CD3-883A-56F97A5B2012}.xml 794 bytes scan completed successfully hidden files: 1 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2383206740-1977817344-2628701725-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}\iexplore] @DACL=(02 0000) "Type"=dword:00000003 "Flags"=dword:00000000 "Time"=hex:d7,07,05,00,00,00,06,00,12,00,11,00,39,00,10,02 [HKEY_USERS\S-1-5-21-2383206740-1977817344-2628701725-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\iexplore] @DACL=(02 0000) "Type"=dword:00000003 "Flags"=dword:00000000 "Time"=hex:d7,07,05,00,00,00,06,00,12,00,11,00,39,00,1f,02 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Completion time: 2009-04-30 22:28 ComboFix-quarantined-files.txt 2009-04-30 03:28 Pre-Run: 219,747,774,464 bytes free Post-Run: 219,739,893,760 bytes free 365--- E O F ---2009-04-29 23:05 Quote c:\users\John\Downloads\ComboFix.exe ComboFix needs to be on the desktop to work properly. Please remove it from the downloads folder and place it on the desktop. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: knzxdvua Folder:: c:\programdata\tosofove c:\programdata\tumuwaku c:\users\All Users\tosofove c:\users\All Users\tumuwaku c:\programdata\witiwegu c:\users\All Users\witiwegu c:\programdata\vasosunu c:\users\All Users\vasosunu c:\programdata\veyopiho c:\users\All Users\veyopiho c:\programdata\sebajuyo c:\users\All Users\sebajuyo c:\programdata\wayapego c:\users\All Users\wayapego c:\programdata\petonuho c:\users\All Users\petonuho c:\programdata\hatikefe c:\users\All Users\hatikefe c:\programdata\lamujoto c:\users\All Users\lamujoto c:\programdata\zahuzewi c:\users\All Users\zahuzewi c:\programdata\hikepohe c:\users\All Users\hikepohe c:\programdata\zezowawi c:\users\All Users\zezowawi c:\programdata\sekisahi c:\users\All Users\sekisahi c:\programdata\hanayupu c:\users\All Users\hanayupu c:\programdata\mumehuve c:\users\All Users\mumehuve c:\programdata\vikikeme c:\users\All Users\vikikeme c:\programdata\vaguyasi c:\users\All Users\vaguyasi c:\programdata\hohokaza c:\users\All Users\hohokaza c:\programdata\hipolugi c:\users\All Users\hipolugi c:\programdata\vegiyemi c:\users\All Users\vegiyemi c:\programdata\lizujopu c:\users\All Users\lizujopu c:\programdata\zuvirumu c:\users\All Users\zuvirumu c:\programdata\wagitiru c:\users\All Users\wagitiru c:\programdata\bewodanu c:\users\All Users\bewodanu c:\programdata\nademiso c:\users\All Users\nademiso c:\programdata\sunimuju c:\users\All Users\sunimuju c:\programdata\bifaruwi c:\users\All Users\bifaruwi c:\programdata\benosafi c:\users\All Users\benosafi c:\programdata\hujuyuju c:\users\All Users\hujuyuju c:\programdata\wanizofu c:\users\All Users\wanizofu c:\programdata\danuzihi c:\users\All Users\danuzihi c:\programdata\nadohipi c:\users\All Users\nadohipi c:\programdata\ginoreru c:\users\All Users\ginoreru c:\programdata\fawofofo c:\programdata\vetaweyo c:\users\All Users\fawofofo c:\users\All Users\vetaweyo c:\programdata\lomehuda c:\users\All Users\lomehuda c:\programdata\sodekeba c:\users\All Users\sodekeba c:\programdata\bimeyonu c:\users\All Users\bimeyonu c:\programdata\yodutiti c:\users\All Users\yodutiti c:\programdata\zumupobi c:\users\All Users\zumupobi c:\programdata\bazamufa c:\users\All Users\bazamufa c:\programdata\hogikata c:\users\All Users\hogikata c:\programdata\johabuji c:\users\All Users\johabuji c:\programdata\moriwami c:\programdata\vuyugije c:\users\All Users\moriwami c:\users\All Users\vuyugije c:\programdata\diforusa c:\users\All Users\diforusa c:\programdata\kupuruzi c:\users\All Users\kupuruzi c:\programdata\wovahuzo c:\users\All Users\wovahuzo c:\programdata\zodogupe c:\users\All Users\zodogupe c:\programdata\ruyigige c:\users\All Users\ruyigige c:\programdata\pehuvesi c:\users\All Users\pehuvesi c:\programdata\minukure c:\users\All Users\minukure c:\programdata\hikemavi c:\users\All Users\hikemavi c:\programdata\zofudaga c:\users\All Users\zofudaga c:\programdata\fizugotu c:\users\All Users\fizugotu c:\programdata\rufowopa c:\users\All Users\rufowopa c:\programdata\zarasane c:\users\All Users\zarasane c:\programdata\resiyefu c:\users\All Users\resiyefu Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] RegNull:: [-HKEY_USERS\S-1-5-21-2383206740-1977817344-2628701725-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}\iexplore] [-HKEY_USERS\S-1-5-21-2383206740-1977817344-2628701725-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\iexplore] [-HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [-HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] [-HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] [-HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [-HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] [-HKEY_USERS\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After REBOOT (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Download the Norton Removal Tool (SymNRT) to your Desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart. 
 ---------- Download the McAfee Consumer Product Removal Tool to your Desktop. Using McAfee Consumer Product Removal tool: 
 | |
| 2779. | Solve : Good free firewall?? | 
| Answer» I am a firm believer in using all the great free programs out there and am currently using AVG, Spybot S&D, MalwareBytes and CCLEANER. I'm still, however, using the built in Windows Firewall and was wondering if anyone here could reccomend a better, free, alternative. I KNOW I could just Google this, but 9 times out of 10 you come across junk and I figured if anyone would know what to use, it would be you guys here.Try Sunbelt personal firewall. There's a free one and a paid version. I'm sure if you dowload the trial it will revert to the free version on it's own. I found this one much easier to use than Comodo and have never had any problems with it.  | |
| 2780. | Solve : PC won't load certain webpages. . .? | 
| Answer» Problem: A PC here at work has some issues w/ certain webpages: hotmail, google maps, yahoo maps, crucial.com's memory finder, etc... For instance, when I try to go to www.hotmail.com, it shows "Done" in the lower left corner, but the web page just stays COMPLETELY blank (white), even though the top "title bar" of IE says, "Sign In - Windows Internet Explorer provided by Yahoo!" | |
| 2781. | Solve : Still getting numerous threat detections even after a virus scan! Help!? | 
| Answer» While I know how to maintain my own computer and am usually pretty capable of knowing which programs to run to keep my computer in a proper condition, I am coming to you because my dad's computer seems to be beyond my reach of help. | |
| 2782. | Solve : Malwarebytes and AVG updates have been disabled by possible virus.? | 
| Answer» Did it. The quick scan found no malicious items. | |
| 2783. | Solve : Renaming HJT exe? | 
| Answer» Haven't had to use HJT at all yet, but will download it just in case, for possible future use. (your suggestions about downloading MBAM and SAS have proved invaluable, GOT me out of a few pickles) | |
| 2784. | Solve : MY logs they show trojan virus and others Please help? | 
| Answer» Below are my logs i have so far | |
| 2785. | Solve : Windows error recovery/ blue screen fatal system error c0000021a at startup...? | 
| Answer» I hope someone can help... I have an LG laptop computer, its a vista, I am UNABLE to access well anything, when I turn on the computer it seems it will work normally, then it goes to a screen that recommends to start " Launch start up repair ( reccomended) so I click on it...the screen goes black and stays that way for a while nearly 15 min, then a blue screen appears with: STOP: C000021a {Fatal system ERROR} The verification of a knownDLL FAILED. system process TERMINATED unexpectedly with a status of 0xc0000221 (0x8d5c768 0x00000000) The system has been SHUT down. thats as far as it goes, I can not get antfurther..I really need help, all my work is on that computer...please please help!!!! PUZZERWOPJust posting for latter if i can find it. sorry that I cant help right off but I dont have the code book with me. | |
| 2786. | Solve : One more time. Which AV is the very BEST for you.? | 
| Answer» One more time.  | |
| 2787. | Solve : PC slowdown? | 
| Answer» Just posted another issue and the reply I got was here. Did not know you had suggested SP3. I tried this once and had problems with it - there were some sites I could not get to work and they were related to my college work so that plus other issues I had caused me to uninstall it and stay away from it. | |
| 2788. | Solve : Re: Sysvxd.exe problem? | 
| Answer» I too am experiencing this problem and I found this forum via a Google search. I dl'ed and installed Hijackthis and ran it, the log to follow. The problem I've been intermittently experiencing is multi pronged, I have ad-aware from Lavasoft installed but I can't dl new definitions. I have Symantic AV and it's been catching new viruses lately. I can't do a windows update, it takes me to a Google page that says it can't find the requested page. Any help would be greatly appreciated, and I'll never dl from torrent sites again. | |
| 2789. | Solve : Adode Warning? | 
| Answer» I read the warning from Adobe on the link below. Do you have any advice other than disable JAVA in their program as they say? Is there a BETTER reader to USE please? | |
| 2790. | Solve : Panda introduces cloud-based free antivirus? | 
| Answer» Panda introduces cloud-based free antivirus and although it's beta right now, it's going to stay free once RTM version RELEASES.  | |
| 2791. | Solve : wireless hot spots? | 
| Answer» Its my understanding that when using public hot spots (unsecured access points) are not safe because someone can monitor the traffic between your laptop and the access point.  I would never perform transactions of any sort in a public hotspot. It's much too risky. You don't know who is watching. by this, it seems that you IMPLY that https is crackable......Is that the risk you are talking about? | |
| 2792. | Solve : Free License for SUPERAntiSpyware Professional Edition? | 
| Answer» I have one Free SUPERAntiSpyware Professional EDITION Lifetime Key to give away. | |
| 2793. | Solve : Trojan problem, Can't get rid of it? | 
| Answer» TROJAN shows up all the TIME (C:\WINDOWS\SYSTEM32\ATI#DUA.DLL) I restart my COMPUTER because it SYS it will be deleted after restart but it always shows back up.. I have followed your guidelines and have run CCleaner, SUPERAntiSpyware, MBAM, updated Java, and run Hijack This. I have a DELL Inspiron 8200 Windows Xp Service Pack 2 Pentium 4 CPU 1.60 GHz 256MB RAM [attachment deleted by admin] | |
| 2794. | Solve : What is the best PC Security Software? | 
| Answer» All free and very GOOD. | |
| 2795. | Solve : Constant Hourglass? | 
| Answer» Greetings! | |
| 2796. | Solve : Posting what i copied from HijackThis in the Notes section? | 
| Answer» Logfile of Trend Micro HijackThis v2.0.2 | |
| 2797. | Solve : 100% CPU usage all the time!!! Help? | 
| Answer» Hi, 
 Post the contents of the ActiveScan report in your next reply. | |
| 2798. | Solve : [CRASHES AFTER CPU DESKTOP SCREEN]? | 
| Answer» Hey, Do you hear the fan running.... has it been cleaned recently.....can you get into safe mode F8..... and see if it remains stable....if so then you can try run malware programs...memory may have to be reseated. Safe Mode I dont Know, My Uncels Friend Sayed He Tried It Wouldnt Work, Fan Hasnt Been Clean Ill Tell Him To Try That, I Cant Even Move My Mouse Hardly, And Im Not ON That CPU If YOur WONDERin, Thanks Though, TorrentIt© | |
| 2799. | Solve : All my program files have been turned into torrent format! PLEASE REPLY!!!!!? | 
| Answer» i can't run DDS as administrator, there is no option, I dragged it from my downloads to my desktop RIGHT clicked, and there were no optionsTry double clicking it.it says it doesn't support my operating systemi still need helpRight click DDS and rename it to DDS.com and then try running it.iono why but all my files seem to be WORKIN fine nwoAre you going to post the LOGS or not?i would if the program could run, i'm sorry, but it seems the problem has been fixed somehow. all my files seems to work and i'll have an update in a few daysit still says it can't run on my operating systemQuote from: slipknotthe9 on May 03, 2009, 03:51:47 PM i would if the program could run, i'm sorry, but it seems the problem has been fixed somehow. You do realize that's a contradiction right? Download random's system information tool (RSIT) by random/random from and save it to your Desktop. 
 | |
| 2800. | Solve : Logs Post-Something is wrong, but I don't know what to do anymore!? | 
| Answer» Go to Microsoft Windows Update and get all critical updates. | |