Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3201.

Solve : do i still need a firewall/antivirus??

Answer»

I used to always rock avast and zone alarm.

but lately i got a modified host file (that blocks all ads)

and removed zone alarm and avast (because they would conflict with a lot of my online gaming) and keep my windows up to date, and been rocking it like this for last 3 months. (mostly from laziness, but I do run ccleaner a lot)

but for the heck of it today i ran a scan with malware BYTES. and i had like 1 infection which was a ad thing from yahoo.

i am a heavy user, facebook, forums, chats, gaming...

and my computer seems to still run as smooth as my gf's inner thigh

so am i alright?
I would never even consider running a SYSTEM without a top notch AV installed and always resident.Quote from: Allan on May 06, 2012, 11:13:01 AM

I would never even consider running a system without a top notch AV installed and always resident.

Yeah I am installing some now.

What do you mean by "always resident"?also wth??

i am running super ANTISPYWARE, and it says i got tracking cookies from my gmail and stuff?

and youtube??

I TRUSTED YOU!!! SNAPE I TRUSTED YOU!!!!!Resident = loading at boot and always running / active in the backgroundi want to do these few things, what order should i do them?

first gonna update all my software, then turn off internet and restart PC

then
virus scan
1. malwayre bytes scan
2. superantispyware scan
3. run ccleaner
4. ccleaner registry fix

is that a good order to do these?1) DO NOT EVER use any registry cleaners / utilities - including the ccleaner registry cleaner MODULE. The best of them do absolutely nothing. The worst of them will leave your system unusable.

2) Ccleaner does nothing you can't do yourself. It certainly is not in any way, shape, or form an anti-malware utility.

As for the rest, there is no "good order" or "bad order". Run the scans however you like.Quote from: Allan on May 07, 2012, 09:44:54 AM
1) DO NOT EVER use any registry cleaners / utilities - including the ccleaner registry cleaner module. The best of them do absolutely nothing. The worst of them will leave your system unusable.

2) Ccleaner does nothing you can't do yourself. It certainly is not in any way, shape, or form and anti-malware utility.

As for the rest, there is no "good order" or "bad order". Run the scans however you like.

cool thanks - i like to update all my programs, then restart in safemode- run scans - then reboot

hey also why did trusted sites like google send me malicious tracking cookies?

Makes me not trust google as much, thinking of transferring my accounts to something less mainstream.They're not malicious - their just tracking cookies - for marketing purposes. Pretty much everyone does it these DAYS. Disable third party cookies in your browser options.
3202.

Solve : Computer Fails To Start Up AFTER Threats Removed. HELP!?

Answer»

It's getting better. Starts up faster. STILL does not copy/PASTE without me hitting Ctrl+C a dozen times.ESETscan just finished.

[year+ old attachment deleted by admin]Quote

Still does not copy/paste without me hitting Ctrl+C a dozen times.
Is that the only method you use to copy and paste? Does right-clicking work? If that's the only method that doesn't work, you could try another key board.Right click SELDOM works. The keystrokes Ctrl+u,i,p etc. work with no issues. It's only copy/paste. Quote
Right click seldom works. The keystrokes Ctrl+u,i,p etc. work with no issues. It's only copy/paste.
I don't believe that this is a malware problem. We should do some cleanup.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you

********************************************
To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
***********************************************
Clean out your temporary INTERNET files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run UNINTERRUPTED until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
3203.

Solve : Is this threat a false positive by avg 2012 free??

Answer» PLZ stay with me just a bit longer, wild tangent does not exist in WIN 7 'programs and features' (formerly known as 'add/remove programs'0. I would like to read your referenced articles first if they give instructions on how to remove wt in windows 7.

ThanksOK. I read the Wild Tangent article. I always side on the ere of caution. The WT games ie poker star (I figured out how to uninstall all 20) where apart of Hewlett Packards initial install. NEVER the less they are gone. I did find an unsolicited wt file and got rid of it as well.

I still need to finish complying with your final instructions.... so as for now, I appreciate all your help; I believe my pc is well.

Before you close this post I have one last curiosity. When you detect the problems, we are not informed of the amount or type of damage that may have incurred. In other words, spyware is spyware and malware and trojans are the like. Even though the problems where removed; to what extent; if any, was the damage? My PC ran crappy, you figured out why it ran crappy. Can you discern wether the removed problems were intended to just destroy just the pc, attack me personally to gain my identity and worse to hurt others.

If the answer doesn't take away you from your priorities, please opine.

Again, thanks for all that you do.
When I tried to use combofix.uninstall, it first looked like it worked. Then a pop up refered that I was trying to uninstall combofix from a windows xp version or something like that and maybe it didn't work. Confusing. If removing combofix is important, is there an uninstaller for Win7?Quote
When you detect the problems, we are not informed of the amount or type of damage that may have incurred. In other words, spyware is spyware and malware and trojans are the like. Even though the problems where removed; to what extent; if any, was the damage? My PC ran crappy, you figured out why it ran crappy. Can you discern wether the removed problems were intended to just destroy just the pc, attack me personally to gain my identity and worse to hurt others.
It's really difficult to say how much damage without sitting in front of the COMPUTER. Some malware does no damage at all; it just collects information about you and your surfing habits. Others such as scareware or ransomeware will freeze up your computer until you pay a fee to unlock it. This can be fixed btw without PAYING. Others try to get your banking information and such.
Quote
If removing combofix is important, is there an uninstaller for Win7?
Download this program and run it Uninstall ComboFix .It will remove ComboFix for you
3204.

Solve : Removing BearShare applications?

Answer»

Hello

I am unable to delete the BearShare applications FOLDER from my C | Program files directory (ATTACHED screenshot). I have run MalWareBytes which didn't PICK up anything, and then SuperSpyWare which removed 30+ 'threats', but the BearShare folder is still there.

Thanks for any suggestions.

High1

[year+ old attachment deleted by admin]Try REVO Uninstaller SELECT the 30 day trial one.Many thanks for that SuperDave

3205.

Solve : How can I get rid of sality.nba virus ??

Answer»

what should I do now ?Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:


Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily HELP you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.ComboFix 12-03-27.03 - Saeid 03/27/2012 23:59:08.2.4 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1256.981.1033.18.3063.1710 [GMT 4.5:30]
Running from: c:\users\Saeid\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
SP: Kaspersky Anti-Virus *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-02-27 to 2012-03-27 )))))))))))))))))))))))))))))))
.
.
2012-03-27 19:37 . 2012-03-27 19:37--------d-----w-c:\users\Default\AppData\Local\temp
2012-03-27 08:01 . 2012-03-27 08:01--------d-----w-C:\_OTL
2012-03-27 07:36 . 2012-03-14 02:156582328----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{54D7E092-BDA8-4721-A5D1-B16B8F591AC9}\mpengine.dll
2012-03-26 08:05 . 2012-03-26 08:05--------d-----w-c:\users\Saeid\AppData\Roaming\SUPERAntiSpyware.com
2012-03-26 08:04 . 2012-03-26 08:05--------d-----w-c:\program files\SUPERAntiSpyware
2012-03-26 08:04 . 2012-03-26 08:04--------d-----w-c:\programdata\SUPERAntiSpyware.com
2012-03-26 07:35 . 2012-03-26 07:35--------d-----w-c:\program files\CCleaner
2012-03-26 07:35 . 2012-03-26 07:35--------d-----w-c:\program files\Google
2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\users\Saeid\AppData\Roaming\Malwarebytes
2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\programdata\Malwarebytes
2012-03-25 07:20 . 2011-12-10 10:5420464----a-w-c:\windows\system32\drivers\mbam.sys
2012-03-24 05:45 . 2012-03-24 05:4510920----a-w-C:\aolconnfix.exe
2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\program files\AOL Toolbar
2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\programdata\AOL Toolbar
2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\program files\Common Files\Software Update Utility
2012-03-23 17:57 . 2012-03-23 22:01--------d-----w-c:\program files\AOL 9.5
2012-03-23 17:57 . 2012-03-23 17:59--------d-----w-c:\program files\Common Files\aol
2012-03-19 19:06 . 2012-03-19 19:09--------d-----w-c:\users\Saeid\AppData\Local\Facebook
2012-03-18 21:59 . 2012-03-18 21:592106216----a-w-c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2012-03-18 21:59 . 2012-03-18 21:591998168----a-w-c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-03-18 21:59 . 2012-03-18 21:59592824----a-w-c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-18 21:59 . 2012-03-18 21:59548864----a-w-c:\program files\Mozilla Firefox\msvcp80.dll
2012-03-18 21:59 . 2012-03-18 21:59479232----a-w-c:\program files\Mozilla Firefox\msvcm80.dll
2012-03-18 21:59 . 2012-03-18 21:5944472----a-w-c:\program files\Mozilla Firefox\mozglue.dll
2012-03-18 21:59 . 2012-03-18 21:59626688----a-w-c:\program files\Mozilla Firefox\msvcr80.dll
2012-03-15 09:45 . 2012-02-03 03:542343424----a-w-c:\windows\system32\win32k.sys
2012-03-15 09:45 . 2012-02-10 05:381077248----a-w-c:\windows\system32\DWrite.dll
2012-03-15 09:37 . 2012-01-25 05:3258880----a-w-c:\windows\system32\rdpwsx.dll
2012-03-15 09:37 . 2012-01-25 05:32129536----a-w-c:\windows\system32\rdpcorekmts.dll
2012-03-15 09:37 . 2012-01-25 05:278192----a-w-c:\windows\system32\rdrmemptylst.exe
2012-03-15 09:37 . 2012-02-17 05:34919040----a-w-c:\windows\system32\rdpcorets.dll
2012-03-15 09:37 . 2012-02-17 05:34826880----a-w-c:\windows\system32\rdpcore.dll
2012-03-15 09:37 . 2012-02-17 04:14183808----a-w-c:\windows\system32\drivers\rdpwd.sys
2012-03-15 09:37 . 2012-02-17 04:1324576----a-w-c:\windows\system32\drivers\tdtcp.sys
2012-03-04 16:16 . 2012-03-04 16:16--------d-----w-c:\users\Saeid\AppData\Local\Behnevis Common
2012-03-04 16:16 . 2012-03-22 17:32--------d-----w-c:\program files\Behnevis for MS Word
2012-03-04 16:15 . 2012-03-04 16:15--------d-----w-c:\program files\Conduit
2012-03-04 16:15 . 2012-03-04 16:15--------d-----w-c:\users\Saeid\AppData\Local\Conduit
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-29 14:50 . 2011-11-15 18:04414368----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-23 04:48 . 2011-11-15 16:44237072------w-c:\windows\system32\MpSigStub.exe
2012-01-17 13:33 . 2011-12-06 12:55189248----a-w-c:\windows\system32\PnkBstrB.exe
2012-01-17 13:33 . 2011-12-06 12:5475136----a-w-c:\windows\system32\PnkBstrA.exe
2012-03-18 21:59 . 2011-11-15 18:0497208----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 14:5021864----a-w-c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nimbuzz"="c:\program files\Nimbuzz\Nimbuzz.exe" [2011-12-01 11713024]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-11-14 3437976]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-23 1594664]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-01 98304]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-02-16 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2008-10-13 50472]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-06-08 284696]
"HostManager"="c:\program files\Common Files\AOL\1332525462\ee\AOLSoftware.exe" [2009-07-20 41264]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-02 5249024]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-02-28 75048]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2011-08-22 3265136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
.
c:\users\Saeid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-12-29 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
2011-04-24 19:45202296----a-w-c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET FRAMEWORK NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 197224]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-01-12 257568]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys

R3 SysProtDrv.sys;SysProtDrv.sys;c:\users\Saeid\Desktop\SysProt\SysProtDrv.sys [2012-03-26 44288]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-22 1343400]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-29 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-29 366936]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-12-18 721904]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-10 23856]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/11/15 19:17];c:\program files\CyberLink\PowerDVD9\000.fcl [2009-02-28 16:10 87536]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-06-01 176128]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-06-08 13336]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-07-06 89376]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 14808]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-06-01 5586432]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-06-01 209920]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl32.sys [2010-02-02 17144]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-03-30 45352]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-30 29472]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-27 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 01a8d408-7896-4588-a444-c4f59eb8fffb.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-03-26 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task f88d71fa-faee-4ea3-9250-22371e658c90.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com
mStart Page = about:blank
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:11536
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{EB069C30-DB0F-4DAE-83D4-466F9A5FEFE4}: NameServer = 8.4.4.8,3.2.2.3
FF - ProfilePath - c:\users\Saeid\AppData\Roaming\Mozilla\Firefox\Profiles\qaurd1x0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=55555
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 11536
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 11536
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 11536
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 11536
FF - prefs.js: network.proxy.type - 0
FF - user.js: protocol-handler.warn-external.dnUpdate - false
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:21,88,68,61,66,d5,35,e4,b7,c5,6a,2f,15,55,a4,7a,45,55,3b,d5,75,31,69,
cc,2d,4a,31,52,d8,3e,6e,cf,5b,5f,0c,2e,c9,48,50,70,5a,49,98,2a,26,be,a6,e6,\
"??"=hex:fe,94,16,33,a2,f0,68,4b,6b,9d,81,d8,7c,85,bb,9d
.
[HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000_Classes\CLSID\{01680c4a-b31f-45d3-8be1-b859b4623e35}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000028
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1b,d8,92,eb,22,77,b1,b4,34,91,07,25,ff,2e,77,3c,bb,80,33,ab,b8,
d7,2f,07,46,07,e5,b1,19,39,ef,99,67,03,07,de,17,77,9b,1a,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3148)
c:\program files\Babylon\Babylon-Pro\Captlib.dll
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Completion time: 2012-03-28 00:10:17
ComboFix-quarantined-files.txt 2012-03-27 19:40
ComboFix2.txt 2012-03-27 19:14
.
Pre-Run: 49,012,285,440 bytes free
Post-Run: 48,951,115,776 bytes free
.
- - End Of File - - 68D5ADAE3F7FD65BAE8430E4B9A21E2C
pardon me, in drive (C), I click on Documents and Settings folder and show an error that say is not accessible and there is a lock on it
and also in drive (D) system volume information folder, it has a same problem otherwise in drive (C) I had this problem and it seems that has been fixed now

Is it normal ?Download HostsXpert

•Unzip HostXpert to your Desktop

•Open up the HostXpert program.

•Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.

•Click Create Back Up

•Then click on Restore Microsoft's Host Files

•Close the HostXpert program
*******************************************
Quote
pardon me, in drive (C), I click on Documents and Settings folder and show an error that say is not accessible and there is a lock on it
and also in drive (D) system volume information folder, it has a same problem otherwise in drive (C) I had this problem and it seems that has been fixed now
Is it normal ?
It was probably caused by an infection.

SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
here has remained one question, there is an error here in SysProt, it says that : error scaning SSDT hooks, then I click on ok and it runs of course and follow the structures .

Is this error normal ?SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\sprf.sys
Service Name: ---
Module Base: 84AB6000
Module End: 84BB7000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\a26x65ir.SYS
Service Name: ---
Module Base: 96F9B000
Module End: 96FD3000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys
Service Name: ---
Module Base: 91216000
Module End: 913CB000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_dumpfve.sys
Service Name: ---
Module Base: 9654B000
Module End: 9655C000
Hidden: Yes

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Object: C:\System Volume Information\WindowsImageBackup\Catalog\BackupGlobalCatalog
Status: Access denied

Object: C:\System Volume Information\WindowsImageBackup\Catalog\GlobalCatalog
Status: Access denied

Object: C:\System Volume Information\WindowsImageBackup\Catalog
Status: Access denied

Object: C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{07cef2ff-c079-4635-a68e-99dc61f91b6f}
Status: Access denied

Object: C:\System Volume Information\WindowsImageBackup\SPPMetadataCache
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\namespace
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\pq
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\sm
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\temp
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
Status: Access denied
Please download SystemLook from one of the links below and save it to your desktop.

Link # 1
Link # 2

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click SystemLook.exe to run it.

Copy the contents of the following codebox into the main textfield.
Code: [Select]:filefind
a26x65ir.SYS

Click the Look button to start the scan.

Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
*******************************************
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these STEPS)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
SystemLook 30.07.11 by jpshortstuff
Log created at 11:07 on 29/03/2012 by Saeid
Administrator - Elevation successful

========== filefind ==========

Searching for "a26x65ir.SYS"
No files found.

-= EOF =-[emailprotected] as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=36882
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=a71137f0d49da94288a404b30554ff76
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-29 11:21:52
# local_time=2012-03-29 03:51:52 (+0330, Iran Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1280 16777215 100 0 11646693 11646693 0 0
# compatibility_mode=5893 16776573 100 94 180509 84641902 0 0
# compatibility_mode=8192 67108863 100 0 10863 10863 0 0
# scanned=148384
# found=4
# cleaned=4
# scan_time=7601
C:\Program Files\Babylon\Babylon-Pro\Utils\MyBabylonTB.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C
C:\Program Files\Babylon\BabylonToolbar\1.4.19.5\BabylonToolbarApp.dlla variant of Win32/Toolbar.Babylon application (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Program Files\Babylon\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exeprobably a variant of Win32/Toolbar.Babylon application (cleaned by deleting - quarantined)00000000000000000000000000000000C
D:\Software\Nero 9.4.13.2b.rarprobably a variant of Win32/Agent.KQNXJLO trojan (deleted - quarantined)00000000000000000000000000000000C
[emailprotected] as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=a71137f0d49da94288a404b30554ff76
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-29 03:21:11
# local_time=2012-03-29 07:51:11 (+0330, Iran Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1280 16777215 100 0 11655368 11655368 0 0
# compatibility_mode=5893 16776573 100 94 189184 84650577 0 0
# compatibility_mode=8192 67108863 100 0 19538 19538 0 0
# scanned=216225
# found=8
# cleaned=8
# scan_time=13285
H:\english file aminuuuu\base\video learning, babylon-maccaro, picture dictionary\AutoPlay\Docs\5\babylon-Maccro\01-Babylon Pro v8.0.10 (r16)\Babylon8_setup.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C
H:\Programs\cnet_fences_public_exe.exea variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)00000000000000000000000000000000C
H:\Programs\SweetImSetup.exea variant of Win32/SweetIM.B application (cleaned by deleting - quarantined)00000000000000000000000000000000C
H:\Programs\Babylon Pro\Babylon9 Setup www.FDL.ir.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C
H:\SAEID-PC\Backup Set 2011-11-27 222550\Backup Files 2011-11-27 222550\Backup files 1.zipa variant of Win32/Adware.MediaFinder.A application (deleted - quarantined)00000000000000000000000000000000C
H:\SAEID-PC\Backup Set 2011-11-27 222550\Backup Files 2011-11-27 222550\Backup files 8.zipa variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C
H:\software\BabylonPro-902(www.vatandownload.com).rara variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C
H:\software\Office 2010 Activator (www.Downloadha.com).rarWin32/HackKMS.A application (deleted - quarantined)00000000000000000000000000000000C
here are the logs, what should I do now? thanks alotIf there are no other issues, we can do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
****************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla BASED browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe SURFING!SuperDave, I think I have a problem, as I said in a reply, system volume information folder is not accessible in my all drives,
except drive E, I still have this problem !

I don't know what's this, I have no idea these folders aren't exist before !

wow, it seems that this problem solved too, Grazie !
I truly appreciate your time and effortYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3206.

Solve : Gateway Blue Screen?

Answer»

When I start up computer I get message that something is wrong with my computer and two options: repair or start normallly. Repair LEADS to a blue SCREEN that says to run chkdsk /f which when I run says device is not ready. All the other chkdsk demands say the same thing. Safe mode does not work and I dont care about saving my information. Alls I want to do is be able to reinstall windows vista but when i boot from the cd it does not see my dvd. I have windows vista 32What is the make and MODEL of your computer?
"Device not ready" and "the cd does not see my DVD" indicate a hardware problem, most LIKELY caused by misconfiguration. If its a desktop, try resetting CMOS. If its a laptop, take out the battery, unplug it from the charger and press the power button a few TIMES. Then try again.1) Replace the cmos battery then reset the bios to default.
2) In the bios, find the device boot order and move the dvd drive to the top followed immediately by the hard drive.

If the system still doesn't boot properly you should at least be able to boot to the Vista cd now.

3207.

Solve : How to do the DOS attack??

Answer»

Please anyone who can HELP me?
I WANT to learn more about DOS attack!!!Here!

3208.

Solve : Antivirus Test Labs?

Answer»

I am searching for buy a proper Antivirus software for myself. i searched about the comparisons on the Internet. I found out that there are some test labs that their results can be useful such as av-test.org and others.
my question is that which labs are best. which has more expert and famous. which can be used as reference and source for comparison of Antivirus software?
http://www.google.com/#hl=en&sclient=psy-ab&q=antivirus+test+labs&oq=antivirus+test+labs&aq=f&aqi=g1&aql=1&gs_l=hp.3..0.18622l18622l6l20096l1l0l0l1l1l0l0l0ll1l0.efis.1.&pbx=1&bav=
on.2,or.r_gc.r_pw.r_qf.,cf.osb&fp=91fbb53e0f2ce1b4&biw=1366&bih=619

Most of these free AV's are just as good as what you can buy. I prefer MSE.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition
7) ThreatFire

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and FALSE virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.thank you very much for introducing free antiviruses.
As you know some SITES such www.av-test.org examine them and give SCORE for their abilities.
i WANT to know how much these sites are useful. can i refer to their statistics for knowing better antivirus?
which antivirus test labs are best?
http://www.av-comparatives.org/ is the best.You can download Avira too!!!(the red umbrella)

3209.

Solve : SVCHOST.exe or Newfolder.exe?

Answer»

thyxxxxxxx GUYS!!!!!!

3210.

Solve : What are these eroors in Event Viewer?

Answer» HI, Can someone tell me what these Errors are in EVENT viewer Volmgr, VSS, Windows media player sharing? I picked them up because My computer keeps crashing to DESKTOP out of the games I run? How do I get rid of them. Thanks!!
3211.

Solve : how can I get rid of sality.nba???

Answer»

Quote

I did every thing you said in earlier posts. but the problem seems exist. there is a lock SHAPE in some folders such "DOCUMENT and settings" and "system recovery. i can't enter these folders with the massage: "ACCESS IS DENIED"

1) Right-click the folder or drive that has a lock icon and select "Properties".

2) Click on the "Security" tab, then select "Edit..." to change permissions. Click "Add.."

3) In the text field for "Object NAME", enter in "Users" (without quotations). Hit "OK".

4) "Apply", "OK", and voila, the padlock next to the icons should be gone.
3212.

Solve : Problem with "welcome to nginx" and website logins?

Answer»

Quote

I changed it back to att.my.yahoo.com to see if the nginx still comes up and it does.
This and this is what I know about nginx

We should do some cleanup

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
********************************************************
To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, PRESS Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
***********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have SAVED all your WORK before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few SECONDS to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a FREE Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up. Malwarebytes captured this in it's log tonight and I had it quarantined:


2012/04/04 06:46:06 -0500PEARSON-HOME-PCAdministratorMESSAGEExecuting scheduled update: Daily
2012/04/04 06:46:54 -0500PEARSON-HOME-PCAdministratorMESSAGEScheduled update executed successfully: database updated from version v2012.03.31.14 to version v2012.04.04.02
2012/04/04 06:46:54 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting database refresh
2012/04/04 06:47:00 -0500PEARSON-HOME-PCAdministratorMESSAGEDatabase refreshed successfully
2012/04/04 19:54:33 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection
2012/04/04 19:54:57 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully
2012/04/04 19:55:00 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection
2012/04/04 19:55:05 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully
2012/04/04 20:11:52 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection
2012/04/04 20:12:19 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully
2012/04/04 20:12:22 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection
2012/04/04 20:12:26 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully
2012/04/04 20:14:58 -0500PEARSON-HOME-PCAdministratorDETECTIONC:\Documents and Settings\Administrator\My Documents\Downloads\B.tmpTrojan.Dropper.PGenQUARANTINE
2012/04/04 20:25:21 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection
2012/04/04 20:25:39 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully
2012/04/04 20:25:42 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection
2012/04/04 20:25:46 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully
2012/04/04 20:33:11 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection
2012/04/04 20:33:37 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully
2012/04/04 20:33:40 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection
2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully
2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEStopping IP protection
2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection stopped
2012/04/04 21:19:29 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection
2012/04/04 21:19:52 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully
2012/04/04 21:19:55 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection
2012/04/04 21:20:20 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully

When I go that downloads folder I do not see this b.temp file, I went into Malwarebytes and deleted it there.

At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas. I thank you for your time over these past few weeks!
Quote
When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up.
TFC will do that sometimes. Just do a disk cleanup instead. Double-click on My Computer, right-click on the C drive and select Disk cleanup.
Quote
At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas.
I don't know too much about Chrome but FireFox is reputed to be a safer browser.Ok I'll do the disk cleanup. Thanks again for all your help!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3213.

Solve : "..." not a valid Win32 application, The application or DLL not valid windows im?

Answer»

Hi SD,
Not trying to be difficult, but those instructions were for Windows 7, and I have Windows XP Media Center Edition 2005. I did try looking for how to boot to systems recovery options on my own though, and it seemed they were saying to just go to Safe Mode to get Safe Mode with command prompt. I did that, went through the process of selecting my user name (HP_Administrator), got C:\Documents and Settings\HP_Administrator> Tried entering bootrec /fixmbr (I remembered to include the space). Got the message that bootrec was not recognized as an internal or external command, operable program, or batch file. So I typed exit, and then just got the black screen with safe mode in the 4 corners. Didn't know how to get out of that, so I just turned off the computer with the power button.

I do have a disk my daughter made when we got this computer, it is labeled "HP Recovery Tools CD". I looked at the contents with WinExplorer: it has a lot of language file folders, some file folders that begin with R and a number, some files that are labeled bootfont with a different extensions (they seem to correspond to the languages), and some files labeled WIN51, [emailprotected], WIN511C, etc.

I also have a set of 3 recovery disks she made when we got the computer, I'm assuming they are for a destructive recovery? I have not looked at them.

Also, under My Computer, C is my hard drive, but there is also a D drive labeled HP_Recovery. I don't know if any of this info helps you decide what to do next. As I said, I'm not trying to be difficult, but want to make sure I'm doing the right THING. Thanks.

After writing all this, I found this site on line that appears to say to ignore the error message for Windows 2000 (but it doesn't say for XP): should I just ignore the error message ?

http://support.microsoft.com/kb/266745

I also found this site that says it also applies to XP:

http://www.tomshardware.com/forum/87475-45-fixmbr-dont

I'm not trying to undermine or second-guess you, just trying to help with research (I don't expect you to know everything. :>). I won't do anything that you haven't checked and said I should do. If you say go ahead then I'll do it. Thanks!Quote

Also, under My Computer, C is my hard drive, but there is also a D drive labeled HP_Recovery
Yes, that's the recovery console we're trying to get into.
Quote
After writing all this, I found this site on line that appears to say to ignore the error message for Windows 2000 (but it doesn't say for XP): should I just ignore the error message ?
I would say just ignore the warning as MS stated in their article. But first, you should save all your important data just in case we have to use the Recovery disks. Wow--that was QUICK! No problems. Here's the log from MBRcheck:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version:Windows XP Professional
Windows Information:Service Pack 3 (build 2600)
Logical Drives Mask:0x00000f1c

Kernel Drivers (total 143):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xF7A3C000 \WINDOWS\system32\KDCOM.DLL
0xF794C000 \WINDOWS\system32\BOOTVID.dll
0xF740D000 ACPI.sys
0xF7A3E000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF73FC000 pci.sys
0xF753C000 isapnp.sys
0xF754C000 ohci1394.sys
0xF755C000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF7950000 compbatt.sys
0xF7954000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xF7B04000 pciide.sys
0xF77BC000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7A40000 viaide.sys
0xF7A42000 intelide.sys
0xF756C000 MountMgr.sys
0xF73DD000 ftdisk.sys
0xF7A44000 dmload.sys
0xF73B7000 dmio.sys
0xF77C4000 PartMgr.sys
0xF757C000 VolSnap.sys
0xF739F000 atapi.sys
0xF758C000 disk.sys
0xF759C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF737F000 fltmgr.sys
0xF736D000 sr.sys
0xF75AC000 PxHelp20.sys
0xF7356000 KSecDD.sys
0xF72C9000 Ntfs.sys
0xF729C000 NDIS.sys
0xF7282000 Mup.sys
0xF6D60000 kl1.sys
0xF76FC000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF631D000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xF6309000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF7914000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF62E5000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF791C000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF770C000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF771C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF772C000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF62C2000 \SystemRoot\system32\DRIVERS\ks.sys
0xF7924000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF629A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF792C000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF6286000 \SystemRoot\system32\DRIVERS\parport.sys
0xF773C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7934000 \SystemRoot\system32\DRIVERS\PS2.sys
0xF793C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7A78000 \SystemRoot\system32\DRIVERS\arkbcfltr.sys
0xF7944000 \SystemRoot\system32\DRIVERS\point32.sys
0xF77D4000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7A7A000 \SystemRoot\system32\DRIVERS\armoucfltr.sys
0xF7814000 \SystemRoot\system32\DRIVERS\aracpi.sys
0xF6241000 \SystemRoot\system32\DRIVERS\HSXHWBS2.sys
0xF614A000 \SystemRoot\system32\DRIVERS\HSX_DP.sys
0xF6094000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0xF781C000 \SystemRoot\System32\Drivers\Modem.SYS
0xF6080000 \SystemRoot\system32\DRIVERS\Rtnicxp.sys
0xF774C000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF7A28000 \SystemRoot\system32\DRIVERS\arpolicy.sys
0xF7C8D000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF775C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7A2C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF6069000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF776C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF777C000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7824000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF6058000 \SystemRoot\system32\DRIVERS\psched.sys
0xF778C000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF782C000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7834000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF6000000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF779C000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7A7C000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF5FA2000 \SystemRoot\system32\DRIVERS\update.sys
0xF6D30000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF77AC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF763C000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7A7E000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF1A0B000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xF19E7000 \SystemRoot\system32\drivers\portcls.sys
0xF766C000 \SystemRoot\system32\drivers\drmk.sys
0xF1970000 \SystemRoot\system32\DRIVERS\klif.sys
0xF7A8A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7C12000 \SystemRoot\System32\Drivers\Null.SYS
0xF7A8C000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7C14000 \SystemRoot\System32\Drivers\ATMhelpr.SYS
0xF784C000 \SystemRoot\System32\drivers\vga.sys
0xF7A8E000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7A90000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7854000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF785C000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF6040000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF7864000 \SystemRoot\system32\DRIVERS\kl2.sys
0xF6030000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xF1915000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF18BC000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF1894000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF1815000 \SystemRoot\System32\vsdatant.sys
0xF17EF000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF6513000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF5F9E000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF6503000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF786C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF7874000 \SystemRoot\system32\DRIVERS\arhidfltr.sys
0xF64F3000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xF787C000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF5F92000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xF17CD000 \SystemRoot\System32\drivers\afd.sys
0xF64E3000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF17AB000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0xF7884000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xF1730000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF1698000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF64D3000 \SystemRoot\System32\Drivers\Fips.SYS
0xF788C000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF1674000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xF165C000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7AC0000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF19CB000 \SystemRoot\System32\drivers\Dxapi.sys
0xF78B4000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C3A000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF055000 \SystemRoot\System32\ati2cqag.dll
0xBF09A000 \SystemRoot\System32\atikvmag.dll
0xBF0D0000 \SystemRoot\System32\ati3duag.dll
0xBF362000 \SystemRoot\System32\ativvaxx.dll
0xBF4BA000 \SystemRoot\System32\ATMFD.DLL
0xEF490000 \??\C:\WINDOWS\system32\drivers\mbam.sys
0xEF428000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xF789C000 \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
0xEEE67000 \SystemRoot\system32\drivers\wdmaud.sys
0xEF3B4000 \SystemRoot\system32\drivers\sysaudio.sys
0xEECFC000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xEEB53000 \SystemRoot\System32\Drivers\HTTP.sys
0xEEAD3000 \SystemRoot\system32\DRIVERS\srv.sys
0xEEB4F000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xEE713000 \SystemRoot\System32\Drivers\Cdfs.SYS
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 56):
0 System Idle Process
4 System
548 C:\WINDOWS\system32\smss.exe
620 csrss.exe
648 C:\WINDOWS\system32\winlogon.exe
692 C:\WINDOWS\system32\services.exe
704 C:\WINDOWS\system32\lsass.exe
860 C:\WINDOWS\system32\ati2evxx.exe
876 C:\WINDOWS\system32\svchost.exe
948 svchost.exe
1016 C:\WINDOWS\system32\svchost.exe
1104 svchost.exe
1160 svchost.exe
1204 C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
1472 C:\WINDOWS\system32\ati2evxx.exe
1564 C:\WINDOWS\explorer.exe
1868 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
2004 C:\WINDOWS\system32\spoolsv.exe
164 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
1044 svchost.exe
1100 C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
1176 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1304 C:\WINDOWS\arservice.exe
1340 C:\Program Files\Microsoft\BingBar\SeaPort.EXE
1416 C:\Program Files\Bonjour\mDNSResponder.exe
1348 C:\WINDOWS\ehome\ehrecvr.exe
1732 C:\WINDOWS\ehome\ehSched.exe
1884 C:\Program Files\Java\jre6\bin\jqs.exe
2056 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2164 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
2296 svchost.exe
2352 C:\WINDOWS\system32\svchost.exe
2440 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
2504 mcrdsvc.exe
2584 C:\WINDOWS\system32\wuauclt.exe
3000 C:\WINDOWS\system32\dllhost.exe
3264 alg.exe
3280 wmiprvse.exe
3352 C:\WINDOWS\ehome\ehtray.exe
3368 C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
3428 C:\WINDOWS\arpwrmsg.exe
3596 C:\WINDOWS\ehome\ehmsas.exe
3776 C:\Program Files\iTunes\iTunesHelper.exe
4008 C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
4072 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
208 C:\Program Files\Common Files\Java\Java Update\jusched.exe
584 C:\Program Files\real\realplayer\Update\realsched.exe
1488 C:\PROGRA~1\ScanSoft\PAPERP~1\PPWEBCAP.EXE
2816 C:\Program Files\iPod\bin\iPodService.exe
2932 C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
2952 C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
3248 C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe
3748 C:\hp\KBD\kbd.exe
3880 C:\WINDOWS\system\hpsysdrv.exe
1528 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
2236 C:\Documents and Settings\HP_Administrator\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000038`11f9bc00 (FAT32)

PhysicalDrive0 Model Number: WDCWD2500JS-60NCB1, Rev: 10.02E02

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644 A


Done!Ok, the MBR has been fixed. That's a major step.

SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
I probably should have thought to ask this earlier: has my information been vulnerable during this INFECTION/invasion? In otherwords, paying bills on-line (at secure sites) or entering private info on the same sites, is there any chance that info has been compromised?

Here's the scan (thank you for all this help, BTW):

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: F15A0000
Module End: F15B8000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7AC2000
Module End: F7AC4000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwAdjustPrivilegesToken
Address: F18D466E
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwClose
Address: F18D4F02
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwConnectPort
Address: F177A2F4
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateEvent
Address: F18D57D0
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreateFile
Address: F17745CA
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateKey
Address: F179358A
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateMutant
Address: F18D56A8
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreateNamedPipeFile
Address: F18D4274
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreatePort
Address: F177AA80
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateProcess
Address: F178DE4E
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateProcessEx
Address: F178E23C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateSection
Address: F17976F6
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateSemaphore
Address: F18D5902
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreateSymbolicLinkObject
Address: F18D758C
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreateThread
Address: F18D4BA0
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwCreateWaitablePort
Address: F177ABB6
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDebugActiveProcess
Address: F18D6F36
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwDeleteFile
Address: F17751E0
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeleteKey
Address: F1794E3C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeleteValueKey
Address: F17947B2
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeviceIoControlFile
Address: F18D5178
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwDuplicateObject
Address: F178CD8A
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwEnumerateKey
Address: F18D3FAC
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwEnumerateValueKey
Address: F18D4056
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwFsControlFile
Address: F18D4F84
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwLoadDriver
Address: F176FE88
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwLoadKey
Address: F1795794
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwLoadKey2
Address: F179599C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwMapViewOfSection
Address: F1797A5E
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwNotifyChangeKey
Address: F18D41A2
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenEvent
Address: F18D5872
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenFile
Address: F1774DF2
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwOpenKey
Address: F18D36BE
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenMutant
Address: F18D5740
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenProcess
Address: F1790160
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwOpenSection
Address: F18D75B6
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenSemaphore
Address: F18D59A4
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwOpenThread
Address: F178FD8A
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwProtectVirtualMemory
Address: F17A4090
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwQueryKey
Address: F18D4100
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwQueryMultipleValueKey
Address: F18D3D28
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwQuerySection
Address: F18D7958
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwQueryValueKey
Address: F18D3978
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwQueueApcThread
Address: F18D72A6
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwRenameKey
Address: F179672A
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwReplaceKey
Address: F1796060
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwReplyPort
Address: F18D5D2E
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwReplyWaitReceivePort
Address: F18D5BF4
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwRequestWaitReplyPort
Address: F1779EC4
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwRestoreKey
Address: F17970FC
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwResumeThread
Address: F18D7E30
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSaveKey
Address: F18D332A
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSecureConnectPort
Address: F177A59C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetContextThread
Address: F18D4DBE
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSetInformationFile
Address: F17755A4
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetInformationObject
Address: F17A3F7C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetInformationToken
Address: F18D6586
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSetSecurityObject
Address: F1796C6A
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetSystemInformation
Address: F176F648
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetValueKey
Address: F1793F72
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSuspendProcess
Address: F18D7B7C
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSuspendThread
Address: F18D7CA4
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwSystemDebugControl
Address: F178EEA4
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwTerminateProcess
Address: F178EC20
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwTerminateThread
Address: F18D4956
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwUnloadDriver
Address: F177029C
Driver Base: F1759000
Driver End: F17D8000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwUnmapViewOfSection
Address: F18D780E
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

Function Name: ZwWriteVirtualMemory
Address: F18D4AE0
Driver Base: F18B4000
Driver End: F1903000
Driver Name: \SystemRoot\system32\DRIVERS\klif.sys

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied




Quote
has my information been vulnerable during this infection/invasion? In otherwords, paying bills on-line (at secure sites) or entering private info on the same sites, is there any chance that info has been compromised?
Well, you did have a rootkit which could have compromised your computer. Here's what you should do just to be safe.
Do you have ZoneAlarm Firewall?

It appears your system is infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue.

Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%.

Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and SECURITY tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to:

What danger is presented by rootkits?
Rootkits and how to combat them
r00tkit Analysis: What Is A Rootkit

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
What Should I Do If I've Become A Victim Of Identity Theft?
Identity Theft Victims Guide - What to do
It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot
be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully:
When should I re-format? How should I reinstall?
Help: I Got Hacked. Now What Do I Do?
Help: I Got Hacked. Now What Do I Do? Part II
Where to draw the line? When to recommend a format and reinstall?

Guides for format and reinstall:

how-to-reformat-and-reinstall-your-operating-system-the-easy-way

However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat.
If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful.

Should you have any questions, please feel free to ask.
*****************************************************
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Hi Dave,

Well, now that I’m thoroughly sick, I have questions, and I hope you can help and don’t mind continuing to help me
.
I run Zone Alarm Security Suite and the teatimer program (is it SAS, or Spybot? I’ve had it on my computer since you helped me a couple of years ago.) I also have WOT. I periodically update and run CCleaner, SAS, Spybot, Spyware Blaster, MBAM, although unfortunately I’ll admit it’s probably been 6 months. Why didn’t ZA or teatimer catch this stuff coming in? Do you think they prevented anything going out?

I tried reading all the links you provided; frankly, I was way in over my head and didn’t understand a good deal of it. I got the idea that rootkits can sometimes be purposely installed for legitimate use. In December I had problems logging into one of the servers at work through the internet, and the tech people said they had to remotely access my computer to fix the problem. They sent me an “invitation” I had to accept so they could gain remote access. Is there any chance that’s where the rootkits came from and they’re harmless? Is there any way to tell where they came from and what they did--or are doing?

I read also that malware can be downloaded to your computer through image files. Unfortunately, I have downloaded LOTS of image files--I draw as a hobby and when I see a picture I like, I download it to use as a reference. I have hundreds of pictures. I backed them all up to CD along with my other files when I did the back-ups this week. Would they have been scanned when downloaded? Would something have shown up if there was something in them? Could they/should they be scanned now on the CD? (I’d like to keep them if I could, but if there’s any chance they’ll do harm, I won’t keep them--but is it safe to get my other files off the disk now?)

Are there any other types of files malware could now be hiding in--word or excel files, for example..

I read that the only way to be sure my computer is clean is to reformat completely and reinstall the disks. I’m not sure I could handle that, even if I bought the disks (could it be done from the recovery disks, or does reformatting require original installation disks?) Besides, how safe is it really for how long--if this stuff got in once, why couldn’t it get in again the first time I went on-line? Is it really a fail-safe?

I don’t save/remember passwords, not even in Outlook for e-mail; I don’t keep password lists on my computer--but I do have a document I save to flash-drive with passwords. Is it possible my passwords are compromised anyway--could the info be stolen when I had the file open while working in it? Same with account #s--the only time they’re on my computer is when I type them in on a “secure” site. Wouldn’t that require a program to log keystrokes, and is there any way to tell if that happened? (I e-filed my taxes, all our taxes, on-line about a month ago. I shudder to think that I typed in social security #s and everything. Is this info vulnerable?)

One of the articles mentioned something about changing passwords if you use a router. We have a router; this computer is attached to the router through a line, but my daughter’s laptop is wireless. This computer is the administrator for the router. Is her computer in danger? Do I need to change the password? (And if I do, how do I know it’s safe to do it now?)

I had ZA off for about a day when it seemed to be causing the problem (I exited from the task tray; does that turn off the firewall too, or just the antivirus?) It’s been back on most of the time since then though. But teatimer resident is still off--I turned it off when your instructions said to. Should I turn it back on yet?

ZA scanned while ESET was scanning, and it came up with 4 items--but when I looked at them, it appeared they were all items quarantined by TDSSKiller. I’m assuming they’re nothing to worry about now. Is that correct?

Last thing: In prepping ESET to scan, the instructions said to check “scan archives”. When I checked that box, there was another box above it checked, the one for fix problems. Since the instructions didn’t say to check that box, I unchecked it. Should I have left it checked? Should I run ESET again with it checked?

My big fear is having done the income taxes and paying bills on-line, wondering how much of a possibility there is that my information was compromised. I thought as I was on a secure site there was nothing to worry about. Is there no way to determine if anything was stolen?

I apologize for all the questions; this really just has me sick. Here’s the scan; I appreciate anything you can do to help or any information you can give me.


[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ee88f3395f713448af264009a4a0aa3e
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-04-06 02:22:58
# local_time=2012-04-05 10:22:58 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 71250665 71250665 0 0
# compatibility_mode=8192 67108863 100 0 70886976 70886976 0 0
# compatibility_mode=9217 16776533 100 13 2026307 11854075 0 0
# scanned=153944
# found=4
# cleaned=0
# scan_time=20021
C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0002.dtaWin64/Olmarik.AD trojan (unable to clean)00000000000000000000000000000000I
C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0004.dtaWin64/Olmarik.AG trojan (unable to clean)00000000000000000000000000000000I
C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0005.dtaa variant of Win32/Rootkit.Kryptik.KS trojan (unable to clean)00000000000000000000000000000000I
C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0006.dtaWin64/Olmarik.AF trojan (unable to clean)00000000000000000000000000000000I
Quote
I run Zone Alarm Security Suite and the teatimer program (is it SAS, or Spybot?
Is your Zone Alarm Security Suite firewall enabled? TeaTimer belongs to Spybot.
Quote
Why didn’t ZA or teatimer catch this stuff coming in? Do you think they prevented anything going out?
If your Firewall is like mine I would imagine it caught the out-going traffic.
Quote
They sent me an “invitation” I had to accept so they could gain remote access. Is there any chance that’s where the rootkits came from and they’re harmless? Is there any way to tell where they came from and what they did--or are doing?
It's almost impossible to determine where the rootkit came from.
Quote
I read also that malware can be downloaded to your computer through image files. Unfortunately, I have downloaded LOTS of image files--I draw as a hobby and when I see a picture I like, I download it to use as a reference. I have hundreds of pictures. I backed them all up to CD along with my other files when I did the back-ups this week. Would they have been scanned when downloaded? Would something have shown up if there was something in them? Could they/should they be scanned now on the CD? (I’d like to keep them if I could, but if there’s any chance they’ll do harm, I won’t keep them--but is it safe to get my other files off the disk now?)
I really depends where you downloaded them from. I really can't say if they had been scanned but I would imagine they were. They should be scanned before replacing them on your computer. Scan them with your AV and also MBAM.
Quote
Are there any other types of files malware could now be hiding in--word or excel files, for example..
Not likely unless you received a file from someone who was infected.
Quote
I read that the only way to be sure my computer is clean is to reformat completely and reinstall the disks. I’m not sure I could handle that, even if I bought the disks (could it be done from the recovery disks, or does reformatting require original installation disks?) Besides, how safe is it really for how long--if this stuff got in once, why couldn’t it get in again the first time I went on-line? Is it really a fail-safe?
That's really the safest way to go and it is fail-safe
Quote
I don’t save/remember passwords, not even in Outlook for e-mail; I don’t keep password lists on my computer--but I do have a document I save to flash-drive with passwords. Is it possible my passwords are compromised anyway--could the info be stolen when I had the file open while working in it? Same with account #s--the only time they’re on my computer is when I type them in on a “secure” site. Wouldn’t that require a program to log keystrokes, and is there any way to tell if that happened? (I e-filed my taxes, all our taxes, on-line about a month ago. I shudder to think that I typed in social security #s and everything. Is this info vulnerable?)
That could only be done if a keylogger was put on your computer and there was no evidence of that.
Quote
One of the articles mentioned something about changing passwords if you use a router. We have a router; this computer is attached to the router through a line, but my daughter’s laptop is wireless. This computer is the administrator for the router. Is her computer in danger? Do I need to change the password? (And if I do, how do I know it’s safe to do it now?)
Some modems do have passwords on them and some don't. I probably wouldn't hurt to change it.
Quote
I had ZA off for about a day when it seemed to be causing the problem (I exited from the task tray; does that turn off the firewall too, or just the antivirus?) It’s been back on most of the time since then though. But teatimer resident is still off--I turned it off when your instructions said to. Should I turn it back on yet?
I'm not sure how ZoneAlarm works. You should turn on teatimer again.
Quote
ZA scanned while ESET was scanning, and it came up with 4 items--but when I looked at them, it appeared they were all items quarantined by TDSSKiller. I’m assuming they’re nothing to worry about now. Is that correct?
As soon as TDSSKiller is removed, they will be gone.
Quote
My big fear is having done the income taxes and paying bills on-line, wondering how much of a possibility there is that my information was compromised. I thought as I was on a secure site there was nothing to worry about. Is there no way to determine if anything was stolen?
I highly doubt it especially if you have the ZoneAlarm Firewall enabled.
Let's do some cleanup

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like FIREFOX.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Hi Superdave,
I can't thank you ENOUGH, both for helping me and for having the patience to answer all my questions (and address my fears!). I ran the scans you recommended. I have just a couple more questions:

I have been running Zone Alarm suite, spybot, and SAS for a couple of years; I update them periodically (I have to get back onto a schedule again, I admit) and also do scans with MBAM, CCleaner, Spyware Blaster...should I keep doing all of this, or are any of them not really necessary? I was thinking I should add TFC (or is CCleaner enough), ESET, Securia occasionally...should I? Should I also be running anything else on a regular basis (like TDSSkiller?) or are these better left to only when there are problems and someone who actually knows what they're doing is supervising their use?

Should I now delete all of the programs we used in this fix and their logs from my desktop, or just move them to a folder and keep them?

Secunia listed 4 instances of Java; I checked Java's website and they said delete older versions, so I'm just updating the latest.

Are we all done now, and would it be OK to defrag? With all the stuff I've removed, I'm sure it needs it.

Again, Thank you for all you've done; I can't imagine how I would have handled this without you. As I said, this computer is my livelihood and my family's sole income and source of security. What you've done is extremely important. Thank you again!Quote
I have been running Zone Alarm suite, spybot, and SAS for a couple of years; I update them periodically (I have to get back onto a schedule again, I admit) and also do scans with MBAM, CCleaner, Spyware Blaster...should I keep doing all of this, or are any of them not really necessary?
It's probably not necessary but if you have the time it wouldn't hurt.
Quote
I was thinking I should add TFC (or is CCleaner enough), ESET, Securia occasionally...should I?
Wouldn't hurt.
Quote
Should I also be running anything else on a regular basis (like TDSSkiller?) or are these better left to only when there are problems and someone who actually knows what they're doing is supervising their use?
No, that's not necessary.
Quote
Should I now delete all of the programs we used in this fix and their logs from my desktop, or just move them to a folder and keep them?
Not necessary. You probably won't need them again.
Quote
Are we all done now, and would it be OK to defrag? With all the stuff I've removed, I'm sure it needs it.
It's a good idea to do that about once a month.

You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3214.

Solve : Computer processing noises are driving me crazy?

Answer»

It may just be my computer, but in the last 5 or 6 months it seems like it is getting more and more bogged down and the constant processing / clicking noise is driving me crazy. Before I spent any money upgrading ram or anything, I would like to have my logs checked to make sure there isn't something else going on.

I have a Gateway E-4610S Desktop with 2GB Ram and a 80GB Hard Drive with less than 25% being used.

Here are my logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/05/2012 at 00:45 AM

Application Version : 5.0.1146

Core Rules Database Version : 8418
Trace Rules Database Version: 6230

Scan type : Complete Scan
Total Scan Time : 00:44:55

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 451
Memory threats detected : 0
Registry items scanned : 32725
Registry threats detected : 0
File items scanned : 113686
File threats detected : 80

Adware.Tracking Cookie
ictv-ic-ec.indieclicktv.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\E4JWD5RD ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.game-advertising-online.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
ad2.adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.dmtracker.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.www.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
www.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.dmtracker.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.usatoday1.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.truevalue.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
wstat.wibiya.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media2.legacy.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media2.legacy.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.timeinc.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.msnportal.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.countingcrows.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.countingcrows.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]


Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.05.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Mike :: MICHAEL [administrator]

4/5/2012 9:10:13 AM
mbam-log-2012-04-05 (09-10-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 236085
Time elapsed: 5 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Mike at 9:18:35 on 2012-04-05
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.387 [GMT -5:00]
.
AV: Kaspersky Anti-Virus *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\ievkbd.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe"
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259633329522
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{B7D8324C-E688-45B7-B0AF-BA9589464CC3} : DhcpNameServer = 192.168.1.254
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\mike\application data\mozilla\firefox\profiles\uk3k73oz.default\
FF - plugin: c:\documents and settings\mike\application data\mozilla\firefox\profiles\uk3k73oz.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll
FF - plugin: c:\documents and settings\mike\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_228.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
.
============= SERVICES / DRIVERS ===============
.
R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2010-6-9 132184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-6-30 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-6-30 31704]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-9-3 475736]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608]
R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe [2010-11-2 365336]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2011-6-30 1983232]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-5-7 32856]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-12-28 287232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 253600]
.
=============== Created Last 30 ================
.
2012-04-05 04:53:40418464----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-03-22 19:56:32592824----a-w-c:\program files\mozilla firefox\gkmedias.dll
2012-03-22 19:56:3244472----a-w-c:\program files\mozilla firefox\mozglue.dll
.
==================== Find3M ====================
.
2012-04-05 05:10:4570304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-11 21:13:4531704----a-w-c:\windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13:44494968----a-w-c:\windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13:4318056----a-w-c:\windows\system32\drivers\cmderd.sys
2012-03-11 21:13:1933984----a-w-c:\windows\system32\cmdcsr.dll
2012-03-11 21:13:18301224----a-w-c:\windows\system32\guard32.dll
2012-02-03 09:22:181860096----a-w-c:\windows\system32\win32k.sys
2012-01-11 19:06:473072------w-c:\windows\system32\iacenc.dll
2012-01-09 16:20:25139784----a-w-c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 9:20:16.57 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/30/2009 10:00:06 PM
System Uptime: 4/4/2012 11:51:14 PM (10 hours ago)
.
Motherboard: Intel Corporation | | DQ965MT
Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz | | 1864/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 73 GiB total, 54.859 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) 82566DM Gigabit Network Connection
Device ID: PCI\VEN_8086&DEV_104A&SUBSYS_0001107B&REV_02\3&61AAA01&0&C8
Manufacturer: Intel
Name: Intel(R) 82566DM Gigabit Network Connection
PNP Device ID: PCI\VEN_8086&DEV_104A&SUBSYS_0001107B&REV_02\3&61AAA01&0&C8
Service: e1express
.
==== System Restore Points ===================
.
RP382: 1/6/2012 10:23:33 PM - System Checkpoint
RP383: 1/7/2012 11:06:15 PM - System Checkpoint
RP384: 1/8/2012 11:30:15 PM - System Checkpoint
RP385: 1/10/2012 12:37:10 AM - System Checkpoint
RP386: 1/11/2012 1:18:15 AM - System Checkpoint
RP387: 1/11/2012 3:00:17 AM - Software Distribution Service 3.0
RP388: 1/12/2012 3:31:35 AM - System Checkpoint
RP389: 1/13/2012 4:31:35 AM - System Checkpoint
RP390: 1/14/2012 4:43:35 AM - System Checkpoint
RP391: 1/15/2012 4:43:55 AM - System Checkpoint
RP392: 1/16/2012 5:49:43 AM - System Checkpoint
RP393: 1/17/2012 6:56:56 AM - System Checkpoint
RP394: 1/18/2012 7:43:56 AM - System Checkpoint
RP395: 1/19/2012 7:44:08 AM - System Checkpoint
RP396: 1/20/2012 8:44:07 AM - System Checkpoint
RP397: 1/21/2012 9:44:08 AM - System Checkpoint
RP398: 1/22/2012 9:44:27 AM - System Checkpoint
RP399: 1/23/2012 10:56:28 AM - System Checkpoint
RP400: 1/24/2012 3:00:15 AM - Software Distribution Service 3.0
RP401: 1/25/2012 3:56:27 AM - System Checkpoint
RP402: 1/26/2012 3:00:15 AM - Software Distribution Service 3.0
RP403: 1/27/2012 3:21:23 AM - System Checkpoint
RP404: 1/28/2012 3:25:46 AM - System Checkpoint
RP405: 1/29/2012 4:31:58 AM - System Checkpoint
RP406: 1/30/2012 5:14:11 AM - System Checkpoint
RP407: 1/31/2012 5:36:44 AM - System Checkpoint
RP408: 2/1/2012 5:48:43 AM - System Checkpoint
RP409: 2/2/2012 6:37:49 AM - System Checkpoint
RP410: 2/3/2012 7:36:44 AM - System Checkpoint
RP411: 2/4/2012 7:37:31 AM - System Checkpoint
RP412: 2/4/2012 5:58:59 PM - Installed Ice Cream Tycoon
RP413: 2/5/2012 11:54:07 PM - System Checkpoint
RP414: 2/7/2012 12:37:03 AM - System Checkpoint
RP415: 2/8/2012 12:49:03 AM - System Checkpoint
RP416: 2/9/2012 1:49:03 AM - System Checkpoint
RP417: 2/9/2012 8:07:35 AM - Installed H&R Block Premium + Efile + State 2011.
RP418: 2/10/2012 8:42:56 AM - System Checkpoint
RP419: 2/11/2012 9:08:34 AM - System Checkpoint
RP420: 2/11/2012 10:51:10 AM - Installed H&R Block Missouri 2011.
RP421: 2/12/2012 11:28:25 AM - System Checkpoint
RP422: 2/15/2012 7:14:01 PM - System Checkpoint
RP423: 2/15/2012 10:05:11 PM - Software Distribution Service 3.0
RP424: 2/16/2012 10:05:36 PM - System Checkpoint
RP425: 2/17/2012 10:17:55 PM - System Checkpoint
RP426: 2/18/2012 10:59:14 PM - System Checkpoint
RP427: 2/19/2012 11:10:10 PM - System Checkpoint
RP428: 2/20/2012 11:58:09 PM - System Checkpoint
RP429: 2/22/2012 12:10:09 AM - System Checkpoint
RP430: 2/23/2012 1:10:09 AM - System Checkpoint
RP431: 2/24/2012 2:10:09 AM - System Checkpoint
RP432: 2/25/2012 2:58:29 AM - System Checkpoint
RP433: 2/26/2012 3:10:30 AM - System Checkpoint
RP434: 2/27/2012 3:58:29 AM - System Checkpoint
RP435: 2/28/2012 5:10:29 AM - System Checkpoint
RP436: 2/29/2012 6:10:30 AM - System Checkpoint
RP437: 3/1/2012 6:58:29 AM - System Checkpoint
RP438: 3/2/2012 7:58:29 AM - System Checkpoint
RP439: 3/3/2012 7:59:03 AM - System Checkpoint
RP440: 3/4/2012 8:59:07 AM - System Checkpoint
RP441: 3/5/2012 9:59:08 AM - System Checkpoint
RP442: 3/6/2012 9:42:24 PM - System Checkpoint
RP443: 3/7/2012 10:11:59 PM - System Checkpoint
RP444: 3/8/2012 10:59:59 PM - System Checkpoint
RP445: 3/10/2012 12:12:02 AM - System Checkpoint
RP446: 3/11/2012 2:12:02 AM - System Checkpoint
RP447: 3/12/2012 3:12:05 AM - System Checkpoint
RP448: 3/13/2012 6:15:41 AM - System Checkpoint
RP449: 3/14/2012 3:00:19 AM - Software Distribution Service 3.0
RP450: 3/15/2012 3:24:25 AM - System Checkpoint
RP451: 3/16/2012 4:24:25 AM - System Checkpoint
RP452: 3/17/2012 4:46:08 AM - System Checkpoint
RP453: 3/18/2012 5:46:07 AM - System Checkpoint
RP454: 3/19/2012 5:50:52 AM - System Checkpoint
RP455: 3/20/2012 6:49:21 AM - System Checkpoint
RP456: 3/21/2012 7:48:57 AM - System Checkpoint
RP457: 3/22/2012 8:23:47 AM - System Checkpoint
RP458: 3/23/2012 8:47:53 AM - System Checkpoint
RP459: 3/24/2012 8:48:12 AM - System Checkpoint
RP460: 3/25/2012 10:26:15 AM - System Checkpoint
RP461: 3/26/2012 10:48:10 AM - System Checkpoint
RP462: 3/27/2012 11:00:11 AM - System Checkpoint
RP463: 3/28/2012 12:00:14 PM - System Checkpoint
RP464: 3/29/2012 12:48:11 PM - System Checkpoint
RP465: 3/30/2012 1:00:10 PM - System Checkpoint
RP466: 3/31/2012 1:00:44 PM - System Checkpoint
RP467: 4/1/2012 2:00:44 PM - System Checkpoint
RP468: 4/2/2012 2:48:43 PM - System Checkpoint
RP469: 4/3/2012 4:00:45 PM - System Checkpoint
RP470: 4/4/2012 4:48:44 PM - System Checkpoint
.
==== Installed Programs ======================
.
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.2)
Adobe Shockwave Player 11.5
Apple Application Support
Apple Software Update
BeerSmith
CCleaner
COMODO Internet Security
Epson Event Manager
Epson FAX Utility
Epson PC-FAX Driver
EPSON Scan
EPSON WorkForce 610 Series Printer Uninstall
EPSON WorkForce 630 Series Printer Uninstall
EpsonNet Print
EpsonNet Setup
EpsonNet Setup 3.3
GIMP 2.6.4
H&R Block Missouri 2011
H&R Block Premium + Efile + State 2011
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Ice Cream Tycoon
Intel Audio Studio 2.0
Intel(R) Active Management Technology LMS Service and SOL Driver
Intel(R) Management Engine Interface
Intel(R) PRO Network Connections Drivers
Java(TM) 6 Update 26
Kaspersky Anti-Virus 2011
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2000 Premium
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 11.0 (x86 en-US)
NETGEAR WG111v3 wireless USB 2.0 adapter
NetZero For Cosmi
OpenOffice.org 3.0
QuickTime
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2416400)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
SigmaTel Audio
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
SpywareBlaster 4.4
Squeezebox Server 7.6.1
SUPERAntiSpyware
Tux Paint 0.9.21c
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Search 4.0
Yahoo! BrowserPlus 2.9.8
.
==== Event Viewer Messages From Past Week ========
.
4/1/2012 12:04:04 AM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied.
.
==== End Of File ========================Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Download Combofix from any of the links below, and save it to your DESKTOP.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:


Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will CONTINUE it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.Thank you for taking a look. Here is the log from ComboFix.

ComboFix 12-04-07.02 - Mike 04/07/2012 7:24.16.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.323 [GMT -5:00]
Running from: c:\documents and settings\Mike\Desktop\AV Tools\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 )))))))))))))))))))))))))))))))
.
.
2012-04-05 04:53 . 2012-04-05 05:10418464----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-03-22 19:56 . 2012-03-22 19:56592824----a-w-c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-22 19:56 . 2012-03-22 19:5644472----a-w-c:\program files\Mozilla Firefox\mozglue.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-05 05:10 . 2011-07-02 01:4770304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-11 21:13 . 2011-06-30 14:3897760----a-w-c:\windows\system32\drivers\inspect.sys
2012-03-11 21:13 . 2011-06-30 14:3831704----a-w-c:\windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13 . 2011-06-30 14:38494968----a-w-c:\windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13 . 2011-06-30 14:3818056----a-w-c:\windows\system32\drivers\cmderd.sys
2012-03-11 21:13 . 2011-12-24 01:1333984----a-w-c:\windows\system32\cmdcsr.dll
2012-03-11 21:13 . 2011-06-30 14:37301224----a-w-c:\windows\system32\guard32.dll
2012-02-04 23:59 . 2012-02-04 23:5969632----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut5_75E8EDD2A1E346219D6D5DDBB46E7CDE.exe
2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut4_E636F7D111FF4BB7A8037F8F16F3DE73.exe
2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut1_E636F7D111FF4BB7A8037F8F16F3DE73.exe
2012-02-03 09:22 . 2009-09-21 20:291860096----a-w-c:\windows\system32\win32k.sys
2012-01-11 19:06 . 2012-02-16 02:123072------w-c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2009-09-21 20:40139784----a-w-c:\windows\system32\drivers\rdpwd.sys
2012-03-22 19:56 . 2011-09-01 23:5297208----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2004-10-15 65588]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-10-12 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Squeezebox Server Tray Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Squeezebox Server Tray Tool.lnk
backup=c:\windows\pss\Squeezebox Server Tray Tool.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Mike\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37843712----a-w-c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 13:2259240----a-w-c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-08-21 12:0015360----a-w-c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2009-12-03 15:12976320----a-w-c:\program files\Epson Software\Event Manager\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
2009-12-03 05:00847872----a-w-c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-10-29 15:1786016----a-r-c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-10-29 15:1798304----a-r-c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
2006-07-13 20:349134080----a-w-c:\program files\Intel Audio Studio\IntelAudioStudio.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-10-29 15:1781920----a-r-c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 20:28421888----a-w-c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 17:59254696----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\EpsonNet\\EpsonNet Setup\\tool09\\ENEasyApp.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:Squeezebox Server 9000 tcp (UI)
"9001:TCP"= 9001:TCP:Squeezebox Server 9001 tcp (UI)
"9002:TCP"= 9002:TCP:Squeezebox Server 9002 tcp (UI)
"9003:TCP"= 9003:TCP:Squeezebox Server 9003 tcp (UI)
"9004:TCP"= 9004:TCP:Squeezebox Server 9004 tcp (UI)
"9005:TCP"= 9005:TCP:Squeezebox Server 9005 tcp (UI)
"9006:TCP"= 9006:TCP:Squeezebox Server 9006 tcp (UI)
"9007:TCP"= 9007:TCP:Squeezebox Server 9007 tcp (UI)
"9008:TCP"= 9008:TCP:Squeezebox Server 9008 tcp (UI)
"9009:TCP"= 9009:TCP:Squeezebox Server 9009 tcp (UI)
"9010:TCP"= 9010:TCP:Squeezebox Server 9010 tcp (UI)
"9100:TCP"= 9100:TCP:Squeezebox Server 9100 tcp (UI)
"8000:TCP"= 8000:TCP:Squeezebox Server 8000 tcp (UI)
"10000:TCP"= 10000:TCP:Squeezebox Server 10000 tcp (UI)
"9090:TCP"= 9090:TCP:Squeezebox Server 9090 tcp (UI)
"3483:UDP"= 3483:UDP:Squeezebox Server 3483 udp
"3483:TCP"= 3483:TCP:Squeezebox Server 3483 tcp
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/30/2011 9:38 AM 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/30/2011 9:38 AM 31704]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 4:43 PM 11352]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 1:25 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [6/29/2010 12:48 PM 116608]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 4:13 PM 38144]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 11:06 AM 32856]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 7:27 PM 19472]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 6:02 PM 287232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/4/2012 11:53 PM 253600]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ADOBEFLASHPLAYERUPDATESVC
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:10]
.
2012-04-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\uk3k73oz.default\
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-07 07:31
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(868)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(304)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-04-07 07:33:09
ComboFix-quarantined-files.txt 2012-04-07 12:33
ComboFix2.txt 2011-07-06 22:16
ComboFix3.txt 2011-07-02 03:47
ComboFix4.txt 2011-04-08 03:38
.
Pre-Run: 58,909,536,256 bytes free
Post-Run: 58,930,921,472 bytes free
.
- - End Of File - - D10E599F924B7B5F6570E2E1C1F4E353
I seriously doubt that your computer is infected. I suspect that the noise you hear is some of the hardware going bad; either your harddrive or one of the fans. You could open the box and see if you can isolate the noise.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Okay that's good news, and I seriously hope I'm not wasting your time. I explained my situation to a reliable source who said it sounded like a bug. I do sincerely appreciate your help.

Here is the ESET log. Thank you.

[emailprotected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=17e1e7d750000e45a6e1160e9aef7e3e
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-04-07 09:23:17
# local_time=2012-04-07 04:23:17 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 73272399 73272399 0 0
# compatibility_mode=768 16777215 100 0 52699339 52699339 0 0
# compatibility_mode=1024 16777215 100 0 45287938 45287938 0 0
# compatibility_mode=1280 16777175 100 0 18655359 18655359 0 0
# compatibility_mode=3073 16777213 80 71 1012073 9320834 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=71721
# found=0
# cleaned=0
# scan_time=2000
Quote
I explained my situation to a reliable source who said it sounded like a bug.
I haven't seen an infection that would make noises on the computer. I can't see anything bad on your computer. You will have to open the box and try to see what is making the noise. Please let me know what you find.
3215.

Solve : Computer acting weird and no Internet Access?

Answer»

You should contact your Internet Service Provider to set up a connection.i contacted them they state the issue is with Internet Explorer not RESPONDING and the virus may have wiped out my drivers?They were unable to help,not sure what i am going to do now?Ok. Let's try to create a NEW connection. Click Start, Control Panel, Network connections and click "create a new connection". You will get the connection Wizard. Click NEXT and select Connect to the internet. Click choose from a list of ISP's and click next. Since I don't know your ISP you will have to search for it. The next drop-down box has two options. The first is Get online with MSN(only GOOD in US.) and the second is Select from a list of ISP's.

3216.

Solve : Computer classroom always virus infected.?

Answer»

Every one, we are computer classroom adminitrator, because all COMPUTERS are USED for all students.
during one week, there is virus infected, it is REALLY headached to manage all computers when there is virus infected.

Is there any good way to solve this problem? Don't you INSTALL antivirus software? It does't WORK?

3217.

Solve : major problems with computer speed. Need big time help?

Answer»

That looks good. If there are no other issues, we can do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press ENTER, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
**************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two.
* Please LET TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & DESTROY. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Okay. I have completed everything. Computer runs so much better than before. Thanks for all of your help! Sincerely.
Now can I uninstall any of the programs you had me install throughout this cleanup process?

Also, would you suggest me incresing my RAM? I only have 2GB. Quote
would you suggest me incresing my RAM? I only have 2GB.
Vista only requires 1 Gb so you should be good with 2.

Quote
Now can I uninstall any of the programs you had me install throughout this cleanup process?
YES. You should consider keeping SAS and MBAM. Update them and run them on a regular basis.

You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3218.

Solve : Windows 7 Computer Turns Off Every Time ANY Folder Is Opened?

Answer»

I Have Windows 7 Gateway SX2851

Its been a couple months now when i was gone, someone was using computer when i came back it was messed up. no previous problems. Now anytime i open ANY folder (new folder, my documents, my computer etc.) the computer turns off within 1-5 seconds and goes to blue screen, But I can RUN any program and open control panel, start menu, internet, play music or movies and open files on the desktop, the only way to access files off desktop is through start menu search. Originally I Only Had AVG Free, and CCleaner, Since problem I have ran many security programs (Norton, Avira, Avast, Superanti Spyware, Malware Bytes, Ad Aware, Boot Scans Etc.) Also have performed ChkDsk disk check, SFC Scannow from Command Prompt, Data Lifeguard Diagnostic for windows, Uniblue Registry Booster.

Please someone give any advice to help fix this. Even if i can access the folders temporarily it will give me time to back up my files on external hd and restore the computer. Thank YouDownload BlueScreenView:
http://www.nirsoft.net/utils/blue_screen_view.html
unzip downloaded file and double click on BlueScreenView.exe to run the program.
when scanning is done, go to EDIT - Select All
Go to FILE - SAVE SELECTED Items, and save the report as BSOD.txt
Open BSOD.txt in Notepad, copy all of the content, and paste it into your next replyBecuase of the problem i cant even save anything because it opens the save as folder and turns off, so i had to copy it by hand

Dump File -040712-17768-01.dmp
Crash Time -4/7/2012 12:07:49 PM
Bug Check String -KMODE_EXCEPTION_NOT_HANDLED
Bug Check Code -0x0000001e
Paramater 1 -ffffffff`c0000005
Paramater 2 -fffff880`0578d5d0
Parameter 3 -00000000`00000000
Paramater 4 -00000000`00000000
Caused By Driver -ntoskrnl.exe
Caused By Address - ntoskrnl.exe+7cd40
File Description -NT Kernel & System
Product Name -Microsoft® Windows® Operating System
Company -Microsoft Corporation
File Version -6.1.7601.17727 (win7sp1_gdr.111118-2330)
Processor -x64
Crash Address -ntoskrnl.exe+7cd40
Stack Address 1 -
Stack Address 2 -
Stack Address 3 -
Computer Name -
Full Path - C:\Windows\Minidump\040712-17768-01.dmp
Processors Count -4
Major Version - 15
Minor Version - 7601
Dump File Size - 262,144






Dump File -040712-18314-01.dmp
Crash Time -4/7/2012 12:00:16 PM
Bug Check String -KMODE_EXCEPTION_NOT_HANDLED
Bug Check Code -0x0000001e
Paramater 1 -ffffffff`c0000005
Paramater 2 -fffff880`06f0a5d0
Parameter 3 -00000000`00000000
Paramater 4 -00000000`00000000
Caused By Driver -ntoskrnl.exe
Caused By Address -ntoskrnl.exe+7cd40
File Description - NT Kernel & System
Product Name -Microsoft® Windows® Operating System
Company -Microsoft Corporation
File Version -6.1.7601.17727 (win7sp1_gdr.111118-2330)
Processor -
Crash Address -ntoskrnl.exe+7cd40
Stack Address 1 -
Stack Address 2 -
Stack Address 3 -
Computer Name -
Full Path - C:\Windows\Minidump\040712-18314-01.dmp
Processors Count -4
Major Version - 15
Minor Version - 7601
Dump File Size - 262,144Does the same thing happen if you boot to safe mode?

Have you recently updated any drivers?

Do you still have multiple antivirus apps installed? If so, please pick one and delete all of the rest. You should never have more than one installed.

Open device manager - any yellow or red SYMBOLS?

See if anything here helps: http://support.microsoft.com/kb/275678i also cant boot in safe mode, while starting up it freezes and will not boot all the way

Not that i know of manually, maybe if set for auto

No i have uninstalled the extras

Nothing Red Or Yellow in Device Manager

And ill be working on trying the suggestions on that link
i ended up fixing it! I restarted my computer in selevtive startup, got access to folders and backed up all my files on external hd and restored the computer to new thank you for the helpOkay, thanks for the follow up. Glad you're all sorted out. I'm a little surprised a selective startup worked since you could not boot to safe mode.

3219.

Solve : Computer turning off and desktop icons not showing?

Answer»

Specs: Gateway 835 GM Windows XP Intel Pentium D CPU, 2.80 GHz 1.0GB RAM, Intel 82945G

I'm not sure if this is a VIRUS PROBLEM or what. But this suddenly started happening Thursday. My computer will randomly turn itself off and when it turns back on it says Windows was not able to successfully turn on. Then it gives me LIKE 5 options including Safe Mode, Last Successful Configurement etc... when I finally get Windows up I get a "windows has recovered from a serious error". I don't know if my computer was getting to hot and turning off? But I cleaned off my fan and it still happened.

NOW my computer is working but my desktop icons disappear within 30 minutes of my computer being on. They are still there now but I'm not sure how long that will last. I ran AVG, Ccleaner (as suggested by someone on here in a previous post) but have not been using my computer long enough to see if that did the trick. Any ideas on what it could be? Let me know if I need to tell you anything else. I'm going crazy trying to figure it out.
Quote

I cleaned off my fan and it still happened.
You only have ONE fan??!! Hopefully you have more. Try cleaning them all out then use the computer with the side OFF so it's open to the air. Check all your fans are working as they should.

I don't know why your desktop icons should vanish like that unless, as you say, it's because of malware operating. When the icons disappear what happens then? Does your computer shut down? Do you have a blank desktop but otherwise all seeming to work OK? What?

Quote
I ran AVG
I assume you are referring to the AVG free antivirus program scan.

If so then try this to start with...

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

------------------------------------------------------------------------------------------------------


If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow for any maware revealed.


OJ

Well I cleaned off the one in the back. It had dust all over it.

When the icons disappear and I go into "desktop" via the start menu I get "windows cannot access the desktop because another program is using this process". That's not word for word what it says but is basically doesn't help matters. The only thing present is my trash can. No files will open either until after I restart. I'm going to run that program in safemode and see if it detects anything. Then I'll post the hijackthis log. Thank you for your help.No problems yet. I will check back if I have any. Thanks for the help!
3220.

Solve : **UPDATE ON WINFIXER FAMILY OF MALWARE**?

Answer»

The scum that write this stuff are being brought to BOOK ...

http://www.theinternetpatrol.com/lawsuit-filed-against-winfixer-aka-errorsafe-winantispyware-winantivirus-systemdoctor-and-drivecleaner

You ALSO have their address if you feel like JOINING in the complaints.


OJthanks ALOT for the info oddjob


unlovedwarrior

3221.

Solve : need help finding and deleting a link for a virus?

Answer»

we have been trying to find a link for days now. we think it may be a virus from an EMAIL. our computer will slow down, freeze up, and states " internet explorer CAUSED an error, and also says SHPRRPRT.DLL." we have tried to find this link or file but everything says that "link/file" is not found or will not let us OPEN a program to find it. PLEASE HELP!!!!! What antivirus and antispyware protection are you using? Try it ALL in safe mode with system restore turned off and post back.war3006.......

This spyware BHO (smrtshpr.dll) is related to SmartShopper

Have you run your anti virus and your antispyware APP from safe mode ? A good antispyware to try is the AVG antispyware ......
get it at http://free.grisoft.com/doc/20/lng/us/tpl/v5 ...make sure to get the latest updates.

Please post a hijackthis log here for us to have a look at ...... after you have run the above mentioned scans.


dl65

3222.

Solve : AVG Free Edition?

Answer»

I have the AVG Free Edition 7.1 which is no longer supported by Grisoft. I'm having difficulty uninstalling it. I tried to DELETE the files as well as remove it from the Add/Remove program but it will not allow me to uninstall. There was a WARNING to the effect that it failed initialization. I don't want it in my PC any longer because the support was somewhat lousy. It won't even acknoledge the license number given to me. Anyone got any ideas how to delete this monster altogether? ThanksTry using ccleaner.AVG Free edition has been updated to version 7.5, and their free antivirus product is still FREE it is a misunderstanding that the product is no longer available but it is FREE ans available from here:-

http://free.grisoft.com/doc/1It's true that AVG is still free, but donsor's version is no longer supported by Grisoft, meaning that they no longer provide updates and whatnot for it.

donsor, if you can get 7.1 off of your COMPUTER, I would advise downloading 7.5; it works very well and the support for it is great.You can install 7.5 right on top of it. If you insist on uninstalling 7.1 first, you have to disable the active scan first. (Right click on the icon in the task bar.)As the product is free and ONE of the best along with having an excellent support forum that is also free i can't understand you bashing it as an inferior program...
But that's just me.

3223.

Solve : OMG PLEASE HELP ME PLEASE!!?

Answer»

ok, im on my laptop and i had a bunch of apps running, and i was very frustrated, so i just turned it off, well, then i turned it BACK on and this black screen keeps SAYING that i can reboot my comp, but it is running very SLOW, and sometimes my computer works but it is super slow, and i think i have a virus, but how do i get rid of it pLEASE HLEP MEPlease see below.Sometimes it helps to turn the computer off, unplug it (to MAKE sure everything is off). Wait a minute or two then plug it in and reboot.Turn the light off....

3224.

Solve : Help please XP! Analyst of Hijackthis?

Answer»

Hello everyone! If anyone could help me I'd really appreciate it.

Problem: Computer has slowed tremediously.

Solutions i've tried: Avg-Antispyware, Avg-Antivirus, Ad-Adware SE Personal, Trojan Hunter, Spybot Search and Destroy, V-cleaner, Find Junk Files software. As far as the system itself i've defrag, disk-cleanup, delete cookies, delete history, delete temporary files under internet options.

The harddrive is fine and I'm seriously at a loss. I downloaded hijackthis but I don't know what to delete if anyone could tell me possibly what to delete i'd appreciate it.

Specs of Computer

Dell Pentium 4
Windows XP Home Edition
256 Ram
1.79 GHz

Logfile of HijackThis v1.99.1
Scan saved at 6:14:44 PM, on 2/28/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet EXPLORER v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Don Nichols\My Documents\Unzipped\hijackthis_199\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SideStep Browser Helper - {08351227-6472-43BD-8A40-D9221FF1C4CE} - C:\WINDOWS\Downloaded Program Files\SbCIe027.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [expcat] C:\WINDOWS\Speech\expcat.exe
O4 - HKLM\..\Run: [*runole] C:\WINDOWS\msagent\runole.exe
O4 - HKLM\..\Run: [*crnut] C:\WINDOWS\Tasks\crnut.exe
O4 - HKLM\..\Run: [*utilcom] C:\WINDOWS\Tasks\utilcom.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [7b8b] C:\WINDOWS\onoptca.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [7b8—?¿L+ú\mú"À‰üžigC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\onoptca.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [YdcvyxCM] C:\WINDOWS\xsbmf.exe
O4 - HKLM\..\Run: [Fast start] C:\WINDOWS\system32\ntnut.exe home
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\BIN\PPCOLink -STATION
O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\System32\dxdlg32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.Unfortunately, I'm only just STARTING to learn this stuff, so I can't tell you too much because I'd hate to accidentally have you remove the wrong thing. What I can tell you, however, is that the guys here will need your complete log. Messages a 5500 character maximum, so you'll have to use multiple posts. The log should go all the way down to 023.

Just from a quick glance of what you posted, I can see that you have at least the Trojan.ISTsvc and Troj/VB-CXT trojans (probably more). So, while you wait for the experts to come along, I WOULD advise updating your protection.It also looks like you need to update your Java (I actually need to get the latest update now that I think about it). And I'm wondering...why don't you have the Windows XP Service Pack 2 installed? Both of these things can help with your protection.O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winxpdll32.exe] C:\WINDOWS\System32\winxpdll32.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe027.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {C72242D0-3AB5-453D-842C-8A3C9AC0838D} - http://download.sidestep.com/get/k00719/sb027.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: JFWService - FREEDOM Scientific BLV Group, LLC. - C:\JAWS402\jfw.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Server Advance (ServerAC) - Unknown owner - C:\WINDOWS\System32\Security.exe (file missing)

Quote

....I'm wondering...why don't you have the Windows XP Service Pack 2 installed? Both of these things can help with your protection.
Well spotted, CBMatt, BUT there is one big problem.

NEVER install SP2 on a machine which is, or may be, infected with malware. It will heap trouble on trouble.

First, evonna_21, you MUST install SP1a. Get it here ....

http://www.microsoft.com/windowsxp/downloads/updates/sp1/default.mspx


THEN rescan with HJT and post a fresh log for review.


OJThanks for everyone's advice
I installed service pack 1 computer went dead. uninstalled computer still slow.Do you still have your Dell WIndows CD?Hey, Im pretty new at this too as you can probably tell but, maybe your over thinking the problem. It could be fairly simple. I dont know if this will help you at all but anytime my laptop starts to slow down, I look at my desktop. I always make sure its fairly clean. I only have a few things on my desktop. So why dontyou try getting rid of some of the stuff on there and see if that helps.

Hope this helps,
-Melissa-evonna_21 .... I don't know what has been going wrong for you. SP1 and SP1a wouldn't cause this problem on their own. I can only guess there is a bigger problem. If you CARRY on browsing the web on this computer without Service Packs your machine will be a magnet to malware. All sorts of nasties will get in.

Follow GX1_Man's advice. Do you have that disk?

If not ... please keep the computer OFFLINE, rescan with HJT and post a fresh log (using a different computer, obviously). I'll see what can be done to try and fix the computer without Service Packs.


OJ
3225.

Solve : AD-AWARE SE PROBLEM?

Answer»

Heu Guys

Just started having this problem today, when I run Adaware it stops when it GETS to CLSID whatever that is. Every time I cancel and restart it stops at the same file again, any ideas?Its happen to me b4 is probly a virus stopping you from opening the file.

Ad Ware Se Detects about 25% of the Adwares on your computer I use to use it.

When I used a diffrent Ad Ware Program it detected 50 sometihng out of the 18 Ad Ware SE found.

I suggest getting a AV like AVG or MCafree run a scan if you cant install it, itss because the virus or trojan is preventing you from installing it. If this does happen.Save everytihng in a USB or Disk and REBOOT your computer from the begining if you have WINDOWS XP press F10 when the computer starts and the computer will begin to reboot everything now you WONT have any Trojans,Viruses,Worms,Adware,Spyware,or any other malicious program.When CLSID is showing it is checking the registry. It is not unusual for AdAware to "appear" to be stopped when it fact it is not. How much time do give it before deciding it is stopped? When this happens, watch the "items checked" for a few minutes to see if it changes.Some good advice here but, if you continue to have trouble, try this .....

Download Ewido/AVG Anti Spyware from here (this prgram will also remove adware) ….

http://www.ewido.net/en/

It has a FULLY working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

----------------------------

If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow for whatever it is that's causing the problem.


OJ

3226.

Solve : Sandboxie 2.79.3 Beta?

Answer»

Any opinions or views on Sandboxie 2.79.3 Beta? I have seen it as a download on majorgeeks and wondered if it was WORTH installing it, but don't WANT to make the same mistake as I did with spyware terminator which caused more problems than it cured.
Thanks for any replies.
Link to Sandboxie 2.79.3 Beta below.

http://www.majorgeeks.com/Sandboxie_d4993.htmlIt has been running on my benchtest machine for a few weeks now...no issues to report as of yet.

PATIO. 8-)Thanks Patio. I will give it a couple of weeks and if you have not posted any problems about it will give it a TRY.

3227.

Solve : log of my computer anti spyware results?

Answer»

Can someone analyze these results for me?
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:13:54 PM 3/9/2007

+ Scan result:



HKLM\SOFTWARE\Classes\AlxTB.BHO -> Adware.Alexa : IGNORED.
HKLM\SOFTWARE\Classes\Popup.PopupKiller -> Adware.Alexa : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} -> Adware.Generic : Ignored.
HKU\S-1-5-21-4039157630-3002777719-1478863617-1007\Software\ADV -> Adware.Generic : Ignored.
C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL -> Adware.IESearch : Ignored.
C:\WINDOWS\SYSTEM32\vtsqn.dll -> Adware.Virtumonde : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Hijacker.Generic : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e52dedbb-d168-4bdb-b229-c48160800e81} -> Hijacker.Generic : Ignored.
HKU\S-1-5-21-4039157630-3002777719-1478863617-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Hijacker.Generic : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Addynamix : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Bluestreak : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Ru4 : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Specificclick : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Specificclick : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][1].txt -> TrackingCookie.Tribalfusion : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Craig Davis\Cookies\craig [emailprotected][2].txt -> TrackingCookie.Zedo : Ignored.


::Report end
The log shows evidence of a fair amount of rubbish, some more serious than others.

First ... go here and RUN through the process to remove Vundo ....

http://www.bleepingcomputer.com/forums/topic18610.html


When done update your AVG Anti Spyware to the latest definitions then scan your computer with it in safe mode. Save the log as you did before.


Download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a LOGFILE".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread.

Also let us know if you are experiencing any trouble.

More specific removal INSTRUCTIONS will follow for anything that's causing problems.


OJ

3228.

Solve : IE7 Running Slow?

Answer»

So if u could let me know which problems to fix from my scan recently posted, that would be very helpful

Thankyou

mattWell, nothing jumps out at me.
We'll have to wait for a HJT expert to come along an analyse it, I know a fair amount but it's easy to miss things, better to wait for someone who knows exactly what's wrong and how to fix it.ok ty for your help anywayI will move this where it may be SPOTTED better. Thankyou for moving the topic GX1_MAN, hopefully i,ll get some answers as my computer is running no faster!!

takes me about 3 minutes to get the web browser up and making some strange noises!!


thanks for any help

MattWhat "strange noises" and when do they happen?

**************

So far as the log goes it's not in bad shape.

However, I see that you do have many processes running (that could slow the system down) and you use PalTalk.

You should check through your processes to see if there are any that you don't need.

Also Paltalk is an advertising-supported program and can let in malware. I strongly recommend you remove/uninstall it immediately.

**************

Once you have done that .... download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe MODE. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

**************

Reboot to normal mode, scan with HJT and post the AVG AS repost and the HJT log here.

Please also update us on how your COMPTER is operating now. Any better?


OJHello OJ,

Thank you very much for your advice,

I downloaded AVG and ran a scan in safe mode and fixed the selected 16 threats it found.

I,ve also ran the hjt and below are is the log from this scan.

It seems to running faster already after the avg scan

thanks again for your help and any further advice.


Logfile of HijackThis v1.99.1
Scan saved at 13:25:10, on 05/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
E:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
E:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\winmine.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe


Matt..the rest of the scan log;

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?f73872f5b454420fb18270efeebf8f0e
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?f73872f5b454420fb18270efeebf8f0e
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Program Files\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Program Files\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Nothing dreradful in the log (although I see you have decided to keep Paytalk )

**************

Open HJT and fix this entry with it IF it's still present ...

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


As ALWAYS ... close ALL open windows before you click on "Fix Checked" at the foot of the HJT window.

**************

Your Java is a little out of date.It's up to version 6 now. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
.

**************

After this, and what you said in your last post, your computer is clean.

Remember to update AVG AS from time to time and scan your computer to keep it relatively clean.

**************

If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well WORTH reading.

If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/


Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.


OJ




3229.

Solve : Aplication close unexpected..pls help me?

Answer»

Dear Experts,

On my Windows XP SP2....when I clicked on "Add Remove Program" on Control Panel, the new pop up window of "Add Remove Programs" appeared as normal...but I dont know why it close automatically without any orders...ANOTHER same case, time and situation, even the same for some application...for instance, when I open application of Windows Fax Viewer, the application close automatically still without any orders....I have no idea what was going on... anyone can help me please what is going on and how to fix this matter? and what the name of the virus or something is please?

Thank's a lot for your HELPS..

NatashaTry this...go to Start / Run and TYPE in sfc /scannow and hit Enter...have your XP CD handy.Hi,

Thank you for your advice. I already follow your steps but still did not WORK. When I open an application CALLED "Window Pictures and Fax Viewer", it opened but when I press any button, suddenly close...any other solution for me pls?

Natashabut do you have a windows cd? and what protection are you using?


unlovedwarrior

3230.

Solve : Best Fire Wall??

Answer»

Advice please? Is Zone Alarm free a good fire wall? Is Jetico BETTER, or is there ANOTHER free one that you would recommend? Thanks for any advice. LINK to Jetico download (from Majorgeeks) below.
http://www.majorgeeks.com/Jetico_Personal_Firewall_d4480.htmlI recommend Sygate Personal Firewall.
It's free, powerful and doesn't slow your system as much as ZoneAlarm.
Just my opinion.Here are links to some ...


Zone Alarm > http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za

Sygate > http://www.simtel.net/product.download.mirrors.php?id=53687

Kerio Firewall > http://www.sunbelt-software.com/Kerio.cfm

Agnitum > http://www.agnitum.com/products/outpost/

m0n0wall > http://m0n0.ch/wall/
(I’ve heard good things about monowall but it takes some setting up, I believe)

SMOOTHWALL > http://www.smoothwall.org/

Tiny Personal > http://www.webmasterfree.com/tpfw.html

Outpost > http://www.agnitum.com/products/outpostfree/download.php

[Footnote … the NORMAN Personal Firewall looks like it isn’t compatible with vista but this may change.]


OJ

3231.

Solve : Freezing at start-up?

Answer»

When ever I start up my computer I have to keep moving the mouse for about 5 minutes. When I do sit there and move the mouse it will work fine, its just a pain. When I first start it up it will APPEAR at the log-in screen and then from there I can access my account and go to the desktop. But, when I start up and it first gets to the log in screen if I am not sitting there and moving the computer will freeze. My computer makes those noises inside it when I am starting it up and when it freezes it becomes completely silent and nothing will work. I have to them turn it off and boot it back up. I haven't a foggiest what this COULD be. If anyone could help explain this to me, that would be excellent!

Thanks,
Brentino
PS: If you need any additional information please post it and I will see what I can do. Yes, how about some basic information about the computer? See below for starting points.Very well.

My computer is a Gateway, Microsoft Wimdows XP Edition verson 2002. It is Pentium 4, 3.00 GHz, 512 MB of RAM.

If I missed anything please tell me. Gatway model and age?

XP Home or Pro?

Sevice Pack?

When did the problem start?

What have you tried to FIX it?

Are you the only one using this computer?

Virus and spyware protection?

Other hardware issues?

Etc.?

Where's Dr. Patio?

Done.
Gateway model 2002, Home edition, Sevice Pack 2.

I can't remember when it started happening, just some random day. I have done nothing since to fix it because I don't have any idea how to. My sister is sharing the computer with me, but she is never on. We have McAfee virus protection, no spyware.
if you can get Ccleaner spybot search and destroy and avg antispyware, update them all reboot in safe mode(press f8 rapidly while booting up) with system restore off.


run ccleaner and also the issue scan( make a back up when it asks

run spybot

then run avg antispyware


unlovedwarriorUW, it's been three weeks! Thank you unloved, I am currently installing all of that and I am going to try.

Brentino Uunloved, I tried installing those things and ran them but, they didn't seem to do anything. But, this morning I turned it on and it worked I think because I uninstalled some of my Simcity 4 Plugins. So, I'm good...for now

BrentinoBrentino it sounds like SimCity4 is the CULPRIT here and has caused other problems per your other thread...is this an "Ahem" copy by chance ? ?I'm not exactly sure what you mean by "copy" but they are two different problems that happened at two different times, so I MADE two different threads. I uninstalled SC4 and deleted all the plugins and the freezing up problem seemed to stop, but the icon one hasn't been fixed yet.

B :-?Quote

[highlight]I'm not exactly sure what you mean by "copy"[/highlight] but they are two different problems that happened at two different times, so I made two different threads. I uninstalled SC4 and deleted all the plugins and the freezing up problem seemed to stop, but the icon one hasn't been fixed yet.

B :-?

What our dear patio means is...is this a legitimate copy of SC4 that you bought, or is it one that you downloaded and found a serial number for? If it's the latter, then that can cause a lot of trouble. Even looking for cracks/serials/keygens for games will often get you bugged.Quote
Quote
[highlight]I'm not exactly sure what you mean by "copy"[/highlight] but they are two different problems that happened at two different times, so I made two different threads. I uninstalled SC4 and deleted all the plugins and the freezing up problem seemed to stop, but the icon one hasn't been fixed yet.

B :-?

What our dear patio means is...is this a legitimate copy of SC4 that you bought, or is it one that you downloaded and found a serial number for? If it's the latter, then that can cause a lot of trouble. Even looking for cracks/serials/keygens for games will often get you bugged.

Thank you for translating. No, this is a real copy of the game. I have the box, and CD case and serial number and all of that jazz.
3232.

Solve : How to find a backdoor?

Answer»

This is a fairly simple question (I think) what is the easiest way to find a backdoor?

-Melissa-Melissa17........ Backdoor ........ usually found at the back of the house .

If you are looking for hack tips , you have come to the WRONG place ..... unfortuneatly we dont offer that sort of help.
What is it your trying to find a back door for ?

dl65 Yes, if you're looking for hacking tips, you'll want to look ELSEWHERE. But if you're looking for backdoors/trojans that may exist on your computer, I would suggest looking into AVG Anti-Virus, AVG Anti-Spyware, and TrojanHunter. And I'm sure everyone here can give you even more good suggestions.

ALSO, check Rob Pomeroy's Software FAQ.Im trying to find ways of finding backdoors so that I can make my own PROGRAM that prevents people using all these different ways of entering computers. I figure that if I know how a "Hacker" thinks and works and if I know how these worms and backdoors and trojans for example work then I can build against them. Any words of wisdom??? lol. Sory for the confusion

-Melissa-If you want to learn how a hacker operates you will need to master at least one programming language first.

This may help take you into the mind of a hacker ...

http://www.catb.org/~esr/faqs/hacker-howto.html


OJQuote

If you want to learn how a hacker operates you will need to master at least one programming language first.

This may help take you into the mind of a hacker ...

http://www.catb.org/~esr/faqs/hacker-howto.html


OJ

good read i found that a while backawsome, thanks so much guys. What language would you recommend starting with. Im awsome with HTML and XHTML. Iv also heard of Perl and C++ but I dont know where to start.Have a read throught that article I posted. This is the extract on the author's view on programs ...

http://www.catb.org/~esr/faqs/hacker-howto.html#skills1


OJOk thats perfect thanks so much again
3233.

Solve : Newdotnet infection - how??

Answer»

that suxs
Quote

I already emailed them last NIGHT asking about it.
They replied pretty soon, and said that they were in no way affiliated with NDN and advised locking my HOSTS file as read-only, which I had already done, and to keep my firewall enabled.
Their spelling was pretty bad too, [highlight]I think it MAY have been wangming [/highlight]. . .
I replied asking them the same thing in a different way, waiting to hear back from them now.
I can't even threaten to drop my service, I'm TIED into a 12 month contract which ends in a few months.



Funny, but true . . . You'd think if they were after a GOOD reputation for customer service they'd at least try to use proper spelling and punctuation.
Anyway, I'm thinking of taking business elsewhere, turns out my contract is over so I can leave, if they let me.
3234.

Solve : HJT?

Answer»

I was wondering...where can I find a good HJT tutorial? It's such a useful program and we're all using it pretty frequently, so it'd be nice to know how to read the logs better. I can kinda get the main gist by looking at them and can sometimes spot things that shouldn't be there, but I don't quite fully understand everything involved.You could have a look, >here<, >here<, >here<, or >here<. Hope that helps.

8-)fffreakThanks a lot for the links. Those are super helpful. It's a lot of info and I'm a little tired, so I can't read it all right now, but what I've read so far has already cleared up quite a few questions I had. Thanks again; this is exactly what I was looking for.Your welcome, again easy to find when you're using Google.Sorry to go of topic but i have often wondered when sending a link
how do i change the link to here or try this eg ??
You could have a look, >here<, >here<, >here<, or >here<. Hope that helps.
Skyblue

It is called BBCode, you can do this by...

Code: [Select][url=http://www.google.com/]Google[/url]Thank you
Now that tells me what its called,the question was how do i do it???
SkyblueI already told you .

Code: [Select][url=http://www.google.com/]google[/url]He just showed you how. Use that code he posted as a guideline.

Code: [Select][url=THE URL OF THE SITE YOU'RE LINKING TO]TEXT[/url]
For example...
Code: [Select]Please click [url=http://www.google.com]here[/url]
Turns into...
Please click here.CBMatt .... glad to hear someone else has caught the bug. With HJT it is imperative you remember old addage .... a little knowledge is a dangerous thing. The malware that you see in the log could be the tip of the iceberg. Much malware just hides deeper than HJT can see. Contrary to what some folk think HJT doesn't reveal everything. Far from it.

There are free training places where you can learn the art of HJT fixing better than just "reading up" on it.

Here are some of the best .....

TechSupprtForums "Academy"
http://www.techsupportforum.com/tsf-academy/

Malware Removal "University"
http://forum.malwareremoval.com/viewtopic.php?t=233

Tom Coyote "Classroom" http://forums.tomcoyote.org/index.php?showtopic=1421

Bleeping Computer "HJT Study Hall"
http://www.bleepingcomputer.com/forums/topic4970.html

Geekstogo "Geek University" (GeekU)
http://www.geekstogo.com/forum/Would_you_like_to_learn_to_fight_malware-t4817.html

SpywareInfo "BOOT camp" http://forums.spywareinfo.com/index.php?showtopic=34


You register at a school ... have a look round to see what's involved ... make your decision if you want to go ahead. You don't have to. There's no compulsion. Many people decide the committment's not there, it's too difficult or they simply haven't got the time. Oh yes .... to do it properly will take a lot of work and study but it will be worth it in the end.


Happy hunting.


OJThanks for all of the helpful links, oddjob. I'm looking into those sites right now. I'm busy with school, but I'm still interested in being adept with this program. I'm already starting to be able to point out CERTAIN things fairly quickly, which is nice. But of course, I still need more experience.With HJT follow what other experienced analysts do, google HJT entries and see what they indicate and, yes, do read up on those tutorials. They will give you an idea of what the entries can mean.

The author wrote the main tutorial on which all others are based. You can read his tutorial here ...

http://www.merijn.org/htlogtutorial.php


When looking at other analysts' work you must not necessarily believe everything you read. Follow only the recommendations of people who are clearly correct in what they say. For example, if the analyst is a member of ASAP or is an MVP you can trust what they are doing.

One small warning at the moment. In your research you may well see two programs being used when analysts fix HJT but which you must avoid at present.... Avenger and Combofix.

Avenger involves writing specific instructions/code for the specific problem of the user in question. It's a VERY powerful tool and can easlily trash a system if someone else carries out the instructions. What I'm saying is that you can learn a lot by reading other analysts' fixes to problems but NEVER copy what they do with Avenger. At least not until you have more experience with HJT first.

Combofix is a "point & shoot" tool. The user could d/l it, run it and it will fix many things without user intervention. It's very popular and easy to recommend to a user.

HOWEVER, at the moment, the author of Combofix has pulled the tool from use. He has development problems with it. It must NOT be used for the time being. There are doubts as to whether the tool will ever return.

Let us know what "training school" you choose.


OJThis took me a couple of days because I've been super busy with school. But I finished up the MAJORITY of my current project, so I have a bit more time now. I looked around at the different sites and I think I'm going to give Geeks To Go a try. It seemed like the most appealing forum to me. So, I've submitted an APPLICATION. And now, I guess I WAIT to see if I get accepted or not.

By the way, I've found another really helpful tutorial...

http://hometown.aol.co.uk/jrmc137/hjttutorial/tutorial.htmYes, Matt, that is also a useful HJT tutorial. All these tutorials will be based on Merijn's own master copy but perhaps some are easier to follow.

If in any HJT entry gives you doubt ... check with Merijn's one and research what other recognised analysts do with a given entry.

Best of luck with your G2G application. I have no doubt you will be accepted (although do let me know if there's a problem).

Happy bug hunting!


OJJust to let you know, I've been accepted and I'm currently working on my first practice log. I haven't received any feedback yet, but I'm confident that I did well. My girlfriend is totally making fun of me, but I'm determined to do well in this. I'm already working on some of my canned speeches. Heh. Oh, and thanks for your help via PM. I'm downloading the two anti-malware programs you suggested and I'll run them as soon as they're done. Yay for dial-up...

I'm going to have to get some sleep pretty soon because I have class in a few hours, so I might have to let you know how it goes later today.

3235.

Solve : Virus or I did something wrong?

Answer»

Windows XP running Norton AV 2007.
A had an alert that said I hadn't run a full system scan in a while...so I ran it.
Next thing I get an error with code 3038,107 and a button to find out more info. I click it and the comp freezes.
Ctrl-Alt-Del doesnt work so i TUNED it off with the power button.
Then upon restarting, it would not get past the welcome screen.
I started in safe mode and went back a month. Now upon rebooting, I make it to where I can see my background before it freezes and craps out.

I ran a HJT log in safe mode (my user, not admin), but have no idea what it means...
Help?
HJT part1:


LOGFILE of HijackThis v1.99.0
Scan saved at 5:15:22 PM, on 6/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Keith Stegmaier\My Documents\download\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB002" /M "Stylus C82"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [AllerCalc] "C:\Program Files\AllerCalc\AllerCalc.exe" /i
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Startup: TDK Launcher.lnk = C:\Program Files\TDK\TDKLauncher\TDKLauncher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
HJT log part 2:

O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download Flash with Flash Capture - C:\Program Files\Flash Capture\dl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.radicalplay.com/socca/joystick.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/ricochet/ReflexiveWebGameLoader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo UPLOADER) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O19 - User stylesheet: (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Compaq Advisor - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Content Monitoring Tool - Unknown - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe



plz run hijackthis in normal mode so we can get all of the things that run.. safe mode limits the things that can run..

do you have any other protections?? if not take a look a my signature for some ideasi have spybot and adaware...from what ive read on the boards here i might switch to avg and dump norton once i get things worked out

I'd love to give you a HJT log from normal mode......... [edit...running spybot and adaware now...hopefully after reboot I can at least get to normal mode]you can get into normal mode?? ok dl superantispyware and avg antispyware update them in safe mode with networking if need be then run Ccleaner and then scan with your protection programsStegs ...... What is the current state of your machine ........?
Was the highjackthis log generated before or after you used system restore ?
What have you done since....... ?

Have you tried to undo the system restore ?
It also seems you are using an outdated hijackthis ......perhaps getting the current version would be a good idea.
The log you produced was done in safe mode ...and it does show that at least one trojan is in your machine.
If .....reversing the system restore, will let you boot up in normal, let us know and we can go on from there .


dl65 got the new HJT and updated adaware and s&D
ran in both safe and normal...
i havent gotten any other antispyware yet, as it took a few hours just to do this...
here is the updated normal HJT log

Logfile of HijackThis v1.99.1
Scan saved at 10:08:10 PM, on 6/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\AllerCalc\AllerCalc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\TDK\TDKLauncher\TDKLauncher.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Keith Stegmaier\My Documents\download\Hijack This\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [AllerCalc] "C:\Program Files\AllerCalc\AllerCalc.exe" /i
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Startup: TDK Launcher.lnk = C:\Program Files\TDK\TDKLauncher\TDKLauncher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

continued

O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download Flash with Flash Capture - C:\Program Files\Flash Capture\dl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.radicalplay.com/socca/joystick.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/ricochet/ReflexiveWebGameLoader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O19 - User stylesheet: (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Stegs ....... How is the machine working now ? You must be up and running in normal mode now....... Were you able to run a complete anti-virus scan ?
You should update your Java ...... it's out of date.
There are several minor things that show up in the logfile, but we will only remove them if you are still having issues.

Please let us know how it is running now.


dl65


dl65...Thanks for your help and patience...

It CAN run in normal mode.
The problem is still that it takes ages to do things.
Startup took at BEST 40 minutes. Simply right clicking on a shortcut takes 3-5 minutes just for the command options to pop up (open, cut, copy)
Now my Norton tells me I need to activate it. (how did it un-activate itself?)
I didn't do an anti-virus yet (just MULTIPLE different kinds of anti-spyware) simply because it took hours just to do all the antispyware tests and hjt.
I will try downloading AVG and running tonight.
I will also try to update Java.

3236.

Solve : Win32/Rustock.gen!C virus HELP!!?

Answer»

i got the Win32/Rustock.gen!C according to windows after sending a error report. it KEEPS restarting my computer, and wont let me update. i had it for a while probably because i was not able to update for a while. recently i cant even stay on normal mode for more than a minute , it just turns off. im on safe mode right now. how do i remove it, nothing works. pleas help.DLoad; INSTALL; update and run AVG Anti-Spyware and Stinger in safe mode with SYSTEM restore turned off.

Then post back with your results...

You didn't list what protection programs you have...this info would be helpful as well.still doesnt work. everytime i try to install updates my computer turns off.. =(Scan with HijackThis and post a log for us to look at. If you can manage to, please try to do the scan in Normal Mode. It's not as effective in Safe Mode, but if that's all you can manage, we'll do our best to work with it.

Also, download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the PROMPTS and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.Quote from: swift328 on June 14, 2007, 05:10:43 PM

still doesnt work. everytime i try to install updates my computer turns off.. =(

This means you did what was suggested and still have the same issues ? ?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3237.

Solve : Please have a look?

Answer»

I am not experiencing any problems at the moment so no rush,
is there anything that shoudnt be their Logfile of HijackThis v1.99.1
Scan saved at 07:34:48, on 22/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Trust\MI-4550XP WIRELESS OPTICAL MINI MOUSE\Mouse32a.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Power Mixer\pwmixer.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\Program Files\ZyXEL\ZyXEL G-202 Wireless Adapter Utility\ZyXEL G-202.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-4550XP WIRELESS OPTICAL MINI MOUSE\Mouse32a.exe
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Power Mixer] "C:\Program Files\Power Mixer\pwmixer.exe" /m
O4 - GLOBAL Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: ZyXEL G-202 Wireless Adapter Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\NETWORK Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe

Looks clean to me.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


You don't need those, so go ahead and fix them.

That aside, I don't see anything you need to worry about. You have anti-virus and anti-spyware, a firewall, and Windows and Java are current. It all looks GOOD.

However, I would suggest moving HijackThis to C:\Program Files\HJT. It's a much better spot where it can work better.Thanks for that (i said no rush )
SkyblueHeh,you're welcome. Don't worry, there's not much activity tonight.Quote

there's not much activity tonight.

Might be tonight for you buts good morning for me
skyblueWell, it's finally morning for me now (3 AM). And I've still got so much left to do before I can go to bed!As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3238.

Solve : Big infection! Can't stop it!?

Answer»

At the beginning it just not responded when I would go to the propertys of a harddrive.
Next thing I knew I could even go to the file tap.
I've tryed CHKSDK/F , SFC /SCANNOW ,System restore
System restore would only fix my problem for 5 min after that I just had the same thing I did this 3 times and the last time it would even repear the problem.
As my protection I have Windows Live OneCare.
I Dloaded and installed the 3 AVG's 2 days ago after I removed them I started to have problems.
I will poste my logfile after this post.
Please help me I'm desperate I've TRIED everything I know

Thanks in advance

Jonas Logfile of HijackThis v1.99.1
Scan saved at 19:13:59, on 16/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\twatdog.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
E:\Mijn programma's\Hijack\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [TridentWatchDog] twatdog.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O8 - Extra context MENU item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000Last time I've got an error message (see attach)
When I run Ccleaner at the Issue part I always have an empty entry {-
What is this??
How can I stop it from doing this?
I think it is a VIRUS but it is moving fast.
I 'll scan with Windows OneCare but as I don't think it is going to find it because otherwise it would when I was infected at first (like it usualy do)
Should I Dload the AVG products?

Jonas

[cleaning up - attachment deleted by admin]I've fixed these entries :
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
By google them I've found that they are no suppos to be there
What else can I do because the problem is still going on
I scaned my PC with AVG AV, AVG AS, Superantispyware, Windows Live OneCare
And not one of them found something
then I runed AVG Anti rootkid but I found nothing.
What NOw???
Nothing seems to work

Jonas
How is the drive being reported in Disk Management ? ?

My Computer/right clik and select Manage...then choose Disk Management.Here it is I don't see anything special just that my C: drive is getting full.

Jonas

[cleaning up - attachment deleted by admin]I don't understand how that drive is even running...it's full.

Your C: drive is FAT32
D: is NTFS
E: is also FAT32
F: NTFS.

Is there a reason it is setup this way ? ?

Also D: is practically empty...you can move a bunch of stuff there from C: as long as there not Program files...think in terms of strivctly data files : music, photos, movies etc.Oh but the problem is C: is only used a a program and windows drive sow there's nothing to move.
ecutaully C, D and E: are the same drives but in the begining the person who Installed the whole PC (din't knew anything about PC's at that time) has splited the drive.
is it possible to make C and D one Dirve?
D is NTFS because it read somewhere that that is the most secure drive but I'll change that back becaus now I realise how stupit it is.
and F: has to be NTFS because WLOC (Windows Live OneCare) will only backup at NTFS drives.
I'll try to find something I can set from C to E but I don't think there is goning to be something.

Jonas Jonas...
The "cannot find IDLIST" appears to usually be related to Intel Wireless drivers. Have a look here.



You didn't post a full log. From what I can see right now, it looks clean, but it's important to post the whole thing because there could be an infection there.



You have the MegaUpload toolbar on your computer. Are you sure this is something you want? You might want to take a look a this excerpt from the toolbar's EULA...
"This toolbar integrates certain services from Alexa Internet, Inc. ("Alexa"). The toolbar may exchange data with Alexa in order to provide: (a) information to you about the web pages you view (ranking information, for example) and (b) basic information to Alexa on your use of the toolbar, including the IP address of your computer, the URL of the web pages you visit and, because the toolbar communicates via HTTP, data typical of normal HTTP communications such as user agent and operating system, will be communicated."

We often consider Alexa to be spyware, so you might want to think about that.



As for CCleaner...I'm not familiar with such an entry. If you right-click on it and open the entry in Regedit, where does it take you? What's the path of that registry entry?Now I have 2Gig free space on C; drive and still have the problem.
Here is a screenshot of the regesrty entry.
I've fixed these entries :
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
Didn't do anything wrong with that I hope.
I removed the Megaupload toolbar do not need him anymore (Was needed for school)
I 'll post a new ogfile in the next 2 post

Jonas

[cleaning up - attachment deleted by admin]Logfile of HijackThis v1.99.1
Scan saved at 19:54:27, on 17/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\twatdog.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Computer\Hijack\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [TridentWatchDog] twatdog.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://tremo4ever.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168273091096
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe" /Service (file missing)
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exeAlright, your log looks clean. For future reference, please refrain from fixing entries on your own. It's easy to disable something important without knowing it.

Did you check out that link I posted?

And this registry entry...when you fix it with CCleaner, it just comes back? What if you manually delete the entry yourself?allright I 'll not do it again.
I was just desperet as my computer was having a strange behavior.
I checked you link I think the problem with me was that my firewall (including ports was restted when I used System restore.)
The regesty just comes back if I restart my computer.
when it shutsdown I ALLWAYS get an error sound like you normally should get an error message but its allways at the time that my pc just goes to the Blue screen and says Windows is shutting down.
I still can't go to the propertys of all my hardrives.
And I don't know how to remove the regestry as I don't know the full path.
Maybe I wouldn't even be able if I knew I only know how to get to the register that's all.
By the way thanks for your help

Jonas Quote

but in the begining the person who Installed the whole PC (din't knew anything about PC's at that time) has splited the drive.

This says it all. How would you like your machine setup ? ?

25G sounds a bit high for just the OS and Programs...No the person how did it is a computer specialist and a good friend of my dad I really trust him.
But when I go to the properties of every folder and I count them together I have 12gig on that drive ?! how is this possible?
Here is whats on the drive and the documents and settings of all users are changed to the E: drive.Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM
allright I 'll not do it again.
I was just desperet as my computer was having a strange behavior.
You haven't disabled anything too important. But next time, you could end up disabling something vital, and that wouldn't be good.

Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM
I checked you link I think the problem with me was that my firewall (including ports was restted when I used System restore.)
If you disconnect from the internet and disable your firewall, do you still get any errors?

Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM
And I don't know how to remove the regestry as I don't know the full path.
Maybe I wouldn't even be able if I knew I only know how to get to the register that's all.
By the way thanks for your help
First, backup your registry with a program like ERUNT... In CCleaner, if you right-click on the entry, you'll be given the option to open it in Regedit. After doing so, you can delete the APPROPRIATE entry. However, I suspect this will have the same results as fixing it with CCleaner.Quote from: CBMatt on June 17, 2007, 09:39:17 PM
Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM
I checked you link I think the problem with me was that my firewall (including ports was restted when I used System restore.)
If you disconnect from the internet and disable your firewall, do you still get any errors?
I don't have that problem anymore I don't know why it stopped but it looks like it fixed itself

Quote from: CBMatt on June 17, 2007, 09:39:17 PM
Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM
And I don't know how to remove the regestry as I don't know the full path.
Maybe I wouldn't even be able if I knew I only know how to get to the register that's all.
By the way thanks for your help
First, backup your registry with a program like ERUNT... In CCleaner, if you right-click on the entry, you'll be given the option to open it in Regedit. After doing so, you can delete the appropriate entry. However, I suspect this will have the same results as fixing it with CCleaner.
Tried it. No luck.

any other suggestions are more than welcome
thanks for helping me but I think that I 'll have to do a format C: (If there is no other way)

Jonas So, the errors have stopped then? Is that registry entry the only concern? If it's not giving you problems, I would just leave it alone until we can find some more information about it. It may be a bit annoying, but it should be harmless.No I still can't right click on a hardrive.
then the explorer freeses.
I've Dloaded and ran Eusing Free Registry Cleaner
That found much more regesty errors but the explorer process I still freesing.

Jonas The C drive contains much more than I've putted on it when I stop the $C Sharing The I get the error Message are you sure you want to stop there are still FOLDERS who are shared But I didn't share anything on that drive or is this error message normal?

Jonas I'm afraid this might be a bit out of my range. You could back up your important data and reformat, but I would wait to see what patio has to say first.As I'm looking I can see that My C: drive is getting full again whitout I save anything on it.
How is this possible is my computer hacked?
What can I do about it?
I can't access the secutery settings to look if there is anything wrong because the explore process freese when I try it!
If I only format the C drive will this be enought to stop all this troble?

Jonas Formatting solves all Windows-related problems. However, if it is a hardware issue, it will eventually return. I don't really see this as being a hardware issue, though.Yes but I have 3internal and one external hard drive.
And those 3 internal hard drives are actually the same but are splitted when Win XP was first installed sow.. what about only formatting C: drive good idea??
Than I won't lose any data

Jonas To be perfectly honest, Jonas, I'm not entirely sure. It's not my field of expertise...you may want to take your question over to the Hardware section to see what they have to say there.
3239.

Solve : Need the most advanced spyware?

Answer»

Hello all!

I have seriously sensitive information on my computer and all I have
is AVG FREE. It has caught and stopped 3 spy attacks.

I need to be CERTAIN that I have the best there is!

I don't care if you give me a link you're selling through. I trust that
you geeks here would only sell me something you approve of!

So, give me some names and where to go!

Thanks, Pennie77 You need a spyware or you need an anti-spyware?

Fact: There is no best anti-malware or anti-spyware program out there. And you should accept that. Hehe.


Malwarebytes and SUPERAntiSpyware are not the best, but I'm using both of it.


Personally I use Microsoft Security Essentials. Asking what is the "best" is only going to START arguments. If AVG Free has stopped 3 "spy attacks" perhaps you need to review your browsing and downloading habits?
Quote from: Salmon Trout on AUGUST 04, 2011, 01:46:01 AM

Personally I use Microsoft Security Essentials. Asking what is the "best" is only going to start arguments. If AVG Free has stopped 3 "spy attacks" perhaps you need to review your browsing and downloading habits?

I'm thinking of putting Microsoft Security Essentials on a old laptop I have is it easy to setup/update etcQuote from: mystic1 on August 04, 2011, 05:00:12 AM
I'm thinking of putting Microsoft Security Essentials on a old laptop I have is it easy to setup/update etc

Very easy to install and update, in fact you can set it to update automatically.
Will give it a go then, thanks for the reply Hi Pennie. You should have a layered approach to malware, spyware, etc. While you should only run one AV program and one Firewall program, you can run more than one malware programs. I would suggest that you turn on Windows Defender. You can also install ThreatFire and also look at some of the suggestions I've posted below.
You can also install Malwarebytes Anti-Malware (link and instructions below) and SuperAntiSpyware ( linked below with instructions.) These are not full-time scanners unless you pay for them but you can run them anytime you feel like doing so to keep your computer clean.

You can download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the LATEST version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

CLOSE browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the BOX for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
****************************************************
SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.Quote from: SuperDave on August 04, 2011, 04:11:49 PM
Hi Pennie. You should have a layered approach to malware, spyware, etc. While you should only run one AV program and one Firewall program, you can run more than one malware programs. I would suggest that you turn on Windows Defender. You can also install ThreatFire and also look at some of the suggestions I've posted below.
You can also install Malwarebytes Anti-Malware (link and instructions below) and SuperAntiSpyware ( linked below with instructions.) These are not full-time scanners unless you pay for them but you can run them anytime you feel like doing so to keep your computer clean.

You can download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
****************************************************
SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping [b]Yourself Safe On The Web [/b] [/URL] for tips and free tools to help keep you safe in the future.

This is one of the reason I joined this forum for finding sites/tips like the one's you've suggested feeling like I'm learning more each time I visit this site mystic1, did you really need to quote all that? And did your post really add anything? This is not a chat room.

3240.

Solve : Bots on my devices?

Answer»

My laptop has a bot and I suspect my iTouch and Dsi to have one to. My laptop won't even GO on the interent anymore. All of these DEVICES had recieved warnings to from comcast SAYING malicious software detected. I have very little knowledge of these things and am going insane. So patience would be suggested....
It's scary when a Dsi is infected because it's the least suspected to me. Desperate help.
Well, for the laptop, you could start at download.com to get your anti-spy free protection. Pc Tools is pretty reliable, so is AVG...
Download DDS from HERE or HERE and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open TWO (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.



1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After DOWNLOADING the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )

3241.

Solve : Imesh problems - please help?

Answer»

Quote

The Imesh search bar has also finally gone (yay) so not sure if that means all is ok now??
Yes. Your computer is clean. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press ENTER, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
If this doesn't remove ComboFix, please let me know.

*****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ENSURE a complete cleaning.
*****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

GO to Microsoft Windows Update and get all critical updates.

----------

I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Ahhhh much better

Thank you so much for all of your help Dave I really appreciate it!!Quote from: Lulylu on July 31, 2011, 09:29:04 PM
Ahhhh much better

Thank you so much for all of your help Dave I really appreciate it!!
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3242.

Solve : Checking out downloaded file?

Answer» HEY guys,
I just downloaded a rar file for a program, and unzipped it to get a .exe file. Before i run it, tho, I want to know if it's virus free. I already scanned it with my antivirus program, but is there ANYTHING ELSE I can do?
I'm using a laptop running windows VISTA, and I have AVG free edition 2011
P.S. sorry for the noobish postWhat is the file and from where did you obtain it?
3243.

Solve : sending emails at 2 am?

Answer»

Here is the Jotti again -

http://virusscan.jotti.org/en/scanresult/a7205d5b72308fe0ae22111f97151bdb0cb1ff19/567
0fa35050531c4676fc366f9c23531bf198a43Here is the 'avenger' log.

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Completed script processing.

*******************

Finished! Terminate.


here is what I see on the Jotti scan.




Jotti's MALWARE scan
This file has been scanned before. The results for this previous scan are listed below.





--------------------------------------------------------------------------------

Filename: is-INFQS.exe
Status: Scan finished. 0 out of 20 scanners reported malware.
Scan taken on: Wed 13 Apr 2011 12:40:22 (CET) Permalink



--------------------------------------------------------------------------------
Additional info
File size: 709456 bytes
Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5: c88c64609de58fa3d8637c4866c7c6bb
SHA1: b1484070813fe2910385ab92167199d5784ea3e f



I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
it is doing the eset scan right now - i neglected to follow through with all of your instructions and am doing so now. thank you i will post the scan results as SOON as it is finished. (just for info - i do not think the computer has sent any 'unauthorized' emails in the last few days) I would still like to know if there is ANYTHING in here that should not be there.Eset displayed that no threats were found - there is no list of found threats so I have nothing to put here.

70714 files scanned - scan time 2 hours and 4 minutes and 5 seconds--- I clicked "finished"Ok. I'm quite sure that your computer is clean. We can now do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
**************************************************
If this doesn't remove ComboFix, please let me know.

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a COMPLETE cleaning.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thank you very much Dave.
Since I did remove anything etc. is there a reason the computer was sending out the emails that you may know of?
Thank you again so much for your help.Quote
Since I did remove anything etc. is there a reason the computer was sending out the emails that you may know of?
Thank you again so much for your help.
ComboFix did removed some malware which may have been causing the problem
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
3244.

Solve : Foreign factory infection computer products, more?

Answer»

A little more from the CIA computor security retiree.

"
Hi _______,
I just returned from Office Depot looking at their all-in-one printers. The Brother 5895CW you were interested in from Costco illustrated in
their latest flyer is "Made in China". The problem with that is the special agreement that the Intel services in China have with local computer/printer
manufacturers. They get Government money/assistance/sponsorship for allowing their Intel service to insert packages into outgoing ELECTRONICS.
(per Wiki-leaks DOS cable traffic). The below news release confirms that relationship. It would be nice if US company's would accept accountability
for this problem, or hold China accountable. That hasn't happened yet.

Alternately, Office Depot has All-in one printers from Epson that are made in Indonesia. There is a MUCH better relationship between the US and Indonesia
for producing products at this time. The equivalent all-in-one appeared to be the Epson Workforce 520 for approximately $129.00.

I helped my buddy in Tucson install his Epson all-in one printer and he just confirmed to me that he is happy with it's capability,
and he apparently has no adverse side effects from the installation. (unlike some HP all-in-ones that produce unpredictable on line behavior)

Cheers,

xxxxxxxxxxxxxxx



U.S.official says pre-infected computer tech entering country
By M. Alex Johnson, msnbc.com reporter

Confirming years of warnings from government and private security experts, a top Homeland Security official has acknowledged that computer hardware and software is already being imported to the United States preloaded with spy ware and security-sabotaging components.
The remarks by Greg Schaffer, the Department of Homeland Security's acting deputy undersecretary for national protection and programs, came Thursday during a tense EXCHANGE at a hearing of the House Oversight and Government Reform Committee. The PANEL is CONSIDERING an Obama administration proposal to tighten monitoring and controls on computer equipment imported for critical government and communications infrastructure.
Schafferdidn't say whether the equipment he was talking about included end-user consumer tech like retail laptops, DVDs and media players. If so, his comments,first reported Friday morning by Fast Company, would be the first time the United States has publicly confirmed that foreign consumer technology is arriving in the country already loaded with nasty bugs like key-logging software, botnetcomponents and even software designed to defeat security programs installed on the same machine.
"""Charlie361,
Without references, your post has zero value.

I just bought a hammer made in china.
Do you think it will attack me?
LOL please provide sources or references

Or simply boycott all china products LOL

I mean, come on man. Can this "contact" of yours not provide anything but some dilettante rambling?The phrase "made in china" will soon become an awesome cliche.

3245.

Solve : Imported computers infected at factory?

Answer»

I know not Linux and did do a hijackit and saw nothing to be worried about in the search.

I fear the bug MAY have come not from the factory, but MAYBE when I VISITED a mainland China site once.

Just do not now REMEMBER having the problem from the getgo when I bought the printer.

If only there was someway I could get rid of the xerox showing up in the add hardware option in "PRINTERS and Scanners" I might be free of the problem. It will not be moved..

3246.

Solve : Windows is not letting me access logs from Malwarebytes Anti-malware?

Answer»

After scanning with Malwarebytes Anti- malware a message will pop up saying : Windows cannot access the specified device , path , or FILE . You may not have the appropriate permissions to access item . : ......................................

Then if i try to view the log it will say the same thing .... That was the only problem i had . Until i tried to do something i found in your forum that seemed to be the same problem ..... But it said i had to disable my anti virus (AVG)2011 free edition to use Combo fix . Well i tried to uninstall it and use the remover and NOTHING seemed to change .. except it wouldn't let me enable AVG again or install anything from AVG .... it now has a error message ............... I have been at this for about 2 days and i don't know what else to do .

Thank you to all that respond .


[recovering disk space - old attachment deleted by admin]SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/18/2011 at 04:44 PM

Application Version : 4.55.1000

Core Rules Database Version : 7419
Trace Rules Database Version: 5231

Scan type : Complete Scan
Total Scan Time : 01:40:47

Memory items scanned : 594
Memory threats detected : 0
Registry items scanned : 7855
Registry threats detected : 0
File items scanned : 156874
File threats detected : 60

Adware.Tracking Cookie
.doubleclick.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.anrtx.tacoda.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ar.atwola.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
segment-pixel.invitemedia.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
dc.tremormedia.com [ C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
secure-us.imrworldwide.com [ C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2DJPKFNP ]
.at.atwola.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\andrewwspike\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:29:22 PM, on 7/18/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Users\ANDREW~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix STORAGE Manager\IAAnotif.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\vsnp2std.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\sniper.exe\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsearcher.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
O1 - Hosts: ::1 localhost
O2 - BHO: vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\ADOBE\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: BHO Project - {cbc5b60a-aa4d-45f6-84c2-d086f320299a} - C:\Program Files\Object\bho_project.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [SIDEBAR] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\ANDREW~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UVXD44UR\TRYWOW~1.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\ANDREW~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UVXD44UR\TRYWOW~1.SH! (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{97A8E8FE-42F1-4B7D-B22B-63782E7C2BE0}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Update Service (gupdate1ca93bd2bfc4dd1) (gupdate1ca93bd2bfc4dd1) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe

--
End of file - 8094 bytesok found the problem .... no virus .... just note pad wasn't set to always use this file type . .... now to reinstall AVG

3247.

Solve : nod32 update?

Answer»

how can i update my nod32 @ where can i get updated files? thank yoy all.If you have an Internet connection on your computer with Nod32, just open the Nod32 then CLICK on "Update now". See SAMPLE screen-shot.

[recovering disk space - OLD ATTACHMENT deleted by admin]

3248.

Solve : Hijacked cookies.sqlite in Thunderbird?

Answer»

I ran that scan, and it crashed again:

Problem signature:
Problem Event Name:BlueScreen
OS VERSION:6.1.7601.2.1.0.768.3
Locale ID:2057

Additional information about the problem:
BCCode:c5
BCP1:01220B00
BCP2:00000002
BCP3:00000000
BCP4:82D2571A
OS Version:6_1_7601
Service Pack:1_0
Product:768_1

Files that help describe the problem:
C:\Windows\Minidump\070111-16203-01.dmp
C:\Users\Stuart\AppData\Local\Temp\WER-35406-0.sysdata.xml

Read our PRIVACY statement online:
http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

If the online privacy statement is not available, please read our privacy statement offline:
C:\Windows\system32\en-US\erofflps.txt
Ok. Let's try something else.I'm not sure if it will work. It's an older program

Download MBRCheck to your desktop.

  • Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
  • It will show a black screen with some data on it.
  • A report called MBRcheckxxxx.txt will be on your desktop
  • Open this report and post its content in your next reply.
.Hi again, before we go any further, my thanks for your continuing help. Without further ado, the MBRcheck log:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version:Windows 7 Home Premium Edition
Windows Information:Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer:MICRO-STAR INTERNATIONAL CO.,LTD
BIOS Manufacturer:American Megatrends Inc.
System Manufacturer:MICRO-STAR INTERNATIONAL CO.,LTD
System Product Name:MS-7360
Logical Drives Mask:0x00003c3d

Kernel Drivers (total 160):
0x82C42000 \SystemRoot\system32\ntoskrnl.exe
0x82C0B000 \SystemRoot\system32\halmacpi.dll
0x80BAF000 \SystemRoot\system32\kdcom.dll
0x89404000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x89489000 \SystemRoot\system32\PSHED.dll
0x8949A000 \SystemRoot\system32\BOOTVID.dll
0x894A2000 \SystemRoot\system32\CLFS.SYS
0x894E4000 \SystemRoot\system32\CI.dll
0x8958F000 \SystemRoot\system32\drivers\Wdf01000.sys
0x89600000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8960E000 \SystemRoot\system32\drivers\ACPI.sys
0x89656000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8965F000 \SystemRoot\system32\drivers\msisadrv.sys
0x89667000 \SystemRoot\system32\drivers\pci.sys
0x89691000 \SystemRoot\system32\drivers\vdrvroot.sys
0x8969C000 \SystemRoot\System32\drivers\partmgr.sys
0x896AD000 \SystemRoot\system32\drivers\volmgr.sys
0x896BD000 \SystemRoot\System32\drivers\volmgrx.sys
0x89708000 \SystemRoot\system32\drivers\pciide.sys
0x8970F000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8971D000 \SystemRoot\System32\drivers\mountmgr.sys
0x89733000 \SystemRoot\system32\drivers\atapi.sys
0x8973C000 \SystemRoot\system32\drivers\ataport.SYS
0x8975F000 \SystemRoot\system32\drivers\amdxata.sys
0x89768000 \SystemRoot\system32\drivers\fltmgr.sys
0x8979C000 \SystemRoot\system32\drivers\fileinfo.sys
0x89833000 \SystemRoot\System32\Drivers\Ntfs.sys
0x89962000 \SystemRoot\System32\Drivers\msrpc.sys
0x8998D000 \SystemRoot\System32\Drivers\ksecdd.sys
0x899A0000 \SystemRoot\System32\Drivers\cng.sys
0x899FD000 \SystemRoot\System32\drivers\pcw.sys
0x89A0B000 \SystemRoot\system32\drivers\eufs.sys
0x89A14000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x89A1D000 \SystemRoot\system32\drivers\ndis.sys
0x89AD4000 \SystemRoot\system32\drivers\NETIO.SYS
0x89B12000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x89C1B000 \SystemRoot\System32\drivers\tcpip.sys
0x89D65000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x89D96000 \SystemRoot\system32\drivers\volsnap.sys
0x89DD5000 \SystemRoot\System32\Drivers\spldr.sys
0x89DDD000 \SystemRoot\System32\drivers\rdyboost.sys
0x89E0A000 \SystemRoot\System32\Drivers\mup.sys
0x89E1A000 \SystemRoot\System32\drivers\hwpolicy.sys
0x89E22000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x89E54000 \SystemRoot\system32\drivers\eubakup.sys
0x89E5F000 \SystemRoot\system32\DRIVERS\disk.sys
0x89E70000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x89EC7000 \SystemRoot\system32\drivers\cdrom.sys
0x89EE6000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x89F56000 \SystemRoot\System32\Drivers\Null.SYS
0x89F5D000 \SystemRoot\System32\Drivers\Beep.SYS
0x89F64000 \SystemRoot\System32\drivers\vga.sys
0x89F70000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x89F91000 \SystemRoot\System32\drivers\watchdog.sys
0x89F9E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x89FA6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x89FAE000 \SystemRoot\system32\drivers\rdprefmp.sys
0x89FB6000 \SystemRoot\System32\Drivers\Msfs.SYS
0x89FC1000 \SystemRoot\System32\Drivers\Npfs.SYS
0x89FCF000 \SystemRoot\system32\DRIVERS\tdx.sys
0x89FE6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x89FF2000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x89B37000 \SystemRoot\System32\DRIVERS\netbt.sys
0x89B69000 \SystemRoot\system32\drivers\afd.sys
0x89C00000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x89C05000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x89BC3000 \SystemRoot\system32\DRIVERS\pacer.sys
0x89C0C000 \SystemRoot\system32\DRIVERS\netbios.sys
0x89BE2000 \SystemRoot\system32\DRIVERS\serial.sys
0x89800000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x89813000 \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys
0x897AD000 \SystemRoot\system32\DRIVERS\VBoxDrv.sys
0x8981C000 \SystemRoot\system32\drivers\termdd.sys
0x897CA000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0x8C41E000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8C45F000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8C469000 \SystemRoot\system32\drivers\mssmbios.sys
0x8C473000 \??\C:\Windows\system32\drivers\eudskacs.sys
0x8C47B000 \SystemRoot\System32\drivers\discache.sys
0x8C487000 \SystemRoot\System32\Drivers\dfsc.sys
0x8C49F000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8C4AD000 \SystemRoot\System32\Drivers\aswSP.SYS
0x8C4F7000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8C518000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x9142C000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x91E27000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x91E29000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x91EE0000 \SystemRoot\System32\drivers\dxgmms1.sys
0x91F19000 \SystemRoot\system32\drivers\usbuhci.sys
0x91F24000 \SystemRoot\system32\drivers\USBPORT.SYS
0x91F6F000 \SystemRoot\system32\drivers\usbehci.sys
0x91F7E000 \SystemRoot\system32\drivers\HDAudBus.sys
0x91F9D000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x91FC2000 \SystemRoot\system32\DRIVERS\el90XND5.SYS
0x91FE8000 \SystemRoot\system32\DRIVERS\serenum.sys
0x91FF2000 \SystemRoot\system32\DRIVERS\fdc.sys
0x91400000 \SystemRoot\system32\drivers\i8042prt.sys
0x91418000 \SystemRoot\system32\drivers\kbdclass.sys
0x8C52A000 \SystemRoot\system32\drivers\mouclass.sys
0x8C537000 \SystemRoot\system32\drivers\CompositeBus.sys
0x8C544000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x8C556000 \SystemRoot\system32\DRIVERS\HssDrv.sys
0x8C566000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8C57E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8C589000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8C5AB000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8C5C3000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8C5DA000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x91425000 \SystemRoot\system32\DRIVERS\taphss.sys
0x8C5F1000 \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys
0x91FFD000 \SystemRoot\system32\drivers\swenum.sys
0x8C60B000 \SystemRoot\system32\drivers\ks.sys
0x8C63F000 \SystemRoot\system32\DRIVERS\EuDisk.sys
0x8C670000 \SystemRoot\system32\drivers\umbus.sys
0x8C67E000 \SystemRoot\system32\drivers\usbhub.sys
0x8C6C2000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x8C6CC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8C6DD000 \SystemRoot\system32\drivers\HdAudio.sys
0x8C72D000 \SystemRoot\system32\drivers\portcls.sys
0x8C75C000 \SystemRoot\system32\drivers\drmk.sys
0x8C775000 \SystemRoot\system32\drivers\usbccgp.sys
0x8C78C000 \SystemRoot\system32\drivers\USBD.SYS
0x8C78E000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8C7B2000 \SystemRoot\system32\drivers\usbaudio.sys
0x8C7C6000 \SystemRoot\system32\drivers\USBSTOR.SYS
0x8C7DD000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8C7EA000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8C7F5000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x8C400000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x92D00000 \SystemRoot\System32\win32k.sys
0x8C411000 \SystemRoot\System32\drivers\Dxapi.sys
0x89E95000 \SystemRoot\system32\DRIVERS\monitor.sys
0x92F60000 \SystemRoot\System32\TSDDD.dll
0x92F90000 \SystemRoot\System32\cdd.dll
0x89EA0000 \SystemRoot\system32\drivers\luafv.sys
0x9902E000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x99066000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x99069000 \SystemRoot\system32\drivers\WudfPf.sys
0x99083000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x99093000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x990A6000 \SystemRoot\system32\drivers\HTTP.sys
0x9912B000 \SystemRoot\system32\DRIVERS\bowser.sys
0x99144000 \SystemRoot\System32\drivers\mpsdrv.sys
0x99156000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x99179000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x991B4000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x991E7000 \SystemRoot\system32\drivers\peauth.sys
0x9927E000 \SystemRoot\System32\Drivers\secdrv.SYS
0x99288000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x992A9000 \SystemRoot\System32\drivers\tcpipreg.sys
0x992B6000 \SystemRoot\System32\DRIVERS\srv2.sys
0x99306000 \SystemRoot\System32\DRIVERS\srv.sys
0x99358000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x993E3000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x99000000 \SystemRoot\System32\Drivers\fastfat.SYS
0x99379000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77950000 \Windows\System32\ntdll.dll
0x47E60000 \Windows\System32\smss.exe
0x77B90000 \Windows\System32\apisetschema.dll
0x00D70000 \Windows\System32\autochk.exe

Processes (total 61):
0 System Idle Process
4 System
320 C:\Windows\System32\smss.exe
428 csrss.exe
484 C:\Windows\System32\wininit.exe
496 csrss.exe
536 C:\Windows\System32\services.exe
568 C:\Windows\System32\lsass.exe
576 C:\Windows\System32\lsm.exe
696 C:\Windows\System32\winlogon.exe
724 C:\Windows\System32\svchost.exe
808 C:\Windows\System32\nvvsvc.exe
848 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\svchost.exe
988 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\svchost.exe
1156 C:\Windows\System32\svchost.exe
1216 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1240 C:\Windows\System32\nvvsvc.exe
1312 C:\Windows\System32\svchost.exe
1396 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1796 C:\Windows\System32\dwm.exe
1820 C:\Windows\explorer.exe
1984 C:\Windows\System32\spoolsv.exe
2016 C:\Windows\System32\svchost.exe
360 C:\Windows\System32\taskhost.exe
1016 C:\Program Files\a-squared Free\a2service.exe
1460 C:\Program Files\EASEUS\Todo Backup 2.0\bin\Agent.exe
660 C:\Program Files\Expat Shield\bin\openvpnas.exe
1784 C:\Program Files\Expat Shield\HssWPR\hsssrv.exe
2124 C:\Program Files\Expat Shield\bin\hsswd.exe
2156 C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
2224 C:\Windows\System32\svchost.exe
2264 C:\Windows\System32\UAService7.exe
2664 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
3004 WUDFHost.exe
3448 C:\Program Files\AVAST Software\Avast\AvastUI.exe
3456 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3464 C:\Program Files\Windows Sidebar\sidebar.exe
3472 C:\Program Files\Skype\Phone\Skype.exe
3516 C:\Program Files\uTorrent\uTorrent.exe
3544 C:\Program Files\eMule\emule.exe
3748 C:\Windows\System32\SearchIndexer.exe
4048 C:\Program Files\Windows Media Player\wmpnetwk.exe
4084 C:\Windows\System32\svchost.exe
2788 C:\Windows\System32\svchost.exe
4484 C:\Program Files\Expat Shield\bin\openvpntray.exe
5240 C:\Windows\System32\svchost.exe
5864 C:\Windows\System32\svchost.exe
3668 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
4412 C:\Windows\System32\audiodg.exe
5404 C:\Program Files\MediaMonkey\MediaMonkey.exe
5972 C:\Program Files\Windows Media Player\wmplayer.exe
5768 C:\Windows\System32\wuauclt.exe
4440 C:\Program Files\Mozilla Firefox\firefox.exe
4536 C:\Windows\System32\SearchProtocolHost.exe
6116 C:\Windows\System32\SearchFilterHost.exe
4140 C:\Windows\explorer.exe
5376 C:\Users\Stuart\Downloads\MBRCheck.exe
2928 C:\Windows\System32\conhost.exe
3276 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000009`ca500000
\\.\E: --> \\.\PhysicalDrive0 at offset 0x0000000e`ac500000 (NTFS)

PhysicalDrive0 Model Number: ST3500418AS, Rev: CC35

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB7 9


Done!Those last scans were to check out the MBR which could have caused the problem with Kernal_Stack_Inpage_Error but it checked out ok. How's the computer RUNNING now?It's running, it does still freeze from time to time, but I can't spot a pattern as to why it's freezing - I could be using Skype, clicking on a Bookmark in Firefox, or MediaMonkey could be playing a song while I'm in the kitchen and the needle starting skipping, as it were. The only WAY out is Ctrl+Alt+Del and a bit of patience until it comes back.

I haven't dared to use Thunderbird all week, but I finally opened it this morning, downloaded my mail etc, and on closing it got a Calendar error (could not write to the calendar) which I've not seen before, so there may still be something lurking.

The alternative I guess is a hardware error, the PC's 3 years old, but the only indication I have of a failure is the on-board ethernet socket stopped working about 3 months ago, so I stuck a PCI card in and it's been fine since. Quote
I could be using Skype, clicking on a Bookmark in Firefox, or MediaMonkey could be playing a song while I'm in the kitchen and the needle starting skipping, as it were.
Did it just start doing that?

I don't see any infections on your computer so I have to surmise that it's a software or hardware problemNo, it was doing that before I started this thread, that was the freezing I was talking about in my first post.

Thank you SO much for your time and effort Dave, I'm gonna invest in a new mobo and perhaps reinstall 7, see if that irons out the creases. You're welcome. Sorry I couldn't be more helpful. I will lock this thread. If you need it re-opened, please send me a pm.Latest update, new motherboard and reinstalled W7 fresh and it's working fine. Obviously a hardware problem and not malware. Cheers!
3249.

Solve : My Windows 7 Computer is infected with Win7 Security 2011?

Answer»

Here's the log

[recovering disk space - old attachment deleted by admin]I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET SMART Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin SCANNING your computer. Please be patient as this can take some time.
•When the scan COMPLETES, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
ESET Log

[recovering disk space - old attachment deleted by admin]Ok. That looks good. If there are no other issues, we can do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
**************************************************
Clean out your TEMPORARY internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
********************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Well Dave, everything seems to be good on my user. The "New Itouch" user is still corrupt. I can't open iTunes. Any ideas?
Quote from: radioflyer91355 on July 10, 2011, 06:07:01 PM
Well Dave, everything seems to be good on my user. The "New Itouch" user is still corrupt. I can't open iTunes. Any ideas?
You should start a new thread for this one and we can take a look. I will lock this thread. If you need it re-opened, please send me a pm.
3250.

Solve : Uninvited guests...Exploit:Win32/pdfjsc.PC and VIRtool:JS/Obfuscator.BN?

Answer»

Quote from: SuperDave on June 28, 2011, 04:42:42 PM

Are you trying to repair two computers at once?
If everything is ok with the computer we're working on, I'd like to do some cleanup. After that we'll have to take a look at the second computer.
I do have two towers, but this one, the Dell Dimension B110 is the tower I am PRESENTLY commnicating from. It is the 'Ole Faithful
in my household. The AMD tower is the tower I RECENTLY purchased, that you have assistied me with.
Let us proceed then with the task at hand. Just tell me what it is that you require. I am using a Belkin KVM switch, which both units use but are kept seperated and are not presently sharing files or functioning togeter as a network group. Please advise as to how you wish to proceed. It isn't over until it's over.I've finished running scans on that computer. If there are no other issues, we can do some cleanup. Please let me know and we can do the cleanup.Quote from: SuperDave on June 28, 2011, 04:42:42 PM

If everything is ok with the computer we're working on, I'd like to do some cleanup. After that we'll have to take a look at the second computer.

I would be glad to have your continued support. Do you still feel that the other tower should be looked at as well? I would feel better knowing that both systems are absolutely infestation free; prior to networking the two together and sharing files. I will check back here tomorrow assuming that you would like to proceed. Thank you for your TIME and patience on my behalf.Quote
Do you still feel that the other tower should be looked at as well?
If you're having problems with it, please start a new thread.
Ok. Let's do some cleanup on this one.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, PRESS Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*******************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any UPDATES are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!I initiated the process that you provided for the final cleanup. The temporary internet files and temp files that were "cleaned out" were limited to only what the DISKCLEANUP in SYSTEM TOOLS offers in the menu of choice. I do not believe this fulfills the scope of your intentions for the final cleanup regarding these files/folders. I have 13 different temp folders; containing hundreds of files spread between 3 different directories that include the WINDOWS OS, and Program Files. In addition, it turns out that that they are case senitive; 6 are uppercase and 5 are lowercase spellings of the same. Temporary internet files are relatively easy to assess, yet I have 3 of those as well in my "list" while not completely confident in which files for sure are seperated then get the AX. Long story short.....I am proceeding on the premise that i am not going to wipeout my system, because i didn't put all my eggs in one basket. I beleive there are file/folders that are directly relatedto some of the operations performed laft week. At any rate...I will send the info tomorrow.

Thank you,
Brent I apologize for being away from this thread for so long. I have been swamped with summer terms workload and really have not had the time to devote to the final details.
OK. Where I am now is having run the uninstall on COMBOFIX, and did a clean-up of Temporary Internet Files (limited to what is flagged by Disk Cleanup in System Tools). I have not ran the program from old timer yet. I do HAVE A QUESTION... Should there be any folders or files left anywhere in my system that pertain to COMBOFIX? If the answer is no, then something isn't right, I sill have a directory folder in my directory tree titled COMBOFIX. This is after running the unistall as directed. I have not even ran the "problem child" after discovering this and my last post. I know I marked it as solved because I feel, Dave, that ultimately you helped me solve the problem at hand. But I could use just a little more direction on the details. Can you assist? Or should I begin a new thread? Thanks in advance. Quote
I have not ran the program from old timer yet. I do HAVE A QUESTION... Should there be any folders or files left anywhere in my system that pertain to COMBOFIX? If the answer is no, then something isn't right, I sill have a directory folder in my directory tree titled COMBOFIX. This is after running the unistall as directed.
After you run OTL cleanup it should be all gone.