Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

4251.

Solve : Msn Photo.zip virus......PLs help?

Answer»

HI evil, the cleanup!.exe free up an addition of 32mb.

Here is the lastest hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:07:08 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed LAUNCH.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! ANTIVIRUS - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 6459 bytesThe log is clean.

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

This is a good TIME to clear your infected system restore points and establish a new clean restore point:

  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and click Next.
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up...
This will remove all restore points except the new one you just created.

Here are some great tools to help you keep from getting infected again.

Spybot Search & Destroy - A safe and effective spyware scanner.
* Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
* AVG Anti-Spyware User Manual

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware

Comodo BOClean - Stops trojans and many more malicious attacks.

Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
* Click here for a list of free firewalls.
* Why WOULD I consider a third party firewall?
* Understanding and Using Firewalls

UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
* Help with Windows updates

Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first PLACE?

Let us know if anything else comes up.You are great!!! and you guys rock!!!

Thank you evil No problem, glad it worked.
4252.

Solve : New Virus?

Answer»

I've heard of a new virus out called ronamonadona virus. Anyone heard of it or how prevalent it is?I searched for it, and found this:

http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus

Quote

It is clearly extortion-ware, offering on the user's screen: "Welcome to MonaRonaDona; hi, my name is Mona RonaDona. i am a virus& i am here to Wreck Your PC."

Where did you hear about it?Kim Komando ShowCould have named it Roseanne Roseannadana virus.Yes I have already been INVOLVED with this one.

Removal instructions.

First:

Have HIJACKTHIS fix these entries (if found)

  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MonaRonaDona
  • O4 - HKLM\..\Run: [.NET.] \FUD.exe
  • O4 - Global Startup: SRVSPOOL.exe
  • O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix2008\RegistryCleaner2008.exe
Second:

Download OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Double-CLICK OTMoveIt2.exe to run it. (Note: If you are running on Vista, RIGHT-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code: [Select]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Window Title
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Window Title
    HKEY_CURRENT_USER\Software\Microsoft\Outlook Express\\Window Title
    C:\Program Files\RegistryCleanFix2008
    C:\Program Files\UniGray Antivirus
    C:\Documents and Settings\All Users\SRVSPOOL.EXE /S /D
    C:\Users\SRVSPOOL.EXE /S /D
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window.
    IMPORTANT -- Paste only into the bottom input panel (under the Yellow bar), The top panel will not help you.
    Right-click and choose Paste.
  • Click the red Moveit! button.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Now, Double click to open OTMoveIt2 again.
Click the green CleanupUp! button at the top.
Note: it will need to access the internet to download a small script file. Please allow your Firewall to do so.

When it finishes it will have deleted all of its qauarantines, as well as the OTMOVEIT2 program and all created folders.

Reboot the computer.

If any problems still exist due to the infection.

Another tool to fix the Task Manager and other policies that this virus effects.

Download to your Desktop this self-extracting ZIP archive FixPolicies.exe
.
  • Double-click FixPolicies.exe
  • Click the Install button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies
  • Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
  • A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any ADMINISTRATIVE warnings.
Quote from: spock on March 05, 2008, 08:38:53 PM
Could have named it Roseanne Roseannadana virus.

This one only says " Nevermind ".......
4253.

Solve : WINDOWS folder in Reclying Bin??

Answer»

Hello all, new here.

I would say that I know QUITE a bit about computers, considering I am studying them but I am having a computer problem that I've only seen once before that for some reason I can't shake it.

I now for some reason have my windows folder in the recycling BIN, with hidden files shown there is nothing inside the recycling bin, the icon shows as stuff in it.

ESET Nod 32 can't find any problems, nor spybot. Any ideas?

Edit: Please move this to the virus section. My fault.Welcome to the CH forum Trent.
Start here and post the info required.
If you SUSPECT an infection you can then go through the STEPS here.

4254.

Solve : hijackthis?

Answer»

ok can someone please analyze this and tell me what i should be doing? I already submitted another forum about my computer not letting me dl anything and having corrupted files. Someone had refered me to getting hijackthis. I have no idea how to read this and what i should be doing with this program so here is what it gave me when i scaned my computer.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:30:26 AM, on 2/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\PCI F5D7000\Wireless Utility\Belkinwcui.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=searchfavweb&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/yessentials_cq/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
O4 - HKLM\..\RUN: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Belkin Wireless Utility.lnk = C:\Program Files\Belkin\PCI F5D7000\Wireless Utility\Belkinwcui.exe
O8 - Extra context MENU item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165092187044
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: B's Recorder GOLD LIBRARY General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 6920 bytesthanks!When did the problem start?
Did you download anything new around the time it started happening?

I don't see anything in the log as far as viruses but there are some questionable entries. Please go to this post and work through as many of the steps as possible then post the logs back here.This problem started about a month ago. I downloaded aim the newest version and it started to act funny by always kicking me off and then restarting. It would do that every 5 minutes and it got really annoying so I uninstalled it by going to add/remove programs. After that I tried to dl spybot, but the download would not go past 4%. Since then any dl I try to get wont dl past 4%.

I currently have CA antivirus and spyware. It wont let me update the antivirus either it says there was an error. Also I am getting messages saying that WDengine.dll failed and some display driver failed i think its called iamnlt or something like that.

We have two computers in the house and this one Im having trouble with is running off of belkin wireless card. I got the chance to look at the main computer yesterday and i went into the users accounts. There was a user that I never set up but am not sure about. The user name was Aspnet. I didnt know if I should be concerned about that so I left it.

I went through the steps you gave me but I couldnt download superantispyware or AVG. I ran my antivirus and spyware that I already have and quaratined everything. I did that yesterday before I posted the log. I went to ADD/Remove programs but I didnt find anything weird. Sorry if this doesnt help much. WDengine.dll is part of WildTagnet and needs to be uninstalled in add/remove programs. After uninstalling it then go back to the removal steps and try again. Try to get CCleaner to run. You should at least be able to get the online scan to run and post that log.I couldnt get the online scanner to work. Here is the log from ccleaner i had to put in three parts it was to big.


[file cleanup - saving space - attachment deleted by admin]2nd one

[file cleanup - saving space - attachment deleted by admin]last one

[file cleanup - saving space - attachment deleted by admin]Try booting into safe mode and running the installer for Superantispyware. If it installs then also run the scan in safe mode.I tried to in safe mode it wont let me either sorry!Try this.

Download Deckard's System Scanner (DSS) to your Desktop.
Note: You must be logged onto an account with administrator privileges.

  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
    • Add the contents of main.txt in your post.
    • Also add extra.txt to your post.
    • The text from these files may exceed the maximum post length for this forum, and may need to be sent over 2 or more posts. Please ensure all text is posted.
    [/COLOR]
    What DSS will do:
    • Create a new System Restore point in Windows XP and Vista.
    • Clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
    • Check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
    ok that WORKED. Here are the results.

    [file cleanup - saving space - attachment deleted by admin]2nd part

    [file cleanup - saving space - attachment deleted by admin]Go to www.java.com and download and uninstall the new version of Java. If you have any problems installing the new Java then let me know.

    Next go to add/remove programs and uninstall the following.

    Java 2 Runtime Environment Standard Edition v1.3.1
    LiveReg
    LiveUpdate 1.6
    Viewpoint Media Player
    WildTangent Updater
    WildTangent Web Driver



    Now go back here and try to run the Superantispyware, Dr Web and Online Scanner.ok i did what you told me and it let me dl superantispyware. However it kept stopping so i had to close it and restart the dl to get it dl all the way. OK, once we get the logs we will know what else may need to be done.
    4255.

    Solve : firewall settings change after every boot. help?

    Answer» for some REASON every time after i boot my vista home PREMIUM sp1 laptop after a couple of minutes of windows started, firewall and network SHARING settings change. every time i have to change it back. dunno why this is happening.
    appreciate any info.
    dunno if its related but have tis event viewer logs tat looked strange to me (among like 400 different ones in one minute -!? and even if its not related is it something ok? wat is it saying?)
    by the way, some time ago my computer was infected by backdoor:win32/refpron.A. supposedly it was removed.


    A Windows Filtering Platform filter has been changed.

    general tab
    Subject:
    Security ID: LOCAL SERVICE
    Account Name: NT AUTHORITY\LOCAL SERVICE

    PROCESS Information:
    Process ID: 1644

    PROVIDER Information:
    ID: {decc16ca-3f33-4346-be1e-8fb4ae0f3d62}
    Name: Windows Firewall

    Change Information:
    Change Type: Delete

    Filter Information:
    ID: {0aa8b2a7-d8e6-4574-8b79-5389071e8fa2}
    Name: Port Scanning Prevention Filter
    Type: Boot-time
    Run-Time ID: 68324

    Layer Information:
    ID: {7fb03b60-7b8d-4dfa-badd-980176fc4e12}
    Name: Outbound ICMP Error v6 Layer
    Run-Time ID: 34

    Callout Information:
    ID: {00000000-0000-0000-0000-000000000000}
    Name: -

    Additional Information:
    Weight: 18446744073709551615
    Conditions:
    Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c}
    Match value: No flags set
    Condition value: 0x00000001

    Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b}
    Match value: Equal to
    Condition value: 0x0001

    Filter Action: Block
    ---------------------------------------------------------------------
    details tab
    + System

    - Provider

    [ Name] Microsoft-Windows-Security-Auditing
    [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}

    EventID 5447

    Version 0

    Level 0

    Task 13573

    Opcode 0

    Keywords 0x8020000000000000

    - TimeCreated

    [ SystemTime] 2009-05-24T19:44:53.406Z

    EventRecordID 483055

    Correlation

    - Execution

    [ ProcessID] 636
    [ ThreadID] 1004

    Channel Security

    Security


    - EventData

    ProcessId 1644
    UserSid S-1-5-19
    UserName NT AUTHORITY\LOCAL SERVICE
    ProviderKey {DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}
    ProviderName Windows Firewall
    ChangeType %%16385
    FilterKey {0AA8B2A7-D8E6-4574-8B79-5389071E8FA2}
    FilterName Port Scanning Prevention Filter
    FilterType %%16386
    FilterId 68324
    LayerKey {7FB03B60-7B8D-4DFA-BADD-980176FC4E12}
    LayerName Outbound ICMP Error v6 Layer
    LayerId 34
    Weight 18446744073709551615
    Conditions Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001
    Action %%16389
    CalloutKey {00000000-0000-0000-0000-000000000000}
    CalloutName -

    --------------------------------------------------------------------
    --------------------------------------------------------------------log2
    general tab
    A Windows Filtering Platform filter has been changed.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: NT AUTHORITY\LOCAL SERVICE

    Process Information:
    Process ID: 1644

    Provider Information:
    ID: {decc16ca-3f33-4346-be1e-8fb4ae0f3d62}
    Name: Windows Firewall

    Change Information:
    Change Type: Delete

    Filter Information:
    ID: {0aa8b2a7-d8e6-4574-8b79-5389071e8fa2}
    Name: Port Scanning Prevention Filter
    Type: Boot-time
    Run-Time ID: 68324

    Layer Information:
    ID: {7fb03b60-7b8d-4dfa-badd-980176fc4e12}
    Name: Outbound ICMP Error v6 Layer
    Run-Time ID: 34

    Callout Information:
    ID: {00000000-0000-0000-0000-000000000000}
    Name: -

    Additional Information:
    Weight: 18446744073709551615
    Conditions:
    Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c}
    Match value: No flags set
    Condition value: 0x00000001

    Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b}
    Match value: Equal to
    Condition value: 0x0001

    Filter Action: Block
    ------------------------------------------------------------------------------
    details tab
    + System

    - Provider

    [ Name] Microsoft-Windows-Security-Auditing
    [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}

    EventID 5447

    Version 0

    Level 0

    Task 13573

    Opcode 0

    Keywords 0x8020000000000000

    - TimeCreated

    [ SystemTime] 2009-05-24T19:44:53.406Z

    EventRecordID 483055

    Correlation

    - Execution

    [ ProcessID] 636
    [ ThreadID] 1004

    Channel Security

    Security


    - EventData

    ProcessId 1644
    UserSid S-1-5-19
    UserName NT AUTHORITY\LOCAL SERVICE
    ProviderKey {DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}
    ProviderName Windows Firewall
    ChangeType %%16385
    FilterKey {0AA8B2A7-D8E6-4574-8B79-5389071E8FA2}
    FilterName Port Scanning Prevention Filter
    FilterType %%16386
    FilterId 68324
    LayerKey {7FB03B60-7B8D-4DFA-BADD-980176FC4E12}
    LayerName Outbound ICMP Error v6 Layer
    LayerId 34
    Weight 18446744073709551615
    Conditions Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001
    Action %%16389
    CalloutKey {00000000-0000-0000-0000-000000000000}
    CalloutName -
    4256.

    Solve : Need help removing invisible virus files?

    Answer»

    Were getting there....

    Download & run this tool SafeBootKeyRepair-CF

    It will only take a short moment for it to finish running.
    A log will be produced at C:\SafeBoot_Repair.txt. PLEASE post that in your next reply.

    ----------

    Go to Start > Run and type NOTEPAD.exe then click OK

    Copy and paste the below into Notepad and save as fixme.REG to Your Desktop

    Code: [Select]REGEDIT4

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

      Locate fixme.reg on your Desktop and double-click it. Answer
    Yes when prompted to merge with the Registry.

    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

    Delete the fixme.reg from the Desktop.

    ----------

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Run CCleaner and let me know how everything is now.Here is the safeboot repair log:

    Code: [Select]Reg export of SafeBoot key after repair:
    ========================

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]
    "AlternateShell"="cmd.exe"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\procexp90.Sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PSEXESVC]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys]
    @="FSFilter System Recovery"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vds]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WdfLoadGroup]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WRConsumerService]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
    @="Universal Serial Bus controllers"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
    @="CD-ROM Drive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
    @="DiskDrive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
    @="Standard floppy disk controller"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
    @="Hdc"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
    @="Keyboard"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
    @="Mouse"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
    @="PCMCIA Adapters"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
    @="SCSIAdapter"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
    @="System"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
    @="Floppy disk drive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
    @="Volume"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
    @="HUMAN Interface Devices"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\procexp90.Sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PSEXESVC]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sharedaccess]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys]
    @="FSFilter System Recovery"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\UploadMgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WdfLoadGroup]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WRConsumerService]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC]
    @="Service"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
    @="Universal Serial Bus controllers"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
    @="CD-ROM Drive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
    @="DiskDrive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
    @="Standard floppy disk controller"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
    @="Hdc"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
    @="Keyboard"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
    @="Mouse"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
    @="Net"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
    @="NetClient"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
    @="NetService"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
    @="NetTrans"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
    @="PCMCIA Adapters"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
    @="SCSIAdapter"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
    @="System"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
    @="Floppy disk drive"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
    @="Volume"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
    @="Human Interface Devices"

    ========================

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\procexp90.Sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PSEXESVC
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WRConsumerService


    success message: fixme.reg was successfully entered into the registry.
    I ran CCleaner and the computer is running great.

    Sounds good.

    Have a look through this.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • UPDATE anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok.
    Thank you very much for your help.
    4257.

    Solve : Possible Virus Infection on Laptop?

    Answer»
    Thanks SuperDave SpyBot found a number of items that SuperAntiSpyware didn't. So I will use both too.You're welcome. I will lock this thread. If you need it re-opened, PLEASE send me a pm.Let's run a few more scans to see what turns up.

    Please download aswMBR.exe ( 511KB ) to your desktop.

    Double click the aswMBR.exe to run it



    Click the "Scan" button to start scan

    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



    On completion of the scan click save log, save it to your desktop and post in your next reply

    aswMBR Scan results

    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-12-07 15:56:50
    -----------------------------
    15:56:50.413 OS Version: Windows x64 6.1.7601 Service Pack 1
    15:56:50.413 Number of processors: 2 586 0x170A
    15:56:50.413 ComputerName: RICHARDNEW-PC UserName: RichardNew
    15:56:51.817 Initialize success
    15:56:55.904 AVAST engine defs: 11120701
    15:57:02.893 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    15:57:02.893 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3
    15:57:02.940 Disk 0 MBR read successfully
    15:57:02.940 Disk 0 MBR scan
    15:57:02.940 Disk 0 unknown MBR code
    15:57:02.956 Service scanning
    15:57:04.266 Modules scanning
    15:57:04.266 Disk 0 trace - called modules:
    15:57:04.328 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
    15:57:04.328 1 NT!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80057e0790]
    15:57:04.344 3 CLASSPNP.SYS[fffff880010c743f] -> nt!IofCallDriver -> [0xfffffa80057e0040]
    15:57:04.344 5 hpdskflt.sys[fffff88002565289] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80047c7050]
    15:57:05.561 AVAST engine scan C:\Windows
    15:57:09.851 AVAST engine scan C:\Windows\system32
    15:59:17.989 AVAST engine scan C:\Windows\system32\drivers
    15:59:31.203 AVAST engine scan C:\Users\RichardNew
    16:03:25.000 AVAST engine scan C:\ProgramData
    17:24:51.334 Scan finished successfully
    18:09:19.875 Disk 0 MBR has been saved successfully to "C:\Users\RichardNew\Desktop\MBR.dat"
    18:09:19.891 The log file has been saved successfully to "C:\Users\RichardNew\Desktop\aswMBR.txt"
    • Download TDSSKiller and save it to your Desktop.
    • Extract its contents to your desktop.
    • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • Click the Report button and copy/paste the contents of it into your next reply
    Note:It will also create a log in the C:\ directory..TDSS Scan Results


    19:26:55.0086 4576TDSS rootkit removing tool 2.6.22.0 Dec 7 2011 13:21:06
    19:26:55.0258 4576============================================================
    19:26:55.0258 4576Current date / time: 2011/12/07 19:26:55.0258
    19:26:55.0258 4576SystemInfo:
    19:26:55.0258 4576
    19:26:55.0258 4576OS Version: 6.1.7601 ServicePack: 1.0
    19:26:55.0258 4576Product type: Workstation
    19:26:55.0258 4576ComputerName: RICHARDNEW-PC
    19:26:55.0258 4576UserName: RichardNew
    19:26:55.0258 4576Windows directory: C:\Windows
    19:26:55.0258 4576System windows directory: C:\Windows
    19:26:55.0258 4576Running under WOW64
    19:26:55.0258 4576Processor architecture: Intel x64
    19:26:55.0258 4576Number of processors: 2
    19:26:55.0258 4576Page size: 0x1000
    19:26:55.0258 4576Boot type: Normal boot
    19:26:55.0258 4576============================================================
    19:26:55.0882 4576Initialize success
    19:27:19.0812 5728============================================================
    19:27:19.0812 5728Scan started
    19:27:19.0812 5728Mode: Manual;
    19:27:19.0812 5728============================================================
    19:27:21.0107 57281394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
    19:27:21.0107 57281394ohci - ok
    19:27:21.0201 5728Accelerometer (1cffe9c06e66a57dae1452e449a58240) C:\Windows\system32\DRIVERS\Accelerometer.sys
    19:27:21.0201 5728Accelerometer - ok
    19:27:21.0294 5728ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
    19:27:21.0294 5728ACPI - ok
    19:27:21.0388 5728AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
    19:27:21.0388 5728AcpiPmi - ok
    19:27:21.0622 5728adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    19:27:21.0622 5728adp94xx - ok
    19:27:21.0715 5728adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    19:27:21.0715 5728adpahci - ok
    19:27:21.0793 5728adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    19:27:21.0793 5728adpu320 - ok
    19:27:21.0934 5728AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
    19:27:21.0934 5728AFD - ok
    19:27:22.0074 5728AgereSoftModem (af4748ef93416159459769a24a0053af) C:\Windows\system32\DRIVERS\agrsm64.sys
    19:27:22.0090 5728AgereSoftModem - ok
    19:27:22.0168 5728agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
    19:27:22.0168 5728agp440 - ok
    19:27:22.0293 5728aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
    19:27:22.0293 5728aliide - ok
    19:27:22.0386 5728amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
    19:27:22.0386 5728amdide - ok
    19:27:22.0480 5728AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    19:27:22.0480 5728AmdK8 - ok
    19:27:22.0558 5728AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    19:27:22.0558 5728AmdPPM - ok
    19:27:22.0636 5728amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
    19:27:22.0651 5728amdsata - ok
    19:27:22.0683 5728amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    19:27:22.0683 5728amdsbs - ok
    19:27:22.0729 5728amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
    19:27:22.0729 5728amdxata - ok
    19:27:22.0823 5728AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
    19:27:22.0823 5728AppID - ok
    19:27:22.0963 5728arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    19:27:22.0979 5728arc - ok
    19:27:23.0057 5728arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    19:27:23.0057 5728arcsas - ok
    19:27:23.0197 5728AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    19:27:23.0197 5728AsyncMac - ok
    19:27:23.0244 5728atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
    19:27:23.0244 5728atapi - ok
    19:27:23.0463 5728atikmdag (3efd964d52221360af0673cd61c2f4f5) C:\Windows\system32\drivers\atikmdag.sys
    19:27:23.0572 5728atikmdag - ok
    19:27:23.0697 5728AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
    19:27:23.0697 5728AVGIDSEH - ok
    19:27:23.0806 5728Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys
    19:27:23.0806 5728Avgtdia - ok
    19:27:23.0962 5728b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    19:27:23.0962 5728b06bdrv - ok
    19:27:24.0071 5728b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    19:27:24.0087 5728b57nd60a - ok
    19:27:24.0258 5728BCM43XX (0e14a0071fe26a570bcaff5401014717) C:\Windows\system32\DRIVERS\bcmwl664.sys
    19:27:24.0321 5728BCM43XX - ok
    19:27:24.0414 5728Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    19:27:24.0414 5728Beep - ok
    19:27:24.0523 5728blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    19:27:24.0523 5728blbdrive - ok
    19:27:24.0617 5728bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
    19:27:24.0633 5728bowser - ok
    19:27:24.0664 5728BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    19:27:24.0664 5728BrFiltLo - ok
    19:27:24.0726 5728BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    19:27:24.0726 5728BrFiltUp - ok
    19:27:24.0820 5728Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    19:27:24.0820 5728Brserid - ok
    19:27:24.0898 5728BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    19:27:24.0898 5728BrSerWdm - ok
    19:27:24.0976 5728BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    19:27:24.0976 5728BrUsbMdm - ok
    19:27:24.0991 5728BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    19:27:24.0991 5728BrUsbSer - ok
    19:27:25.0085 5728BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    19:27:25.0085 5728BTHMODEM - ok
    19:27:25.0210 5728cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    19:27:25.0210 5728cdfs - ok
    19:27:25.0303 5728cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
    19:27:25.0303 5728cdrom - ok
    19:27:25.0397 5728circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    19:27:25.0397 5728circlass - ok
    19:27:25.0444 5728CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    19:27:25.0444 5728CLFS - ok
    19:27:25.0569 5728CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    19:27:25.0569 5728CmBatt - ok
    19:27:25.0631 5728cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
    19:27:25.0631 5728cmdide - ok
    19:27:25.0662 5728CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
    19:27:25.0662 5728CNG - ok
    19:27:25.0818 5728Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    19:27:25.0818 5728Compbatt - ok
    19:27:25.0912 5728CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
    19:27:25.0927 5728CompositeBus - ok
    19:27:26.0021 5728crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    19:27:26.0021 5728crcdisk - ok
    19:27:26.0161 5728DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
    19:27:26.0161 5728DfsC - ok
    19:27:26.0239 5728discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    19:27:26.0239 5728discache - ok
    19:27:26.0302 5728Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    19:27:26.0302 5728Disk - ok
    19:27:26.0411 5728drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    19:27:26.0411 5728drmkaud - ok
    19:27:26.0520 5728DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
    19:27:26.0536 5728DXGKrnl - ok
    19:27:26.0692 5728ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    19:27:26.0754 5728ebdrv - ok
    19:27:26.0879 5728elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    19:27:26.0879 5728elxstor - ok
    19:27:26.0973 5728enecir (524c79054636d2e5751169005006460b) C:\Windows\system32\DRIVERS\enecir.sys
    19:27:26.0973 5728enecir - ok
    19:27:27.0004 5728ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
    19:27:27.0004 5728ErrDev - ok
    19:27:27.0113 5728exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    19:27:27.0113 5728exfat - ok
    19:27:27.0191 5728fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    19:27:27.0207 5728fastfat - ok
    19:27:27.0316 5728fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    19:27:27.0316 5728fdc - ok
    19:27:27.0394 5728FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    19:27:27.0394 5728FileInfo - ok
    19:27:27.0409 5728Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    19:27:27.0409 5728Filetrace - ok
    19:27:27.0519 5728flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    19:27:27.0519 5728flpydisk - ok
    19:27:27.0612 5728FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
    19:27:27.0612 5728FltMgr - ok
    19:27:27.0721 5728FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    19:27:27.0737 5728FsDepends - ok
    19:27:27.0768 5728Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    19:27:27.0784 5728Fs_Rec - ok
    19:27:27.0862 5728fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
    19:27:27.0862 5728fvevol - ok
    19:27:27.0955 5728gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    19:27:27.0955 5728gagp30kx - ok
    19:27:28.0049 5728GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    19:27:28.0049 5728GEARAspiWDM - ok
    19:27:28.0174 5728hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    19:27:28.0174 5728hcw85cir - ok
    19:27:28.0283 5728HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
    19:27:28.0283 5728HdAudAddService - ok
    19:27:28.0377 5728HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
    19:27:28.0392 5728HDAudBus - ok
    19:27:28.0408 5728HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    19:27:28.0408 5728HidBatt - ok
    19:27:28.0486 5728HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    19:27:28.0501 5728HidBth - ok
    19:27:28.0595 5728HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    19:27:28.0595 5728HidIr - ok
    19:27:28.0673 5728HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
    19:27:28.0673 5728HidUsb - ok
    19:27:28.0782 5728hpdskflt (05712fddbd45a5864eb326faabc6a4e3) C:\Windows\system32\DRIVERS\hpdskflt.sys
    19:27:28.0782 5728hpdskflt - ok
    19:27:28.0876 5728HpqKbFiltr (9af482d058be59cc28bce52e7c4b747c) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
    19:27:28.0876 5728HpqKbFiltr - ok
    19:27:29.0001 5728HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
    19:27:29.0001 5728HpSAMD - ok
    19:27:29.0125 5728HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
    19:27:29.0141 5728HTTP - ok
    19:27:29.0203 5728hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
    19:27:29.0219 5728hwpolicy - ok
    19:27:29.0328 5728i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
    19:27:29.0328 5728i8042prt - ok
    19:27:29.0437 5728iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
    19:27:29.0437 5728iaStor - ok
    19:27:29.0547 5728iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
    19:27:29.0547 5728iaStorV - ok
    19:27:29.0827 5728igfx (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys
    19:27:29.0999 5728igfx - ok
    19:27:30.0077 5728iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    19:27:30.0077 5728iirsp - ok
    19:27:30.0186 5728IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys
    19:27:30.0186 5728IntcHdmiAddService - ok
    19:27:30.0249 5728intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
    19:27:30.0249 5728intelide - ok
    19:27:30.0311 5728intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    19:27:30.0327 5728intelppm - ok
    19:27:30.0358 5728IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    19:27:30.0358 5728IpFilterDriver - ok
    19:27:30.0451 5728IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
    19:27:30.0451 5728IPMIDRV - ok
    19:27:30.0498 5728IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    19:27:30.0498 5728IPNAT - ok
    19:27:30.0592 5728IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    19:27:30.0592 5728IRENUM - ok
    19:27:30.0654 5728isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
    19:27:30.0654 5728isapnp - ok
    19:27:30.0701 5728iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
    19:27:30.0701 5728iScsiPrt - ok
    19:27:30.0795 5728kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
    19:27:30.0795 5728kbdclass - ok
    19:27:30.0873 5728kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
    19:27:30.0873 5728kbdhid - ok
    19:27:30.0966 5728KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
    19:27:30.0966 5728KSecDD - ok
    19:27:31.0013 5728KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
    19:27:31.0013 5728KSecPkg - ok
    19:27:31.0091 5728ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    19:27:31.0091 5728ksthunk - ok
    19:27:31.0231 5728lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    19:27:31.0231 5728lltdio - ok
    19:27:31.0325 5728LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    19:27:31.0325 5728LSI_FC - ok
    19:27:31.0403 5728LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    19:27:31.0419 5728LSI_SAS - ok
    19:27:31.0497 5728LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    19:27:31.0497 5728LSI_SAS2 - ok
    19:27:31.0590 5728LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    19:27:31.0590 5728LSI_SCSI - ok
    19:27:31.0699 5728luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    19:27:31.0699 5728luafv - ok
    19:27:31.0793 5728megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    19:27:31.0793 5728megasas - ok
    19:27:31.0824 5728MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    19:27:31.0824 5728MegaSR - ok
    19:27:31.0918 5728Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    19:27:31.0933 5728Modem - ok
    19:27:31.0996 5728monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    19:27:31.0996 5728monitor - ok
    19:27:32.0089 5728mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
    19:27:32.0089 5728mouclass - ok
    19:27:32.0199 5728mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    19:27:32.0199 5728mouhid - ok
    19:27:32.0261 5728mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
    19:27:32.0261 5728mountmgr - ok
    19:27:32.0355 5728mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
    19:27:32.0355 5728mpio - ok
    19:27:32.0433 5728mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    19:27:32.0433 5728mpsdrv - ok
    19:27:32.0511 5728MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
    19:27:32.0526 5728MRxDAV - ok
    19:27:32.0604 5728mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
    19:27:32.0604 5728mrxsmb - ok
    19:27:32.0682 5728mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    19:27:32.0682 5728mrxsmb10 - ok
    19:27:32.0760 5728mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    19:27:32.0760 5728mrxsmb20 - ok
    19:27:32.0823 5728msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
    19:27:32.0823 5728msahci - ok
    19:27:32.0901 5728msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
    19:27:32.0901 5728msdsm - ok
    19:27:32.0979 5728Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    19:27:32.0979 5728Msfs - ok
    19:27:33.0010 5728mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    19:27:33.0010 5728mshidkmdf - ok
    19:27:33.0088 5728msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
    19:27:33.0088 5728msisadrv - ok
    19:27:33.0181 5728MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    19:27:33.0181 5728MSKSSRV - ok
    19:27:33.0259 5728MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    19:27:33.0259 5728MSPCLOCK - ok
    19:27:33.0306 5728MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    19:27:33.0306 5728MSPQM - ok
    19:27:33.0384 5728MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
    19:27:33.0384 5728MsRPC - ok
    19:27:33.0462 5728mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
    19:27:33.0462 5728mssmbios - ok
    19:27:33.0525 5728MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    19:27:33.0525 5728MSTEE - ok
    19:27:33.0556 5728MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    19:27:33.0556 5728MTConfig - ok
    19:27:33.0649 5728Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    19:27:33.0649 5728Mup - ok
    19:27:33.0790 5728NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    19:27:33.0790 5728NativeWifiP - ok
    19:27:33.0899 5728NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
    19:27:33.0915 5728NDIS - ok
    19:27:33.0993 5728NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    19:27:33.0993 5728NdisCap - ok
    19:27:34.0071 5728NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    19:27:34.0071 5728NdisTapi - ok
    19:27:34.0180 5728Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
    19:27:34.0180 5728Ndisuio - ok
    19:27:34.0242 5728NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
    19:27:34.0242 5728NdisWan - ok
    19:27:34.0273 5728NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
    19:27:34.0273 5728NDProxy - ok
    19:27:34.0367 5728NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    19:27:34.0367 5728NetBIOS - ok
    19:27:34.0398 5728NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
    19:27:34.0414 5728NetBT - ok
    19:27:34.0695 5728netw5v64 (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys
    19:27:34.0819 5728netw5v64 - ok
    19:27:34.0882 5728nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    19:27:34.0882 5728nfrd960 - ok
    19:27:34.0960 5728Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    19:27:34.0960 5728Npfs - ok
    19:27:34.0975 5728nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    19:27:34.0975 5728nsiproxy - ok
    19:27:35.0085 5728Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
    19:27:35.0116 5728Ntfs - ok
    19:27:35.0209 5728Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    19:27:35.0209 5728Null - ok
    19:27:35.0303 5728nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
    19:27:35.0319 5728nvraid - ok
    19:27:35.0397 5728nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
    19:27:35.0397 5728nvstor - ok
    19:27:35.0428 5728nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
    19:27:35.0428 5728nv_agp - ok
    19:27:35.0506 5728ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
    19:27:35.0506 5728ohci1394 - ok
    19:27:35.0646 5728Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    19:27:35.0646 5728Parport - ok
    19:27:35.0677 5728partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
    19:27:35.0677 5728partmgr - ok
    19:27:35.0724 5728pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
    19:27:35.0724 5728pci - ok
    19:27:35.0755 5728pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
    19:27:35.0755 5728pciide - ok
    19:27:35.0802 5728pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    19:27:35.0818 5728pcmcia - ok
    19:27:35.0896 5728pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    19:27:35.0896 5728pcw - ok
    19:27:35.0974 5728PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    19:27:35.0989 5728PEAUTH - ok
    19:27:36.0099 5728pgfilter - ok
    19:27:36.0255 5728PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
    19:27:36.0255 5728PptpMiniport - ok
    19:27:36.0333 5728Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    19:27:36.0333 5728Processor - ok
    19:27:36.0442 5728Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
    19:27:36.0442 5728Psched - ok
    19:27:36.0535 5728ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    19:27:36.0551 5728ql2300 - ok
    19:27:36.0645 5728ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    19:27:36.0645 5728ql40xx - ok
    19:27:36.0723 5728QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    19:27:36.0723 5728QWAVEdrv - ok
    19:27:36.0785 5728RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    19:27:36.0785 5728RasAcd - ok
    19:27:36.0879 5728RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    19:27:36.0879 5728RasAgileVpn - ok
    19:27:36.0972 5728Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
    19:27:36.0972 5728Rasl2tp - ok
    19:27:37.0035 5728RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    19:27:37.0035 5728RasPppoe - ok
    19:27:37.0128 5728RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    19:27:37.0128 5728RasSstp - ok
    19:27:37.0191 5728rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
    19:27:37.0206 5728rdbss - ok
    19:27:37.0284 5728rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    19:27:37.0284 5728rdpbus - ok
    19:27:37.0378 5728RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    19:27:37.0378 5728RDPCDD - ok
    19:27:37.0456 5728RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    19:27:37.0456 5728RDPENCDD - ok
    19:27:37.0549 5728RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    19:27:37.0549 5728RDPREFMP - ok
    19:27:37.0627 5728RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
    19:27:37.0627 5728RDPWD - ok
    19:27:37.0737 5728rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
    19:27:37.0737 5728rdyboost - ok
    19:27:37.0815 5728RimUsb - ok
    19:27:37.0893 5728RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
    19:27:37.0893 5728RimVSerPort - ok
    19:27:37.0986 5728ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys
    19:27:37.0986 5728ROOTMODEM - ok
    19:27:38.0095 5728rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    19:27:38.0095 5728rspndr - ok
    19:27:38.0220 5728RSUSBSTOR (a5df2f732a6c95554e548fcb6932bd31) C:\Windows\system32\Drivers\RtsUStor.sys
    19:27:38.0236 5728RSUSBSTOR - ok
    19:27:38.0329 5728RTL8167 (91296f0b2653281b2f11e0fce56aa427) C:\Windows\system32\DRIVERS\Rt64win7.sys
    19:27:38.0329 5728RTL8167 - ok
    19:27:38.0407 5728RtsUIR - ok
    19:27:38.0454 5728SASDIFSV (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
    19:27:38.0470 5728SASDIFSV - ok
    19:27:38.0470 5728SASKUTIL (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
    19:27:38.0470 5728SASKUTIL - ok
    19:27:38.0548 5728sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
    19:27:38.0548 5728sbp2port - ok
    19:27:38.0673 5728scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
    19:27:38.0673 5728scfilter - ok
    19:27:38.0766 5728sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
    19:27:38.0766 5728sdbus - ok
    19:27:38.0844 5728secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    19:27:38.0844 5728secdrv - ok
    19:27:38.0953 5728Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    19:27:38.0953 5728Serenum - ok
    19:27:38.0985 5728Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    19:27:38.0985 5728Serial - ok
    19:27:39.0063 5728sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    19:27:39.0078 5728sermouse - ok
    19:27:39.0156 5728sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
    19:27:39.0156 5728sffdisk - ok
    19:27:39.0219 5728sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
    19:27:39.0234 5728sffp_mmc - ok
    19:27:39.0234 5728sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
    19:27:39.0234 5728sffp_sd - ok
    19:27:39.0343 5728sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    19:27:39.0343 5728sfloppy - ok
    19:27:39.0421 5728SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    19:27:39.0421 5728SiSRaid2 - ok
    19:27:39.0437 5728SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    19:27:39.0437 5728SiSRaid4 - ok
    19:27:39.0531 5728Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    19:27:39.0531 5728Smb - ok
    19:27:39.0624 5728spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    19:27:39.0624 5728spldr - ok
    19:27:39.0671 5728srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
    19:27:39.0671 5728srv - ok
    19:27:39.0749 5728srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
    19:27:39.0749 5728srv2 - ok
    19:27:39.0843 5728SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    19:27:39.0843 5728SrvHsfHDA - ok
    19:27:39.0952 5728SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
    19:27:39.0983 5728SrvHsfV92 - ok
    19:27:40.0077 5728SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
    19:27:40.0092 5728SrvHsfWinac - ok
    19:27:40.0170 5728srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
    19:27:40.0170 5728srvnet - ok
    19:27:40.0295 5728stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    19:27:40.0295 5728stexstor - ok
    19:27:40.0404 5728STHDA (8d1ce4322a35f840711b87927cb57c05) C:\Windows\system32\DRIVERS\stwrt64.sys
    19:27:40.0420 5728STHDA - ok
    19:27:40.0513 5728StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
    19:27:40.0513 5728StillCam - ok
    19:27:40.0560 5728swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
    19:27:40.0560 5728swenum - ok
    19:27:40.0685 5728SynTP (924d711941956f7420a4925592be8253) C:\Windows\system32\DRIVERS\SynTP.sys
    19:27:40.0685 5728SynTP - ok
    19:27:40.0841 5728Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
    19:27:40.0872 5728Tcpip - ok
    19:27:40.0997 5728TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
    19:27:41.0013 5728TCPIP6 - ok
    19:27:41.0091 5728tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
    19:27:41.0091 5728tcpipreg - ok
    19:27:41.0137 5728TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    19:27:41.0137 5728TDPIPE - ok
    19:27:41.0184 5728TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
    19:27:41.0184 5728TDTCP - ok
    19:27:41.0278 5728tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
    19:27:41.0278 5728tdx - ok
    19:27:41.0325 5728TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
    19:27:41.0325 5728TermDD - ok
    19:27:41.0418 5728tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
    19:27:41.0434 5728tssecsrv - ok
    19:27:41.0527 5728TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
    19:27:41.0527 5728TsUsbFlt - ok
    19:27:41.0637 5728tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
    19:27:41.0637 5728tunnel - ok
    19:27:41.0699 5728uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    19:27:41.0715 5728uagp35 - ok
    19:27:41.0777 5728udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
    19:27:41.0793 5728udfs - ok
    19:27:41.0839 5728uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
    19:27:41.0839 5728uliagpkx - ok
    19:27:41.0949 5728umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
    19:27:41.0949 5728umbus - ok
    19:27:42.0027 5728UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    19:27:42.0027 5728UmPass - ok
    19:27:42.0058 5728USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
    19:27:42.0058 5728USBAAPL64 - ok
    19:27:42.0151 5728usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
    19:27:42.0151 5728usbccgp - ok
    19:27:42.0229 5728USBCCID - ok
    19:27:42.0307 5728usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
    19:27:42.0307 5728usbcir - ok
    19:27:42.0401 5728usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
    19:27:42.0401 5728usbehci - ok
    19:27:42.0479 5728usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
    19:27:42.0479 5728usbhub - ok
    19:27:42.0573 5728usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
    19:27:42.0573 5728usbohci - ok
    19:27:42.0651 5728usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    19:27:42.0651 5728usbprint - ok
    19:27:42.0682 5728USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    19:27:42.0682 5728USBSTOR - ok
    19:27:42.0760 5728usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
    19:27:42.0760 5728usbuhci - ok
    19:27:42.0869 5728usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
    19:27:42.0869 5728usbvideo - ok
    19:27:42.0978 5728vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
    19:27:42.0978 5728vdrvroot - ok
    19:27:43.0072 5728vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    19:27:43.0072 5728vga - ok
    19:27:43.0087 5728VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    19:27:43.0087 5728VgaSave - ok
    19:27:43.0165 5728vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
    19:27:43.0181 5728vhdmp - ok
    19:27:43.0243 5728viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
    19:27:43.0243 5728viaide - ok
    19:27:43.0290 5728volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
    19:27:43.0290 5728volmgr - ok
    19:27:43.0337 5728volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
    19:27:43.0337 5728volmgrx - ok
    19:27:43.0446 5728volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
    19:27:43.0446 5728volsnap - ok
    19:27:43.0524 5728vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    19:27:43.0524 5728vsmraid - ok
    19:27:43.0587 5728vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
    19:27:43.0587 5728vwifibus - ok
    19:27:43.0711 5728vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    19:27:43.0711 5728vwififlt - ok
    19:27:43.0805 5728WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    19:27:43.0805 5728WacomPen - ok
    19:27:43.0930 5728WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    19:27:43.0930 5728WANARP - ok
    19:27:43.0945 5728Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    19:27:43.0945 5728Wanarpv6 - ok
    19:27:44.0055 5728Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    19:27:44.0055 5728Wd - ok
    19:27:44.0133 5728Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    19:27:44.0148 5728Wdf01000 - ok
    19:27:44.0226 5728WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    19:27:44.0226 5728WfpLwf - ok
    19:27:44.0257 5728WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    19:27:44.0257 5728WIMMount - ok
    19:27:44.0413 5728WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
    19:27:44.0413 5728WinUsb - ok
    19:27:44.0523 5728WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
    19:27:44.0523 5728WmiAcpi - ok
    19:27:44.0632 5728ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    19:27:44.0632 5728ws2ifsl - ok
    19:27:44.0741 5728WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
    19:27:44.0741 5728WudfPf - ok
    19:27:44.0803 5728WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
    19:27:44.0803 5728WUDFRd - ok
    19:27:44.0913 5728yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
    19:27:44.0928 5728yukonw7 - ok
    19:27:44.0959 5728MBR (0x1B8) (8ca37966eb3c750d08ac01dcd8dda115) \Device\Harddisk0\DR0
    19:27:44.0959 5728\Device\Harddisk0\DR0 - ok
    19:27:44.0959 5728Boot (0x1200) (04dfb600a5d3c97f2dfd11dd84c1c8ac) \Device\Harddisk0\DR0\Partition0
    19:27:44.0959 5728\Device\Harddisk0\DR0\Partition0 - ok
    19:27:44.0975 5728Boot (0x1200) (5ec31804363fa57ade9e699acbdfa4fc) \Device\Harddisk0\DR0\Partition1
    19:27:44.0975 5728\Device\Harddisk0\DR0\Partition1 - ok
    19:27:45.0006 5728Boot (0x1200) (3c5b591e42ef80d39e7681c659ee5aa9) \Device\Harddisk0\DR0\Partition2
    19:27:45.0006 5728\Device\Harddisk0\DR0\Partition2 - ok
    19:27:45.0006 5728============================================================
    19:27:45.0006 5728Scan finished
    19:27:45.0006 5728============================================================
    19:27:45.0037 5848Detected object count: 0
    19:27:45.0037 5848Actual detected object count: 0
    19:28:43.0272 4952============================================================
    19:28:43.0272 4952Scan started
    19:28:43.0272 4952Mode: Manual;
    19:28:43.0272 4952============================================================
    19:28:44.0208 49521394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
    19:28:44.0208 49521394ohci - ok
    19:28:44.0271 4952Accelerometer (1cffe9c06e66a57dae1452e449a58240) C:\Windows\system32\DRIVERS\Accelerometer.sys
    19:28:44.0271 4952Accelerometer - ok
    19:28:44.0349 4952ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
    19:28:44.0364 4952ACPI - ok
    19:28:44.0442 4952AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
    19:28:44.0442 4952AcpiPmi - ok
    19:28:44.0489 4952adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    19:28:44.0505 4952adp94xx - ok
    19:28:44.0583 4952adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    19:28:44.0583 4952adpahci - ok
    19:28:44.0661 4952adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    19:28:44.0676 4952adpu320 - ok
    19:28:44.0723 4952AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
    19:28:44.0723 4952AFD - ok
    19:28:44.0848 4952AgereSoftModem (af4748ef93416159459769a24a0053af) C:\Windows\system32\DRIVERS\agrsm64.sys
    19:28:44.0863 4952AgereSoftModem - ok
    19:28:44.0941 4952agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
    19:28:44.0941 4952agp440 - ok
    19:28:45.0035 4952aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
    19:28:45.0035 4952aliide - ok
    19:28:45.0097 4952amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
    19:28:45.0097 4952amdide - ok
    19:28:45.0129 4952AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    19:28:45.0129 4952AmdK8 - ok
    19:28:45.0207 4952AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    19:28:45.0207 4952AmdPPM - ok
    19:28:45.0269 4952amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
    19:28:45.0269 4952amdsata - ok
    19:28:45.0300 4952amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    19:28:45.0300 4952amdsbs - ok
    19:28:45.0378 4952amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
    19:28:45.0378 4952amdxata - ok
    19:28:45.0409 4952AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
    19:28:45.0409 4952AppID - ok
    19:28:45.0503 4952arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    19:28:45.0503 4952arc - ok
    19:28:45.0534 4952arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    19:28:45.0534 4952arcsas - ok
    19:28:45.0581 4952AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    19:28:45.0581 4952AsyncMac - ok
    19:28:45.0612 4952atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
    19:28:45.0628 4952atapi - ok
    19:28:45.0815 4952atikmdag (3efd964d52221360af0673cd61c2f4f5) C:\Windows\system32\drivers\atikmdag.sys
    19:28:45.0862 4952atikmdag - ok
    19:28:46.0018 4952AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
    19:28:46.0018 4952AVGIDSEH - ok
    19:28:46.0065 4952Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys
    19:28:46.0065 4952Avgtdia - ok
    19:28:46.0143 4952b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    19:28:46.0143 4952b06bdrv - ok
    19:28:46.0221 4952b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    19:28:46.0221 4952b57nd60a - ok
    19:28:46.0377 4952BCM43XX (0e14a0071fe26a570bcaff5401014717) C:\Windows\system32\DRIVERS\bcmwl664.sys
    19:28:46.0408 4952BCM43XX - ok
    19:28:46.0486 4952Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    19:28:46.0486 4952Beep - ok
    19:28:46.0517 4952blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    19:28:46.0517 4952blbdrive - ok
    19:28:46.0611 4952bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
    19:28:46.0611 4952bowser - ok
    19:28:46.0642 4952BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    19:28:46.0642 4952BrFiltLo - ok
    19:28:46.0735 4952BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    19:28:46.0735 4952BrFiltUp - ok
    19:28:46.0829 4952Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    19:28:46.0829 4952Brserid - ok
    19:28:46.0907 4952BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    19:28:46.0907 4952BrSerWdm - ok
    19:28:46.0923 4952BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    19:28:46.0923 4952BrUsbMdm - ok
    19:28:47.0001 4952BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    19:28:47.0001 4952BrUsbSer - ok
    19:28:47.0032 4952BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    19:28:47.0032 4952BTHMODEM - ok
    19:28:47.0125 4952cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    19:28:47.0125 4952cdfs - ok
    19:28:47.0219 4952cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
    19:28:47.0219 4952cdrom - ok
    19:28:47.0297 4952circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    19:28:47.0297 4952circlass - ok
    19:28:47.0375 4952CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    19:28:47.0375 4952CLFS - ok
    19:28:47.0469 4952CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    19:28:47.0469 4952CmBatt - ok
    19:28:47.0531 4952cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
    19:28:47.0531 4952cmdide - ok
    19:28:47.0578 4952CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
    19:28:47.0578 4952CNG - ok
    19:28:47.0656 4952Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    19:28:47.0656 4952Compbatt - ok
    19:28:47.0749 4952CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
    19:28:47.0749 4952CompositeBus - ok
    19:28:47.0827 4952crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    19:28:47.0827 4952crcdisk - ok
    19:28:47.0937 4952DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
    19:28:47.0937 4952DfsC - ok
    19:28:48.0030 4952discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    19:28:48.0030 4952discache - ok
    19:28:48.0061 4952Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    19:28:48.0061 4952Disk - ok
    19:28:48.0155 4952drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    19:28:48.0155 4952drmkaud - ok
    19:28:48.0249 4952DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
    19:28:48.0264 4952DXGKrnl - ok
    19:28:48.0420 4952ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    19:28:48.0451 4952ebdrv - ok
    19:28:48.0561 4952elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    19:28:48.0561 4952elxstor - ok
    19:28:48.0639 4952enecir (524c79054636d2e5751169005006460b) C:\Windows\system32\DRIVERS\enecir.sys
    19:28:48.0639 4952enecir - ok
    19:28:48.0685 4952ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
    19:28:48.0685 4952ErrDev - ok
    19:28:48.0779 4952exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    19:28:48.0795 4952exfat - ok
    19:28:48.0873 4952fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    19:28:48.0873 4952fastfat - ok
    19:28:48.0951 4952fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    19:28:48.0951 4952fdc - ok
    19:28:49.0044 4952FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    19:28:49.0044 4952FileInfo - ok
    19:28:49.0091 4952Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    19:28:49.0091 4952Filetrace - ok
    19:28:49.0138 4952flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    19:28:49.0138 4952flpydisk - ok
    19:28:49.0216 4952FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
    19:28:49.0216 4952FltMgr - ok
    19:28:49.0294 4952FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    19:28:49.0294 4952FsDepends - ok
    19:28:49.0325 4952Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    19:28:49.0325 4952Fs_Rec - ok
    19:28:49.0419 4952fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
    19:28:49.0419 4952fvevol - ok
    19:28:49.0497 4952gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    19:28:49.0497 4952gagp30kx - ok
    19:28:49.0575 4952GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    19:28:49.0575 4952GEARAspiWDM - ok
    19:28:49.0637 4952hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    19:28:49.0637 4952hcw85cir - ok
    19:28:49.0731 4952HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
    19:28:49.0731 4952HdAudAddService - ok
    19:28:49.0793 4952HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
    19:28:49.0793 4952HDAudBus - ok
    19:28:49.0871 4952HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    19:28:49.0871 4952HidBatt - ok
    19:28:49.0902 4952HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    19:28:49.0902 4952HidBth - ok
    19:28:49.0980 4952HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    19:28:49.0980 4952HidIr - ok
    19:28:50.0012 4952HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
    19:28:50.0012 4952HidUsb - ok
    19:28:50.0090 4952hpdskflt (05712fddbd45a5864eb326faabc6a4e3) C:\Windows\system32\DRIVERS\hpdskflt.sys
    19:28:50.0090 4952hpdskflt - ok
    19:28:50.0152 4952HpqKbFiltr (9af482d058be59cc28bce52e7c4b747c) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
    19:28:50.0168 4952HpqKbFiltr - ok
    19:28:50.0199 4952HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
    19:28:50.0199 4952HpSAMD - ok
    19:28:50.0324 4952HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
    19:28:50.0324 4952HTTP - ok
    19:28:50.0402 4952hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
    19:28:50.0402 4952hwpolicy - ok
    19:28:50.0433 4952i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
    19:28:50.0433 4952i8042prt - ok
    19:28:50.0542 4952iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
    19:28:50.0542 4952iaStor - ok
    19:28:50.0636 4952iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
    19:28:50.0651 4952iaStorV - ok
    19:28:50.0916 4952igfx (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys
    19:28:50.0979 4952igfx - ok
    19:28:51.0150 4952iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    19:28:51.0150 4952iirsp - ok
    19:28:51.0244 4952IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys
    19:28:51.0244 4952IntcHdmiAddService - ok
    19:28:51.0306 4952intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
    19:28:51.0306 4952intelide - ok
    19:28:51.0338 4952intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    19:28:51.0338 4952intelppm - ok
    19:28:51.0431 4952IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    19:28:51.0431 4952IpFilterDriver - ok
    19:28:51.0462 4952IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
    19:28:51.0462 4952IPMIDRV - ok
    19:28:51.0540 4952IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    19:28:51.0540 4952IPNAT - ok
    19:28:51.0618 4952IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    19:28:51.0634 4952IRENUM - ok
    19:28:51.0712 4952isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
    19:28:51.0712 4952isapnp - ok
    19:28:51.0743 4952iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
    19:28:51.0759 4952iScsiPrt - ok
    19:28:51.0821 4952kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
    19:28:51.0821 4952kbdclass - ok
    19:28:51.0868 4952kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
    19:28:51.0868 4952kbdhid - ok
    19:28:51.0946 4952KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
    19:28:51.0946 4952KSecDD - ok
    19:28:51.0977 4952KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
    19:28:51.0977 4952KSecPkg - ok
    19:28:52.0055 4952ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    19:28:52.0055 4952ksthunk - ok
    19:28:52.0102 4952lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    19:28:52.0102 4952lltdio - ok
    19:28:52.0196 4952LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    19:28:52.0196 4952LSI_FC - ok
    19:28:52.0211 4952LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    19:28:52.0211 4952LSI_SAS - ok
    19:28:52.0289 4952LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    19:28:52.0289 4952LSI_SAS2 - ok
    19:28:52.0383 4952LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a)Save these instructions so you can have access to them while in Safe Mode.

    Please click here to download AVP Tool by Kaspersky.
    • Save it to your desktop.
    • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    • Double click the setup file to run it.
    • Click Next to continue.
    • Accept the License agreement and click on next.
    • It will, by default, install it to your desktop folder. Click Next.
    • It will then open a box There will be a tab that says Automatic scan.
    • Under Automatic scan make SURE these are checked.
    • Hidden Startup Objects
    • System Memory
    • Disk Boot Sectors.
    • My Computer.
    • Also any other drives (Removable that you may have)
    Leave the rest of the settings as they appear as default.
    •Then click on Scan at the to right hand Corner.
    •It will automatically Neutralize any objects found.
    •If some objects are left un-neutralized then click the button that says Neutralize all
    •If it says it cannot be neutralized then choose the delete option when prompted.
    •After that is done click on the reports button at the bottom and save it to file name it Kas.
    •Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.
    I had a problem trying to save the log while in the SAFE MODE...It did say there were no threats. Is it important for you to see the log...?

    I can try again.

    Also please note that in the bottom right hand corner of the screen I get a "test mode" Rebuild 7601. Would this account for any instability...?Quote
    It did say there were no threats. Is it important for you to see the log...?
    No. If there were no threats I don't need to see it.

    Quote
    Also please note that in the bottom right hand corner of the screen I get a "test mode" Rebuild 7601. Would this account for any instability...?
    What do you mean by instability?
    My main problem is that programs. IE, etc sudeenly they start FLASHING o n and off and not responding can be read at the top of the program.

    It seems to happen to all programs and websites.All the scans are not picking up any infections. I would suspect that there is something wrong with the video card or some other piece of hardware in your computer. You could start another thread in the proper forum for the OS of your computer and perhaps, someone could help your there.
    4258.

    Solve : Taking charge?

    Answer»

    HI everyone!

    Today I read about BOT nets, and got an idea:
    (Purely THEORETICAL:)
    Would it be possible to use an infected computer to take control over, and destroy the entire network?

    Would it also be possible to trace the origin of the bot NET?

    Thx!
    //RG0D SIGH

    4259.

    Solve : Norton Anti-Virus2011?

    Answer»

    Hey guys. I'm new here and I thought I/d let you know that I have Norton Anti-Virus Security and it has to be one of the best out there! It's very easy to USE and it works very well at apprehending viruses. Aside from the COST, I think everyone who is currently dealing with viruses should use the free trial to their needs.
    I think you are the only person on this forum who would actually recommend Norton. There are better Anti-Viruses out there. NAV is an excellent product. It's among the best anti virus utilities AVAILABLE. Quote from: NoahF on December 05, 2011, 03:44:46 AM

    Aside from the cost, I think everyone who is currently dealing with viruses should use the free trial to their needs.
    So, just use it during the free trial period, right? Quote from: reddevilggg on December 05, 2011, 03:47:00 AM
    I think you are the only person on this forum who would actually recommend Norton. There are better Anti-Viruses out there.
    Quote from: Allan on December 05, 2011, 05:29:53 AM
    NAV is an excellent product. It's among the best anti virus utilities available.

    I've got absolutely no idea why i wrote my first response, it was a shock when i just read it. Allan is right, of course. Now, where is my head............??I posted this a couple of weeks ago on another thread.

    Quote
    Maximum PC magazine just did a rating on av programs. They rated Norton as best of the paid programs with a 9+ rating and all of the free programs rated from 6 to 8. Based on that you usually, but not always, get what you pay for since McAfee was rated a 5.

    Since Comcast is my ISP I get Norton for "free" and it's worked fairly well for me.

    And I know if you get 10 people to rate anything you will get 10 different opinions.
    I say that the "right" antivirus is a combo of personal preference and detection. While another product may offer slightly more detection, some feel content with an AV that they prefer. Most modern AV solutions are similar in detection and on par with each other. KEYWORD: most.
    4260.

    Solve : Question about AVG Free 2012??

    Answer»

    So, I kept getting threats from 'Trojan.fakealert' and I ssent them to the virus vault. I CLEARED the virus vault and today while scanning, it said in the scan RESULTS I have an infection called: Trojan Horse Generic26.xku
    It is in the virus vault. Since it is in there- will it still harm my computer?
    And can I safely clear the virus vault?Quote from: terenkleon on December 15, 2011, 04:33:25 AM

    So, I kept getting threats from 'Trojan.fakealert' and I ssent them to the virus vault. I cleared the virus vault and today while scanning, it said in the scan results I have an infection called: Trojan Horse Generic26.xku
    It is in the virus vault. Since it is in there- will it still harm my computer?
    And can I safely clear the virus vault?
    As long as it remains in the vault it is HARMLESS. Yes, you can clear the vault.Update your software protection.
    Microsoft Defender maybe
    Run SPYBOT, from safer-networking.org
    4261.

    Solve : Google redirrection virus?

    Answer»

    Quote

    I didn't try it YET. I wait for your answer...

    Please do not run any scans unless I ask you to do so.

    Save these instructions so you can have access to them while in Safe Mode.

    Please CLICK here to download AVP Tool by Kaspersky.
    • Save it to your desktop.
    • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    • Double click the setup file to run it.
    • Click Next to continue.
    • Accept the License agreement and click on next.
    • It will, by default, install it to your desktop folder. Click Next.
    • It will then open a box There will be a tab that says Automatic scan.
    • Under Automatic scan make sure these are checked.
    • Hidden Startup Objects
    • System Memory
    • Disk Boot Sectors.
    • My Computer.
    • Also any other drives (Removable that you may have)
    Leave the rest of the settings as they appear as default.
    •Then click on Scan at the to right hand Corner.
    •It will automatically Neutralize any objects found.
    •If some objects are left un-neutralized then click the button that says Neutralize all
    •If it says it cannot be neutralized then choose the delete option when PROMPTED.
    •After that is done click on the reports button at the bottom and save it to file name it Kas.
    •Save it SOMEWHERE convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.Well....

    They didn't want to wait anymore... they took it to a repair shop...
    I guess it's their problem now

    Sorry for that
    But thank you for all your help.Too bad, I would loved to know how to clean it... and know what was this virus...Quote
    They didn't want to wait anymore... they took it to a repair shop...
    They'll just re-format it. I will lock this thread. If you need it re-opened, please send me a PM.
    4262.

    Solve : remove spyware removal, trojan rootkit?

    Answer»

    Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.The rescue cds didn't work. But I will tell you this I was finally able to boot from my Windows cd and do a fresh INSTALL thank you guys for everything.You're welcome. It's too bad it had to come to that but some infections damage the FILES so badly that there's no other option. I will lock this thread. If you need it re-opened, PLEASE send me a PM.

    4263.

    Solve : relevant knowledge is back 3rd time?

    Answer»

    Quote

    can i just leave the programs you suggested to download?
    The only two that you should keep is SAS and MBAM. Update them and run them on a regular basis.
    Quote
    relevant knowledge is really bad for the computer?
    Just annoying.
    There no EVIDENCE of Relevant Knowledge on your computer. What's makes you think that it is there?
    You should uninstall the two programs listed below because they have some level of spyware.

    GamesBar 2.0.1.82

    MyPoints Point FinderI'm assuming we are done. tyvmQuote from: darcomputer on December 13, 2011, 10:05:13 PM
    I'm assuming we are done. tyvm
    We can run a whole bunch of scans but it would be for nothing if you're not having any PROBLEMS. Are you still having problems?except for facebook games yes tysoo very much, i have done as you said Quote from: darcomputer on December 14, 2011, 09:19:40 PM
    except for facebook games yes tysoo very much, i have done as you said
    Please explain the facebook games problem to me again.When playing The Sims on Facebook every 6 minutes i would be asked to reload. i now have a terrible problem. i thought the computer froze while updating my nvidia and then the computer started to turn itself off, checked and both video and ethernet controllers are gone. i'm on my FRIENDS laptop. computer. It went into safe mode last time i turned it on. haven't turned on today out of fear I have posted in the driver forum yesterday at 10am Waiting patiently. thank you for listening. i guess we're really done now, again thank you from the bottom of my heart for your help until next time You're welcome. I'm sorry I couldn't be more helpful. I will lock this thread. If you need it re-opened, please send me a pm.
    4264.

    Solve : McAfee app installed?

    Answer»

    I've just installed the LATEST FOXIT Reader - this download included "McAfee Security Scan Plus", which I suppose is a virus checking program. I am a bit wary of this - I already have Avira Anti Virus, and Malwarebyte, and Super Antispyware - I don't want to have a conflicting AV program. Is the McAfee app. any good or would it be best to uninstall? Advice appreciated. Uninstall it.McAfee Security Scan Plus actively CHECKS your computer for anti-virus software, firewall protection, and web security, and threats in your OPEN applications.

    Thanks for replies - I'll uninstall.

    4265.

    Solve : IRQL_NOT_LESS_OR_EQUAL caused by a virus .exe?

    Answer»

    Logs From OTL


    ========== OTL ==========
    ========== FILES ==========
    File\Folder C:\found.009 not found.
    ========== COMMANDS ==========
    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully

    OTL by OldTimer - VERSION 3.2.28.0 log created on 09152011_172403


    Combofix was detected as a malware.1) I got a bosd while running scans using malware anti malbytes

    ==================================================
    Dump File : 091511-45645-01.dmp
    Crash Time : 9/15/2011 6:44:21 PM
    Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
    Bug Check Code : 0x00000050
    Parameter 1 : fffff8a0`067b0000
    Parameter 2 : 00000000`00000000
    Parameter 3 : fffff880`0165fa38
    Parameter 4 : 00000000`00000000
    Caused By Driver : ntoskrnl.exe
    Caused By Address : ntoskrnl.exe+7cc40
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : x64
    Crash Address : ntoskrnl.exe+7cc40
    Stack Address 1 :
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\091511-45645-01.dmp
    Processors Count : 3
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 274,576
    ==================================================


    2) The Attachment of the DDS test is here




    [regaining space - attachment deleted by admin]I strongly recommend that you remove Ask from your computer because it;

    •Promotes its toolbars on sites targeted to kids.

    •Promotes its toolbars through ads that appear to be part of other companies' sites.

    •Promotes its toolbars through other companies' spyware.

    •Installs without any disclosure whatsoever and without any consent whatsoever.

    •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

    •Makes confusing changes to users' browsers -- increasing Ask's revenues while TAKING users to pages they didn't intend to visit.

    See Here for more info.

    If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

    AskBarDis or anything related to Ask

    Then please find and delete this folder in bold (if present):
    C:\Program Files\AskBarDis. or anything related to Ask.
    *****************************************************
    I see you are running Poker Stars. Poker Stars has a history of distributing spyware in their products. However, security experts still question this program as good or bad. I recommend to remove it to prevent spyware, but it is up to you to decide if you want to keep it.

    If you would like to uninstall it, do so as follows:

    Press Start, and navigate to the Control Panel. When in the control panel enter Add or Remove programs. Search for and locate PokerStars, and either click Change/Remove or Remove.
    ******************************************************
    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to INFECT your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL OPEN web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java QUICK Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    *****************************************************
    P2P - I see you have P2P software installed on your machine. (µTorrent, Ares 2.1.5, FrostWire 4.21.6 and FrostWire 5.0. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
    ***************************************************
    Quote

    Combofix was detected as a malware.
    You need to turn off your protection. Please try it again.

    Quote
    I got a bosd while running scans using malware anti malbytes
    Re-boot in Safe Mode and try running MBAM.sorry for the delay again, im running the tests atm
    4266.

    Solve : Stupid Virus Removal Question?

    Answer»

    I have to sort through some old files and DISKS for WORK... But they were downloaded from a sketchy source.

    If I set a System Restore POINT before I download, copy, or OPEN the suspect files... If I go back to the restore point once I'm done, will I have mitigated any damage?If you create an image or your "clean disc" with Disc Imaging software you will have no problem. System Restore only copies/restores certain files & foldersThat's what I was afraid of.

    Thanks.

    rjbYou should be using disc imaging software on a regular basis anyway. It is without question the best and most reliable means of system BACKUP and restore.You can run some scans on the disks before you do anything else.

    4267.

    Solve : whitesmoke toolbar virus trouble?

    Answer»

    ComboFix 11-03-13.02 - Connor 03/14/2011 17:28:33.3.2 - x64
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4095.2447 [GMT -4:00]
    Running from: c:\users\Connor\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    FW: PC Tools Firewall Plus *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other DELETIONS )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Connor\AppData\Local\Temp\VPN_77D6\9218E5A4.dll
    c:\windows\TEMP\VPN_57C7\9218E5A4.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-14 to 2011-03-14 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-14 21:44 . 2011-03-14 21:44--------d-----w-c:\windows\system32\config\systemprofile\AppData\Local\temp
    2011-03-14 21:44 . 2011-03-14 21:44--------d-----w-c:\users\Default\AppData\Local\temp
    2011-03-14 21:24 . 2011-03-14 21:25--------d-----w-C:\32788R22FWJFW
    2011-03-14 03:03 . 2011-02-11 04:317947600----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4300CDD2-4DB3-47E4-88F4-D19C9343D8E6}\mpengine.dll
    2011-03-10 21:20 . 2011-03-10 21:20--------d-----w-C:\_OTL
    2011-03-08 20:20 . 2011-03-08 20:20--------d-----w-c:\program files (x86)\Common Files\Skype
    2011-03-06 03:29 . 2011-03-06 03:29--------d-----w-C:\LazyNewbPack[0.31.19][V8.0]
    2011-03-05 12:31 . 2008-10-15 11:22519000----a-w-c:\windows\system32\d3dx10_40.dll
    2011-03-05 12:31 . 2008-10-15 11:22452440----a-w-c:\windows\SysWow64\d3dx10_40.dll
    2011-03-05 12:31 . 2008-10-15 11:222605920----a-w-c:\windows\system32\D3DCompiler_40.dll
    2011-03-05 12:31 . 2008-10-15 11:222036576----a-w-c:\windows\SysWow64\D3DCompiler_40.dll
    2011-03-05 12:31 . 2008-10-15 11:225631312----a-w-c:\windows\system32\D3DX9_40.dll
    2011-03-05 12:31 . 2008-10-15 11:224379984----a-w-c:\windows\SysWow64\D3DX9_40.dll
    2011-03-05 12:30 . 2011-03-05 12:30--------d-----w-c:\users\Public\Games
    2011-03-05 01:26 . 2011-03-05 01:37364201984----a-w-C:\WindSlayer-01_09_0000.exe
    2011-03-05 00:23 . 2011-03-05 00:23--------d-----w-C:\gPotato
    2011-03-05 00:11 . 2011-03-05 00:23472781133----a-w-C:\AIKAOnline_US_Setup_20101103.exe
    2011-03-04 03:33 . 2011-03-04 03:35--------d-----w-c:\users\Connor\AppData\Roaming\BugTrap Console Test108
    2011-02-28 23:57 . 2011-02-11 04:317947600----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-02-28 23:57 . 2011-02-28 23:56601424------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{92021A4C-7412-4852-B81E-546412346036}\gapaengine.dll
    2011-02-28 23:46 . 2011-02-28 23:46--------d-----w-c:\program files (x86)\Microsoft Security CLIENT
    2011-02-28 23:46 . 2011-02-28 23:47--------d-----w-c:\program files\Microsoft Security Client
    2011-02-28 23:46 . 2010-04-09 11:06374664----a-w-c:\windows\system32\drivers\netio.sys
    2011-02-27 23:37 . 2011-02-27 23:37388096----a-r-c:\users\Connor\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-02-27 23:37 . 2011-02-27 23:37--------d-----w-c:\program files (x86)\Trend Micro
    2011-02-27 23:17 . 2011-02-27 23:17--------d-sh--w-c:\windows\SysWow64\%APPDATA%
    2011-02-27 21:04 . 2011-02-27 21:04--------d-----w-c:\users\Connor\AppData\Roaming\SUPERAntiSpyware.com
    2011-02-27 21:04 . 2011-02-27 21:04--------d-----w-c:\programdata\SUPERAntiSpyware.com
    2011-02-27 21:04 . 2011-02-27 21:04--------d-----w-c:\programdata\!SASCORE
    2011-02-27 21:04 . 2011-02-27 21:04--------d-----w-c:\program files\SUPERAntiSpyware
    2011-02-27 20:46 . 2011-02-27 20:46--------d-----w-c:\program files\CCleaner
    2011-02-27 20:38 . 2010-03-29 16:06233488----a-w-c:\windows\system32\drivers\PCTCore64.sys
    2011-02-27 20:38 . 2010-11-17 15:20331368----a-w-c:\windows\system32\drivers\pctgntdi64.sys
    2011-02-27 20:38 . 2010-11-17 15:20136168----a-w-c:\windows\system32\drivers\pctwfpfilter64.sys
    2011-02-27 20:38 . 2011-02-27 23:17--------d-----w-c:\users\Connor\AppData\Roaming\PCToolsFirewallPlus
    2011-02-27 20:37 . 2011-02-27 20:38--------d-----w-c:\program files (x86)\Common Files\PC Tools
    2011-02-27 20:37 . 2010-11-24 14:18119688----a-w-c:\windows\system32\drivers\pctNdis-PacketFilter64.sys
    2011-02-27 20:37 . 2010-07-08 14:4979000----a-w-c:\windows\system32\drivers\pctNdis64.sys
    2011-02-27 20:37 . 2010-02-05 14:2642968----a-w-c:\windows\system32\drivers\pctNdis-DNS64.sys
    2011-02-27 20:37 . 2010-11-25 15:42179464----a-w-c:\windows\system32\drivers\pctplfw64.sys
    2011-02-27 20:37 . 2011-02-27 23:17--------d-----w-c:\program files (x86)\PC Tools Firewall Plus
    2011-02-27 16:31 . 2011-02-27 21:01--------d-----w-c:\program files (x86)\Spybot - Search & Destroy
    2011-02-27 16:31 . 2011-02-27 21:01--------d-----w-c:\programdata\Spybot - Search & Destroy
    2011-02-27 15:52 . 2010-12-20 23:0938224----a-w-c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2011-02-27 07:49 . 2011-02-27 15:52--------d-----w-c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
    2011-02-24 13:49 . 2010-09-14 06:45367104----a-w-c:\windows\system32\wcncsvc.dll
    2011-02-24 13:49 . 2010-09-14 06:07276992----a-w-c:\windows\SysWow64\wcncsvc.dll
    2011-02-23 21:20 . 2011-02-23 21:20--------d-----w-c:\program files (x86)\Common Files\Java
    2011-02-23 21:19 . 2011-02-03 02:40472808----a-w-c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    2011-02-23 21:18 . 2011-02-23 21:18--------d-----w-c:\programdata\McAfee
    2011-02-23 20:23 . 2011-02-23 20:23--------d-----w-c:\program files (x86)\LOLReplay
    2011-02-23 16:55 . 2011-01-07 08:07662528----a-w-c:\windows\system32\XpsPrint.dll
    2011-02-23 16:55 . 2011-01-07 08:07475648----a-w-c:\windows\system32\XpsGdiConverter.dll
    2011-02-23 16:55 . 2011-01-07 07:31442880----a-w-c:\windows\SysWow64\XpsPrint.dll
    2011-02-23 16:55 . 2011-01-07 07:31288256----a-w-c:\windows\SysWow64\XpsGdiConverter.dll
    2011-02-21 20:44 . 2008-10-15 14:25461680----a-w-C:\Dbgview.exe
    2011-02-20 21:17 . 2011-02-20 21:17--------d--h--w-c:\windows\system32\CanonMF Uninstaller Information
    2011-02-20 21:17 . 2011-02-20 21:17--------d-----w-c:\program files\Canon
    2011-02-20 21:16 . 2007-04-18 22:1366048----a-w-c:\windows\system32\CNAS0MMK.DLL
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-02-03 02:40 . 2011-01-13 14:44472808----a-w-c:\windows\SysWow64\deployJava1.dll
    2011-01-30 03:17 . 2011-01-30 03:1729808----a-w-c:\windows\system32\drivers\Neo_0014.sys
    2011-01-30 03:16 . 2011-01-30 03:1681920----a-w-c:\windows\SysWow64\vpncmd.exe
    2011-01-26 06:53 . 2011-02-09 20:22982912----a-w-c:\windows\system32\drivers\dxgkrnl.sys
    2011-01-26 06:53 . 2011-02-09 20:22265088----a-w-c:\windows\system32\drivers\dxgmms1.sys
    2011-01-26 06:31 . 2011-02-09 20:22144384----a-w-c:\windows\system32\cdd.dll
    2011-01-19 08:26 . 2011-01-19 08:2686016----a-w-c:\windows\SysWow64\frapsvid.dll
    2011-01-19 08:26 . 2011-01-19 08:2684992----a-w-c:\windows\system32\frapsv64.dll
    2011-01-07 08:06 . 2011-02-09 20:2246080----a-w-c:\windows\system32\atmlib.dll
    2011-01-07 07:27 . 2011-02-09 20:2234304----a-w-c:\windows\SysWow64\atmlib.dll
    2011-01-07 05:49 . 2011-02-09 20:22366080----a-w-c:\windows\system32\atmfd.dll
    2011-01-07 05:33 . 2011-02-09 20:22294400----a-w-c:\windows\SysWow64\atmfd.dll
    2011-01-05 06:20 . 2011-02-09 20:22612352----a-w-c:\windows\system32\vbscript.dll
    2011-01-05 05:37 . 2011-02-09 20:22428032----a-w-c:\windows\SysWow64\vbscript.dll
    2011-01-05 04:00 . 2011-02-09 20:223127808----a-w-c:\windows\system32\win32k.sys
    2011-01-03 06:32 . 2010-01-08 14:1445056----a-w-c:\windows\system32\acovcnt.exe
    2010-12-27 18:55 . 2008-11-25 16:12348160----a-w-c:\windows\SysWow64\msvcr71.dll
    2010-12-27 18:55 . 2008-11-25 16:12499712----a-w-c:\windows\SysWow64\msvcp71.dll
    2010-12-21 06:16 . 2011-02-09 20:2262976----a-w-c:\windows\system32\wscapi.dll
    2010-12-21 06:16 . 2011-02-09 20:2297280----a-w-c:\windows\system32\wscsvc.dll
    2010-12-21 06:16 . 2011-02-09 20:22214016----a-w-c:\windows\system32\winsrv.dll
    2010-12-21 06:16 . 2011-02-09 20:221197056----a-w-c:\windows\system32\wininet.dll
    2010-12-21 06:16 . 2011-02-09 20:22442880----a-w-c:\windows\system32\winhttp.dll
    2010-12-21 06:16 . 2011-02-09 20:22258048----a-w-c:\windows\system32\WebClnt.dll
    2010-12-21 06:15 . 2011-02-09 20:22264192----a-w-c:\windows\system32\upnp.dll
    2010-12-21 06:15 . 2011-02-09 20:2215360----a-w-c:\windows\system32\slwga.dll
    2010-12-21 06:13 . 2011-02-09 20:222003968----a-w-c:\windows\system32\msxml6.dll
    2010-12-21 06:13 . 2011-02-09 20:221880576----a-w-c:\windows\system32\msxml3.dll
    2010-12-21 06:10 . 2011-02-09 20:22100864----a-w-c:\windows\system32\davclnt.dll
    2010-12-21 05:38 . 2011-02-09 20:2251200----a-w-c:\windows\SysWow64\wscapi.dll
    2010-12-21 05:38 . 2011-02-09 20:22981504----a-w-c:\windows\SysWow64\wininet.dll
    2010-12-21 05:38 . 2011-02-09 20:22350720----a-w-c:\windows\SysWow64\winhttp.dll
    2010-12-21 05:38 . 2011-02-09 20:22204800----a-w-c:\windows\SysWow64\WebClnt.dll
    2010-12-21 05:38 . 2011-02-09 20:22204288----a-w-c:\windows\SysWow64\upnp.dll
    2010-12-21 05:38 . 2011-02-09 20:2214336----a-w-c:\windows\SysWow64\slwga.dll
    2010-12-21 05:36 . 2011-02-09 20:221389568----a-w-c:\windows\SysWow64\msxml6.dll
    2010-12-21 05:36 . 2011-02-09 20:221236992----a-w-c:\windows\SysWow64\msxml3.dll
    2010-12-21 05:34 . 2011-02-09 20:2280384----a-w-c:\windows\SysWow64\davclnt.dll
    2010-12-20 23:08 . 2010-12-04 20:3124152----a-w-c:\windows\system32\drivers\mbam.sys
    2010-12-18 06:11 . 2011-02-09 20:2257856----a-w-c:\windows\system32\licmgr10.dll
    2010-12-18 06:11 . 2011-02-09 20:22714752----a-w-c:\windows\system32\kerberos.dll
    2010-12-18 05:29 . 2011-02-09 20:2244544----a-w-c:\windows\SysWow64\licmgr10.dll
    2010-12-18 05:29 . 2011-02-09 20:22541184----a-w-c:\windows\SysWow64\kerberos.dll
    2010-12-18 04:55 . 2011-02-09 20:22482816----a-w-c:\windows\system32\html.iec
    2010-12-18 04:20 . 2011-02-09 20:22386048----a-w-c:\windows\SysWow64\html.iec
    2010-12-18 04:13 . 2011-02-09 20:221638912----a-w-c:\windows\system32\mshtml.tlb
    2010-12-18 03:47 . 2011-02-09 20:221638912----a-w-c:\windows\SysWow64\mshtml.tlb
    .
    .
    ((((((((((((((((((((((((((((( [emailprotected]_00.19.51 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2011-02-27 23:17 . 2011-02-27 23:1616384 c:\windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
    + 2011-02-27 23:17 . 2011-03-14 17:5616384 c:\windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
    + 2009-09-16 01:36 . 2011-03-14 21:1857818 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2011-03-14 21:4848854 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2009-11-15 10:07 . 2011-03-14 21:4826572 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-712587676-1097138996-4050794247-1000_UserData.bin
    + 2010-11-21 04:55 . 2011-03-09 08:5316384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
    - 2010-11-21 04:55 . 2011-02-28 05:4916384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
    - 2009-11-15 10:12 . 2011-03-01 00:0516384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-15 10:12 . 2011-03-14 21:4716384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-07-14 04:46 . 2011-03-12 15:2780352 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    + 2009-11-15 10:12 . 2011-03-14 21:4732768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-11-15 10:12 . 2011-03-01 00:0532768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-11-15 10:12 . 2011-03-14 21:4716384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-15 10:12 . 2011-03-01 00:0516384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-15 10:09 . 2011-03-01 00:0516384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-15 10:09 . 2011-03-14 21:4816384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-15 10:09 . 2011-03-14 21:4816384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-15 10:09 . 2011-03-01 00:0516384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-16 03:17 . 2011-03-09 08:0135088 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\oisicon.exe
    - 2009-11-16 03:17 . 2011-02-10 12:4635088 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\oisicon.exe
    + 2009-11-16 03:17 . 2011-03-09 08:0118704 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-11-16 03:17 . 2011-02-10 12:4618704 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-11-16 05:33 . 2011-02-10 12:4620240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\cagicon.exe
    + 2009-11-16 05:33 . 2011-03-09 08:0120240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\cagicon.exe
    - 2010-02-13 04:50 . 2010-02-13 04:5012800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
    + 2011-03-05 12:31 . 2011-03-05 12:3112800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
    + 2011-03-05 12:31 . 2011-03-05 12:3153248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
    - 2010-02-13 04:50 . 2010-02-13 04:5053248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
    + 2011-03-08 02:05 . 2011-03-08 02:059560 c:\windows\system32\NetworkList\Icons\{D891C3B3-3BF7-4431-9FC1-850715DE7EC8}_48.bin
    + 2011-03-08 02:05 . 2011-03-08 02:054280 c:\windows\system32\NetworkList\Icons\{D891C3B3-3BF7-4431-9FC1-850715DE7EC8}_32.bin
    + 2011-03-08 02:05 . 2011-03-08 02:052456 c:\windows\system32\NetworkList\Icons\{D891C3B3-3BF7-4431-9FC1-850715DE7EC8}_24.bin
    - 2011-03-01 00:19 . 2011-03-01 00:192048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2011-03-14 21:45 . 2011-03-14 21:452048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2011-03-14 21:45 . 2011-03-14 21:452048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2011-03-01 00:19 . 2011-03-01 00:192048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-03-14 21:46 . 2011-03-14 21:46119808 c:\windows\temp\VPN_25DD\0FC343C0.dll
    - 2009-07-14 00:06 . 2009-07-14 01:16850432 c:\windows\SysWOW64\sbe.dll
    + 2011-03-08 23:40 . 2010-12-23 05:28850432 c:\windows\SysWOW64\sbe.dll
    + 2011-03-05 00:06 . 2011-03-05 00:06235168 c:\windows\SysWOW64\Macromed\Flash\FlashUtil10n_Plugin.exe
    - 2009-07-14 00:41 . 2009-07-14 01:16534528 c:\windows\SysWOW64\EncDec.dll
    + 2011-03-08 23:40 . 2010-12-23 05:28534528 c:\windows\SysWOW64\EncDec.dll
    + 2011-03-08 23:40 . 2011-02-19 05:32739840 c:\windows\SysWOW64\d2d1.dll
    - 2011-01-12 13:35 . 2010-11-02 04:35739840 c:\windows\SysWOW64\d2d1.dll
    + 2011-03-08 23:40 . 2010-12-23 05:28642048 c:\windows\SysWOW64\CPFilters.dll
    - 2009-07-14 02:36 . 2011-02-28 23:46703262 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2011-03-14 21:20703262 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2011-03-14 21:20136794 c:\windows\system32\perfc009.dat
    - 2009-07-14 02:36 . 2011-02-28 23:46136794 c:\windows\system32\perfc009.dat
    + 2011-03-08 23:40 . 2010-12-23 06:07723968 c:\windows\system32\EncDec.dll
    + 2011-03-08 23:40 . 2011-02-19 06:36902656 c:\windows\system32\d2d1.dll
    - 2011-01-12 13:35 . 2010-11-02 05:12902656 c:\windows\system32\d2d1.dll
    - 2010-10-26 20:40 . 2010-08-04 07:07961024 c:\windows\system32\CPFilters.dll
    + 2011-03-08 23:40 . 2010-12-23 06:07961024 c:\windows\system32\CPFilters.dll
    + 2009-07-14 05:01 . 2011-03-14 21:45421204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    - 2009-07-14 05:01 . 2011-03-01 00:18421204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2010-12-08 23:58 . 2010-12-08 23:58752640 c:\windows\Installer\5af3d60.msi
    + 2011-03-08 20:20 . 2011-03-08 20:20371272 c:\windows\Installer\{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}\SkypeIcon.exe
    - 2010-12-29 18:52 . 2010-12-29 18:52371272 c:\windows\Installer\{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}\SkypeIcon.exe
    - 2009-11-16 03:17 . 2011-02-10 12:46888080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-11-16 03:17 . 2011-03-09 08:01888080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01272648 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pubs.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46272648 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pubs.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01922384 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46922384 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46845584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\outicon.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01845584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\outicon.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46217864 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\misc.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01217864 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\misc.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46184080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\joticon.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01184080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\joticon.exe
    - 2009-11-16 05:33 . 2011-02-10 12:46159504 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\inficon.exe
    + 2009-11-16 05:33 . 2011-03-09 08:01159504 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\inficon.exe
    + 2009-02-14 11:04 . 2009-02-14 11:04625520 c:\windows\Installer\$PatchCache$\Managed\00002119E20000000000000000F01FEC\12.0.6425\GROOVEWEBSERVICES.DLL
    + 2009-02-12 20:19 . 2009-02-12 20:19688512 c:\windows\Installer\$PatchCache$\Managed\00002119E20000000000000000F01FEC\12.0.6425\GROOVEWEBPLATFORMSERVICES.DLL
    + 2009-03-06 09:33 . 2009-03-06 09:33961888 c:\windows\Installer\$PatchCache$\Managed\00002119E20000000000000000F01FEC\12.0.6425\GROOVEUTIL.DLL
    + 2009-02-14 11:03 . 2009-02-14 11:03337264 c:\windows\Installer\$PatchCache$\Managed\00002119E20000000000000000F01FEC\12.0.6425\GROOVE.EXE
    - 2010-02-13 04:50 . 2010-02-13 04:50223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:08563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2010-02-13 04:50 . 2010-02-13 04:50473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
    + 2011-03-05 12:31 . 2011-03-05 12:31473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
    + 2011-03-14 21:46 . 2011-03-14 21:462240512 c:\windows\temp\VPN_25DD\9218E5A4.dll
    + 2011-03-14 21:46 . 2011-03-14 21:461185288 c:\windows\temp\.unicode_cache_78ae99a9.dat
    + 2011-03-08 23:40 . 2010-12-18 05:302690560 c:\windows\SysWOW64\mstscax.dll
    + 2011-03-08 23:40 . 2010-12-18 05:261034240 c:\windows\SysWOW64\mstsc.exe
    - 2010-01-27 01:07 . 2011-02-11 21:416053536 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    + 2010-01-27 01:07 . 2011-03-05 00:066053536 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    + 2011-03-08 23:40 . 2011-02-19 05:321074176 c:\windows\SysWOW64\DWrite.dll
    - 2011-01-12 13:35 . 2010-11-02 04:351074176 c:\windows\SysWOW64\DWrite.dll
    + 2011-03-08 23:40 . 2010-12-23 06:071118720 c:\windows\system32\sbe.dll
    - 2009-07-14 00:21 . 2009-07-14 01:411118720 c:\windows\system32\sbe.dll
    + 2011-03-08 23:40 . 2010-12-18 06:123138048 c:\windows\system32\mstscax.dll
    + 2011-03-08 23:40 . 2010-12-18 06:081097216 c:\windows\system32\mstsc.exe
    + 2011-03-08 23:40 . 2011-02-19 06:371135104 c:\windows\system32\FntCache.dll
    - 2011-01-12 13:35 . 2010-11-02 05:121540608 c:\windows\system32\DWrite.dll
    + 2011-03-08 23:40 . 2011-02-19 06:371540608 c:\windows\system32\DWrite.dll
    - 2009-07-14 04:45 . 2011-02-28 23:513798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2009-07-14 04:45 . 2011-03-09 08:223798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2011-02-16 18:54 . 2011-02-16 18:544992000 c:\windows\Installer\1d0321f.msp
    + 2011-01-11 22:53 . 2011-01-11 22:531763328 c:\windows\Installer\1d03209.msp
    + 2009-11-16 05:33 . 2011-03-09 08:011172240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\xlicons.exe
    - 2009-11-16 05:33 . 2011-02-10 12:461172240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\xlicons.exe
    - 2009-11-16 05:33 . 2011-02-10 12:461165584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\accicons.exe
    + 2009-11-16 05:33 . 2011-03-09 08:011165584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\accicons.exe
    + 2009-02-14 11:03 . 2009-02-14 11:033070832 c:\windows\Installer\$PatchCache$\Managed\00002119E20000000000000000F01FEC\12.0.6425\GROOVEDOCUMENTSHARETOOL.DLL
    - 2009-11-16 03:08 . 2009-11-16 03:082846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:312846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2011-03-05 12:31 . 2011-03-05 12:312676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-11-16 03:08 . 2009-11-16 03:082676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    - 2009-07-14 02:34 . 2011-03-01 00:1710223616 c:\windows\system32\SMI\Store\Machine\schema.dat
    + 2009-07-14 02:34 . 2011-03-14 21:3010223616 c:\windows\system32\SMI\Store\Machine\schema.dat
    + 2009-11-15 13:25 . 2011-03-09 08:0139946696 c:\windows\system32\MRT.exe
    + 2011-03-08 20:19 . 2011-03-08 20:1918307072 c:\windows\Installer\2f64c.msi
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{d22f6f66-2f47-4184-8625-fbfa4cbdb7ce}]
    2010-11-06 03:142735200----a-w-c:\program files (x86)\OnRPG\tbOnR0.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{d22f6f66-2f47-4184-8625-fbfa4cbdb7ce}"= "c:\program files (x86)\OnRPG\tbOnR0.dll" [2010-11-06 2735200]
    .
    [HKEY_CLASSES_ROOT\clsid\{d22f6f66-2f47-4184-8625-fbfa4cbdb7ce}]
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
    @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
    [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
    2007-06-02 00:08143360----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BitTorrent DNA"="c:\program files (x86)\DNA\btdna.exe" [2010-11-19 323392]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
    "CinemaNowMediaManagerApp"="c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe" [2009-06-11 2088296]
    "HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
    "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
    "ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-08-10 421888]
    "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-12-06 1910152]
    "cwcptray"="c:\program files (x86)\ContentWatch\Internet Protection\cwtray.exe" [2010-11-16 353088]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "00PCTFW"="c:\program files (x86)\PC Tools Firewall Plus\FirewallGUI.exe" [2010-11-29 2676696]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2009-9-15 12862]
    LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe [2011-3-3 201728]
    PacketiX VPN Client Task Tray.lnk - c:\program files (x86)\PacketiX VPN Client English\vpncmgr.exe [2008-5-15 2682880]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2011-01-31 08:4435760----a-w-c:\program files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
    2009-06-24 19:30272952----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
    2009-09-16 01:3372248----a-w-c:\windows\AsScrProlog.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
    2009-09-16 01:333054136----a-w-c:\windows\AsScrPro.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
    2008-07-19 00:52104936------w-c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2Go_Menu]
    2008-06-13 23:11210216------w-c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 dump_wmimmc;dump_wmimmc;c:\hanpurple\elsword\data\GameGuard\dump_wmimmc.sys


    R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys

    R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys

    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys

    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
    R3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\DRIVERS\pctNdis64.sys

    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys

    R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

    R3 X6va003;X6va003;c:\users\Connor\AppData\Local\Temp\003CFBB.tmp

    R3 X6va005;X6va005;c:\users\Connor\AppData\Local\Temp\005845B.tmp

    R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
    R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
    S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys

    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

    S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
    S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
    S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2009-06-11 127352]
    S2 CwAltaService20;ContentWatch;c:\program files (x86)\ContentWatch\Internet Protection\cwsvc.exe [2010-11-16 2109440]
    S2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
    S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640]
    S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-02-25 23680]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
    S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe

    S2 vpnclient;PacketiX VPN Client;c:\program files (x86)\PacketiX VPN Client English\vpnclient.exe [2008-05-15 2478080]
    S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-11-24 127784]
    S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys

    S3 Neo_VPN;VPN Client Device Driver - VPN;c:\windows\system32\DRIVERS\Neo_0014.sys

    S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys

    S3 PCTFW-PacketFilter;PCTools Firewall - PACKET filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter64.sys

    S3 pctNdisMP;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys

    S3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw64.sys

    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys

    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - pctESPInject
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    AkamaiREG_MULTI_SZ Akamai
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
    @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
    [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
    2007-06-01 23:52159744----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.bing.com/?pc=Z023&form=ZGAPHP
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
    LSP: c:\windows\system32\cwalsp.dll
    Trusted Zone: cinemanow.com
    Trusted Zone: real.com\rhap-app-4-0
    Trusted Zone: real.com\rhapreg
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
    DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} - hxxp://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab
    DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} - hxxp://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab
    FF - ProfilePath - c:\users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\ecx7ksuv.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=Z023&form=ZGAPHP
    FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z023&form=ZGAADF&q=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
    FF - Ext: Move Media Player: [emailprotected] - c:\users\Connor\AppData\Roaming\Move Networks
    FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
    FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    FF - Ext: flashget3 Extension: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} - %profile%\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
    FF - Ext: SyncPlaces: [emailprotected] - %profile%\extensions\[emailprotected]
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    WebBrowser-{D22F6F66-2F47-4184-8625-FBFA4CBDB7CE} - (no file)
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet002\services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va003]
    "ImagePath"="\??\c:\users\Connor\AppData\Local\Temp\003CFBB.tmp"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va005]
    "ImagePath"="\??\c:\users\Connor\AppData\Local\Temp\005845B.tmp"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
    c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
    c:\program files\ATKGFNEX\GFNEXSrv.exe
    c:\program files (x86)\Bonjour\mDNSResponder.exe
    c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe
    c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
    c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
    c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
    c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
    c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
    c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe
    c:\program files (x86)\ASUS\ASUS Live Update\ALU.exe
    .
    **************************************************************************
    .
    Completion time: 2011-03-14 17:58:55 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-03-14 21:58
    ComboFix2.txt 2011-03-02 19:28
    ComboFix3.txt 2011-03-01 00:27
    .
    Pre-Run: 137,372,893,184 bytes free
    POST-Run: 137,028,952,064 bytes free
    .
    - - End Of File - - F509B404EEE2E4C542C804E8620E1182
    Please download Rooter and Save it to your desktop.
    • Double click it to start the tool.Vista and Windows7 run as administrator.
    • Click Scan.
    • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
    First time to post:
    Have tried all the above actions to remove Whitesmoke
    At first it looked like Malwarebytes took care of it but Whitesmoke never actually is removed.
    Have tried ComboFix (placed on desktop) and now OldTimer with your suggested fix code.
    Here is the results from OldTimer. Not sure yet if it worked, just trying to capture the text into the string. I will re-post the result if Whitesmoke is finally off my computer.

    Thanks for your time is helping folks on this, it is great that you do that.
    ....................................... ...

    All processes killed
    ========== OTL ==========
    ========== FILES ==========
    File\Folder C:\found.000 not found.
    File\Folder c:\users\Connor\AppData\Local\Temp\00199D8.tmp not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va001\ not found.
    HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va001\\"ImagePath"|"\??\c:\users\Connor\AppData\Local\Temp\00199D8.tmp" /E : value set successfully!
    ========== SERVICES/DRIVERS ==========
    Error: No service named X6va001 was found to stop!
    Service\Driver key X6va001 not found.
    ========== COMMANDS ==========
    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully

    [EMPTYTEMP]

    User: All Users

    User: Anne
    ->Temp folder emptied: 61088 bytes
    ->Temporary Internet Files folder emptied: 119918476 bytes
    ->Java cache emptied: 144187 bytes
    ->Google Chrome cache emptied: 7385685 bytes
    ->Flash cache emptied: 83496 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 56502 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1610 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 122.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 12302011_101001

    Files\Folders moved on Reboot...
    C:\Users\Anne\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS4ZGF6\1053965053[1].htm moved successfully.
    C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS4ZGF6\activityi;src=2542116;type=clien612;cat=chromx;u2=;u1=;ord=1;num=5615028436588[1].htm moved successfully.
    C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CANMWGVQ\cJZKeOuBrn4kERxqtaUH3fY6323mHUZFJMgTvxaG2iE[1].eot moved successfully.

    Registry entries deleted on Reboot...
    4268.

    Solve : Cannot view hidden files.?

    Answer»

    Hi when I go into RIBBON and attempt to view hidden FILES it un-ticks itself. I have gone in file options STILL does not WORK and I have changed the regedit still not working. I had hear this may be caused by a virus so I did a system scan with bitdefender total security 2016 but the problem still persists. OS is win10.What ribbon? What exactly are we talking about?Ribbon as in the one in file explorer.
    ThatAre you logged in as admin?Yes I am admin. I already said I attempted to change it in the ribbon and in file explorer options.Anyone GOT any idea?Okay so seems as though no one knows then...

    4269.

    Solve : Question about ransomeware?

    Answer»

    I've just listened to an item on radio about "ransomware" and the effect it has on pcs attacked by this malware. I gather that it completely locks the pc and demands are made for money to unlock. I appreciate that common sense and good av and malware protection, kept up-to-date, can help avoid problems but if your pc does GET infected what can you do yourself about it? What would be the best course of action - if the SYSTEM is locked then presumably you're stymied?
    There are program that you can download to a USB and use them to start up your PC. If it ever happens to your PC, you will need EXCESS to ANOTHER PC or laptop and a USB stick, preferably a 1GB one.

    Of course, if you only download or access reputable sites and do not click on anything for the sake of it, you'll be fine.

    Safe surfing works wonders. Thanks for comments. This was new to me - the radio report was the first I've heard of it and it does seem to be serious criminality.I have never seen or heard about any sort of ransomeware personally. I've only heard about it on the internet. I don't doubt it exists but there is no more to be worried about than there is in the case of malware infections which destroy everything. Very few of them are difficult to circumvent anyway. I have only heard of one that actually ENCRYPTS the data and tells the user to send money to a certain address to get the key. But iirc the perpetrators were found and are in prison.

    4270.

    Solve : browser redirecting to a site?

    Answer»

    this is what happens, when i type a key word onto the address bar of google chrome.and press enter it directs me to this
    http://www.questbasic.com/b.cgi?bk=H8QuaD58wP9ZQYyXDXDpufl1zTeBcpDHoS4ZrDzh1DMZLDM-JCByOf4SXPJ0TtJcmKW01AKi4xS-ZKb28*yZI8OMOn6laSdo26f3lF8xeXCnnwNUkZw5qFNcA8ONrthKG1EA1Q

    i posted this problem on the browsers area.but they told me my pc is infected.but my esset anti virus doesnt detect any virus.this happened when i DOWNLOADED and install wamp from this site http://www.wampserver.com/en/

    im using windows 7 home PREMIUM 64bit

    and on the OPTION my search is set to google. any one please HELP me fix thisand questbasic.exe is on my processes.and i cant end process.how to fix this??found the folder then deleted it. Do you still NEED help?

    4271.

    Solve : Sony VAIO Shut Down Today...Help?

    Answer»

    Quote

    Also it never asked so I never did reboot. Is this ok?
    Yup, that's ok.

    P2P - I see you have P2P software installed on your machine. (BitLord 2.0) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
    **************************************************
    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    ***************************************************
    Download OTL to your desktop.

    * Open OTL
    * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

    Code: [Select]:OTL

    uURLSearchHooks: H - No File
    BHO: Complitly: {d27fc31c-6e3d-4305-8d53-acdaefa5f862} - c:\users\johnny ola\appdata\roaming\complitly\Complitly.dll
    mRun: [<NO NAME>]

    :COMMANDS
    [resethosts]
    [purity]
    [start explorer]

    * Click Run Fix
    * OTLI2 may ask to reboot the machine. Please do so if asked.
    * Click OK
    * A report will open. Copy and Paste that report in your next reply.
    ****************************************************************
    Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

    link # 1
    Link # 2
    If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Right-click combofix.exe and select Run as Administrator and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix login your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.OK Dave, few things:

    1) PC has been running fine until the issue this week, since, it has been slower and I have heard more grinding, so once we fix this issue, I'd like to know if the PC is fine or if it needs work.

    2) Checked Java, was out of date, now it is up to date.

    3) So can I delete:
    -Java RA
    -OTL
    -Combo fix?

    4) Logs

    OTL
    Quote
    ========== OTL ==========
    ========== COMMANDS ==========
    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully

    OTL by OldTimer - Version 3.2.31.0 log created on 12292011_141813

    Combofix
    Quote
    ComboFix 11-12-29.04 - Johnny Ola 12/29/2011 14:31:52.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1055 [GMT -5:00]
    Running from: c:\users\Johnny Ola\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
    SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\Install.exe
    c:\programdata\pswi_preloaded.exe
    c:\users\Johnny Ola\AppData\Local\assembly\tmp
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))
    .
    .
    2011-12-29 20:18 . 2011-12-29 20:21--------d-----w-c:\users\Johnny Ola\AppData\Local\temp
    2011-12-29 20:18 . 2011-12-29 20:18--------d-----w-c:\users\Guest\AppData\Local\temp
    2011-12-29 20:18 . 2011-12-29 20:18--------d-----w-c:\users\Default\AppData\Local\temp
    2011-12-29 19:18 . 2011-12-29 19:18--------d-----w-C:\_OTL
    2011-12-21 04:56 . 2011-12-21 04:56--------d-----w-c:\program files\iPod
    2011-12-21 04:56 . 2011-12-21 04:56--------d-----w-c:\program files\iTunes
    2011-12-15 01:33 . 2011-11-23 13:372043904----a-w-c:\windows\system32\win32k.sys
    2011-12-15 01:33 . 2011-11-08 12:102409784----a-w-c:\program files\Windows Mail\OESpamFilter.dat
    2011-12-15 01:33 . 2011-10-27 08:013602816----a-w-c:\windows\system32\ntkrnlpa.exe
    2011-12-15 01:33 . 2011-10-27 08:013550080----a-w-c:\windows\system32\ntoskrnl.exe
    2011-12-15 01:33 . 2011-10-14 16:02429056----a-w-c:\windows\system32\EncDec.dll
    2011-12-15 01:33 . 2011-10-25 15:5649152----a-w-c:\windows\system32\csrsrv.dll
    2011-12-15 01:33 . 2011-11-08 14:422048----a-w-c:\windows\system32\tzres.dll
    2011-12-08 18:02 . 2011-12-08 18:02--------d-----w-C:\Temp
    2011-12-08 17:29 . 2011-12-15 18:06--------d-----w-c:\users\Johnny Ola\AppData\Local\LogMeIn Rescue Applet
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-29 19:05 . 2011-10-17 04:18472808----a-w-c:\windows\system32\deployJava1.dll
    2011-12-19 18:59 . 2011-10-07 22:4782400----a-w-c:\windows\system32\drivers\inspect.sys
    2011-12-19 18:59 . 2011-10-07 22:4738616----a-w-c:\windows\system32\drivers\cmdhlp.sys
    2011-12-19 18:59 . 2011-10-07 22:47491816----a-w-c:\windows\system32\drivers\cmdGuard.sys
    2011-12-19 18:59 . 2011-10-07 22:4719600----a-w-c:\windows\system32\drivers\cmderd.sys
    2011-12-19 18:58 . 2011-10-07 22:4733984----a-w-c:\windows\system32\cmdcsr.dll
    2011-12-19 18:58 . 2011-10-07 22:47301224----a-w-c:\windows\system32\guard32.dll
    2011-12-10 20:24 . 2011-10-11 20:0620464----a-w-c:\windows\system32\drivers\mbam.sys
    2011-11-19 21:24 . 2011-10-11 18:18414368----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-05 17:47 . 2011-11-05 17:4711264----a-r-c:\users\Johnny Ola\AppData\Roaming\Microsoft\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
    2011-10-29 23:10 . 2011-10-29 23:100----a-w-c:\windows\system32\ConduitEngine.tmp
    2011-10-26 06:49 . 2011-10-26 06:4986528----a-w-c:\windows\system32\iesysprep.dll
    2011-10-26 06:49 . 2011-10-26 06:4976800----a-w-c:\windows\system32\SetIEInstalledDate.exe
    2011-10-26 06:49 . 2011-10-26 06:4974752----a-w-c:\windows\system32\RegisterIEPKEYs.exe
    2011-10-26 06:49 . 2011-10-26 06:4948640----a-w-c:\windows\system32\mshtmler.dll
    2011-10-26 06:49 . 2011-10-26 06:49161792----a-w-c:\windows\system32\msls31.dll
    2011-10-26 06:49 . 2011-10-26 06:4963488----a-w-c:\windows\system32\tdc.ocx
    2011-10-26 06:49 . 2011-10-26 06:49367104----a-w-c:\windows\system32\html.iec
    2011-10-26 06:49 . 2011-10-26 06:4974752----a-w-c:\windows\system32\iesetup.dll
    2011-10-26 06:49 . 2011-10-26 06:4923552----a-w-c:\windows\system32\licmgr10.dll
    2011-10-26 06:49 . 2011-10-26 06:49420864----a-w-c:\windows\system32\vbscript.dll
    2011-10-26 06:49 . 2011-10-26 06:49152064----a-w-c:\windows\system32\wextract.exe
    2011-10-26 06:49 . 2011-10-26 06:49150528----a-w-c:\windows\system32\iexpress.exe
    2011-10-26 06:49 . 2011-10-26 06:49142848----a-w-c:\windows\system32\ieUnatt.exe
    2011-10-26 06:49 . 2011-10-26 06:4935840----a-w-c:\windows\system32\imgutil.dll
    2011-10-26 06:49 . 2011-10-26 06:4911776----a-w-c:\windows\system32\mshta.exe
    2011-10-26 06:49 . 2011-10-26 06:49110592----a-w-c:\windows\system32\IEAdvpack.dll
    2011-10-26 06:49 . 2011-10-26 06:49101888----a-w-c:\windows\system32\admparse.dll
    2011-10-26 06:48 . 2011-10-26 06:48979456----a-w-c:\windows\system32\MFH264Dec.dll
    2011-10-26 06:48 . 2011-10-26 06:48357376----a-w-c:\windows\system32\MFHEAACdec.dll
    2011-10-26 06:48 . 2011-10-26 06:48302592----a-w-c:\windows\system32\mfmp4src.dll
    2011-10-26 06:48 . 2011-10-26 06:4898816----a-w-c:\windows\system32\mfps.dll
    2011-10-26 06:48 . 2011-10-26 06:482873344----a-w-c:\windows\system32\mf.dll
    2011-10-26 06:48 . 2011-10-26 06:48261632----a-w-c:\windows\system32\mfreadwrite.dll
    2011-10-26 06:48 . 2011-10-26 06:48209920----a-w-c:\windows\system32\mfplat.dll
    2011-10-26 06:48 . 2011-10-26 06:48586240----a-w-c:\windows\system32\stobject.dll
    2011-10-26 06:48 . 2011-10-26 06:48667648----a-w-c:\windows\system32\printfilterpipelinesvc.exe
    2011-10-26 06:48 . 2011-10-26 06:48638336----a-w-c:\windows\system32\drivers\dxgkrnl.sys
    2011-10-26 06:48 . 2011-10-26 06:48478720----a-w-c:\windows\system32\dxgi.dll
    2011-10-26 06:48 . 2011-10-26 06:4837376----a-w-c:\windows\system32\cdd.dll
    2011-10-26 06:48 . 2011-10-26 06:4826112----a-w-c:\windows\system32\printfilterpipelineprxy.dll
    2011-10-26 06:48 . 2011-10-26 06:48258048----a-w-c:\windows\system32\winspool.drv
    2011-10-26 06:48 . 2011-10-26 06:48135680----a-w-c:\windows\system32\XpsRasterService.dll
    2011-10-26 06:47 . 2011-10-26 06:474096----a-w-c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
    2011-10-26 06:47 . 2011-10-26 06:47369664----a-w-c:\windows\system32\WMPhoto.dll
    2011-10-26 06:47 . 2011-10-26 06:47252928----a-w-c:\windows\system32\dxdiag.exe
    2011-10-26 06:47 . 2011-10-26 06:47195584----a-w-c:\windows\system32\dxdiagn.dll
    2011-10-26 06:47 . 2011-10-26 06:47974848----a-w-c:\windows\system32\WindowsCodecs.dll
    2011-10-26 06:47 . 2011-10-26 06:47519680----a-w-c:\windows\system32\d3d11.dll
    2011-10-26 06:47 . 2011-10-26 06:47321024----a-w-c:\windows\system32\PhotoMetadataHandler.dll
    2011-10-26 06:47 . 2011-10-26 06:47189440----a-w-c:\windows\system32\WindowsCodecsExt.dll
    2011-10-17 05:25 . 2006-11-02 10:32101888----a-w-c:\windows\system32\ifxcardm.dll
    2011-10-17 05:25 . 2006-11-02 10:3282432----a-w-c:\windows\system32\axaltocm.dll
    2011-10-14 07:04 . 2011-10-14 07:04377344----a-w-c:\windows\system32\winhttp.dll
    2011-10-14 07:02 . 2011-10-14 07:0236864----a-w-c:\windows\system32\drivers\en-US\http.sys.mui
    2011-10-13 08:09 . 2011-10-13 08:0923552----a-w-c:\windows\system32\lpk.dll
    2011-10-13 08:09 . 2011-10-13 08:0910240----a-w-c:\windows\system32\dciman32.dll
    2011-10-13 08:05 . 2011-10-13 08:0561440----a-w-c:\windows\system32\winipsec.dll
    2011-10-13 08:05 . 2011-10-13 08:05272896----a-w-c:\windows\system32\polstore.dll
    2011-10-13 08:02 . 2011-10-13 08:029728----a-w-c:\windows\system32\TCPSVCS.EXE
    2011-10-13 08:02 . 2011-10-13 08:028704----a-w-c:\windows\system32\HOSTNAME.EXE
    2011-10-13 08:02 . 2011-10-13 08:0211264----a-w-c:\windows\system32\MRINFO.EXE
    2011-10-13 08:02 . 2011-10-13 08:02105984----a-w-c:\windows\system32\netiohlp.dll
    2011-10-13 08:02 . 2011-10-13 08:0210240----a-w-c:\windows\system32\finger.exe
    2011-10-13 08:02 . 2011-10-13 08:0227136----a-w-c:\windows\system32\NETSTAT.EXE
    2011-10-13 08:02 . 2011-10-13 08:0219968----a-w-c:\windows\system32\ARP.EXE
    2011-10-13 08:02 . 2011-10-13 08:0217920----a-w-c:\windows\system32\ROUTE.EXE
    2011-10-13 07:59 . 2011-10-13 07:5965024----a-w-c:\windows\system32\wlanapi.dll
    2011-10-13 07:59 . 2011-10-13 07:59127488----a-w-c:\windows\system32\L2SecHC.dll
    2011-10-13 07:59 . 2011-10-13 07:5968096----a-w-c:\windows\system32\wlanhlp.dll
    2011-10-13 07:59 . 2011-10-13 07:59513536----a-w-c:\windows\system32\wlansvc.dll
    2011-10-13 07:59 . 2011-10-13 07:59302592----a-w-c:\windows\system32\wlansec.dll
    2011-10-13 07:59 . 2011-10-13 07:59293376----a-w-c:\windows\system32\wlanmsm.dll
    2011-10-13 07:59 . 2011-10-13 07:5915181----a-w-c:\windows\system32\gatherWirelessInfo.vbs
    2011-10-13 07:58 . 2011-10-13 07:581401856----a-w-c:\windows\system32\msxml6.dll
    2011-10-13 07:58 . 2011-10-13 07:582048----a-w-c:\windows\system32\msxml3r.dll
    2011-10-13 07:58 . 2011-10-13 07:582048----a-w-c:\windows\system32\msxml6r.dll
    2011-10-13 07:57 . 2011-10-13 07:57218624----a-w-c:\windows\system32\msv1_0.dll
    2011-10-13 07:55 . 2011-10-13 07:5553248----a-w-c:\windows\system32\rrinstaller.exe
    2011-10-13 07:55 . 2011-10-13 07:5524576----a-w-c:\windows\system32\mfpmp.exe
    2011-10-13 07:55 . 2011-10-13 07:552048----a-w-c:\windows\system32\mferror.dll
    2011-10-13 07:52 . 2011-10-13 07:5271680----a-w-c:\windows\system32\atl.dll
    2011-10-13 07:47 . 2011-10-13 07:47160256----a-w-c:\windows\system32\wkssvc.dll
    2011-10-13 07:46 . 2011-10-13 07:4653248----a-w-c:\windows\system32\tsgqec.dll
    2011-10-13 07:46 . 2011-10-13 07:46136192----a-w-c:\windows\system32\aaclient.dll
    2011-10-13 07:44 . 2011-10-13 07:44714240----a-w-c:\windows\system32\timedate.cpl
    2011-10-13 07:36 . 2011-10-13 07:36623616----a-w-c:\windows\system32\localspl.dll
    2011-10-13 07:33 . 2011-10-13 07:33499712----a-w-c:\windows\system32\kerberos.dll
    2011-10-13 07:33 . 2011-10-13 07:33175104----a-w-c:\windows\system32\wdigest.dll
    2011-10-13 07:33 . 2011-10-13 07:339728----a-w-c:\windows\system32\lsass.exe
    2011-10-13 07:33 . 2011-10-13 07:3372704----a-w-c:\windows\system32\secur32.dll
    2011-10-13 07:33 . 2011-10-13 07:33439864----a-w-c:\windows\system32\drivers\ksecdd.sys
    2011-10-13 07:33 . 2011-10-13 07:331259008----a-w-c:\windows\system32\lsasrv.dll
    2011-10-13 07:31 . 2011-10-13 07:316656----a-w-c:\windows\system32\kbd106n.dll
    2011-10-13 07:29 . 2011-10-13 07:2962464----a-w-c:\windows\system32\l3codeca.acm
    2011-10-13 07:29 . 2011-10-13 07:29220672----a-w-c:\windows\system32\l3codecp.acm
    2011-10-13 07:27 . 2011-10-13 07:2730720----a-w-c:\windows\system32\drivers\tcpipreg.sys
    2011-10-13 07:27 . 2011-10-13 07:2725088----a-w-c:\windows\system32\drivers\tunnel.sys
    2011-10-13 07:27 . 2011-10-13 07:27200704----a-w-c:\windows\system32\iphlpsvc.dll
    2011-10-13 07:27 . 2011-10-13 07:2715360----a-w-c:\windows\system32\drivers\TUNMP.SYS
    2011-11-09 16:37 . 2011-10-11 17:40134104----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2011-11-11 59240]
    "ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2011-11-11 59240]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
    "VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
    "VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 36864]
    "VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2007-03-14 2322432]
    "VAIOSurvey"="c:\program files\Sony\VAIO Survey\Vista VAIO Survey.exe" [2006-12-07 577536]
    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
    "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-21 6676808]
    .
    c:\users\Johnny Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-3 2756608]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2007-04-24 00:1998304----a-w-c:\windows\System32\VESWinlogon.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\System32\guard32.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecuteREG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=""
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
    backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
    2011-05-03 15:434321112----a-w-c:\program files\AIM\aim.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
    2011-11-02 04:2559240----a-w-c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\com.apple.dav.bookmarks.daemon]
    2011-11-16 02:5259240----a-w-c:\program files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2011-10-11 20:04136176----atw-c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2011-12-08 06:36421736----a-w-c:\program files\iTunes\iTunesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
    2011-12-24 22:50981680----a-w-c:\program files\Malwarebytes' Anti-Malware\mbam.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickBooks Simple Start]
    2007-01-31 05:59371712----a-w-c:\program files\Intuit\SimpleStartEntice\entice.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunSpySweeperScheduleAtStartup]
    2011-10-26 06:4910752----a-w-c:\windows\System32\msfeedssync.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
    2007-04-06 18:181822720----a-w-c:\windows\SkyTel.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    2008-01-19 07:381008184----a-w-c:\program files\Windows Defender\MSASCui.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
    2009-04-11 06:282153472----a-w-c:\windows\System32\oobefldr.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
    R3 DIRECTIO;DIRECTIO;T:\DirectIo.sys

    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
    R3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [2007-01-26 75952]
    R3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\Sony\Image Converter 3\IcVzMonLauncher.exe [2007-01-26 67760]
    R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 745472]
    R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-01-09 397312]
    R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-01-16 1089536]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
    S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
    S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-12-19 491816]
    S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-12-19 38616]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
    S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
    S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
    S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
    S2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
    S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-01-03 11032]
    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
    S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-04-04 73472]
    S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-04-04 43904]
    S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [2007-04-05 31104]
    S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-02-08 807424]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59]
    .
    2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59]
    .
    2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005Core.job
    - c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04]
    .
    2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005UA.job
    - c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2818425
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    TCP: Interfaces\{20DA44BE-98A1-475D-B8AC-88DF3AD26CDD}: NameServer = 8.26.56.26,156.154.70.22
    TCP: Interfaces\{D83D5627-FB49-437C-B3E7-C61C85550B27}: NameServer = 8.26.56.26,156.154.70.22
    FF - ProfilePath - c:\users\Johnny Ola\AppData\Roaming\Mozilla\Firefox\Profiles\3yu3mje6.default\
    FF - prefs.js: BROWSER.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2818425&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-{7aeb3efd-e564-43f1-b658-5058a7c5743b} - (no file)
    HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
    MSConfigStartUp-COMODO - c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe
    MSConfigStartUp-CPA - c:\program files\COMODO\COMODO GeekBuddy\VALA.exe
    MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-12-29 15:21
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    detected NTDLL code modification:
    ZwClose
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(1112)
    c:\windows\system32\guard32.dll
    .
    - - - - - - - > 'lsass.exe'(1060)
    c:\windows\system32\guard32.dll
    .
    Completion time: 2011-12-29 15:26:46
    ComboFix-quarantined-files.txt 2011-12-29 20:26
    .
    Pre-Run: 208,664,760,320 bytes free
    Post-Run: 207,876,616,192 bytes free
    .
    - - End Of File - - 5F749A562566151542C7F28A2F0CEFC5
    Quote
    I have heard more grinding
    That sounds like either your hard drive or one of the fans.

    Quote
    Java RA
    -OTL
    -Combo fix?
    You can uninstall/ delete Java RA. We'll remove the others when we're finished.

    SysProt Antirootkit

    Download
    SysProt Antirootkit from the link below (you will find it at the bottom
    of the page under attachments, or you can get it from one of the
    mirrors).

    http://sites.google.com/site/sysprotantirootkit/

    Unzip it into a folder on your desktop.
    • Double click Sysprot.exe to start the program.
    • Click on the Log tab.
    • In the Write to log box select the following items.
      • Process << Selected
      • Kernel Modules << Selected
      • SSDT << Selected
      • Kernel Hooks << Selected
      • IRP Hooks << NOT Selected
      • Ports << NOT Selected
      • Hidden Files << Selected
    • At the bottom of the page
      • Hidden Objects Only << Selected
    • Click on the Create Log button on the bottom right.
    • After a few seconds a new window should appear.
    • Select Scan Root Drive. Click on the Start button.
    • When it is complete a new window will appear to indicate that the scan is finished.
    • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
    1) PC tonight has been weird, at times very slow and uncharaterisitcally unresponsive, hope we find out why and stop it.

    2) Scan:

    Quote
    SysProt AntiRootkit v1.0.1.0
    by swatkat

    ******************************************************************************************
    ******************************************************************************************

    No Hidden Processes found

    ******************************************************************************************
    ******************************************************************************************
    Kernel Modules:
    Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
    Service Name: ---
    Module Base: 8C9F0000
    Module End: 8C9FB000
    Hidden: Yes

    Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
    Service Name: ---
    Module Base: 8E3F8000
    Module End: 8E400000
    Hidden: Yes

    ******************************************************************************************
    ******************************************************************************************
    SSDT:
    Function Name: ZwAdjustPrivilegesToken
    Address: 8E6E0F60
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwAlpcConnectPort
    Address: 8E6E114C
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwConnectPort
    Address: 8E6E02C0
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwCreateFile
    Address: 8E6E0BC6
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwCreateSection
    Address: 8E6E097A
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwCreateSymbolicLinkObject
    Address: 8E6E1CC4
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwCreateThread
    Address: 8E6DFCAC
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwLoadDriver
    Address: 8E6E16F6
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwMakeTemporaryObject
    Address: 8E6E0588
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwOpenFile
    Address: 8E6E0DA2
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwOpenProcess
    Address: AC925F3C
    Driver Base: AC925000
    Driver End: AC928000
    Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

    Function Name: ZwOpenSection
    Address: 8E6E0822
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwSetSystemInformation
    Address: 8E6E19E2
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwShutdownSystem
    Address: 8E6E04F2
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwSystemDebugControl
    Address: 8E6E070E
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    Function Name: ZwTerminateProcess
    Address: AC925FE4
    Driver Base: AC925000
    Driver End: AC928000
    Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

    Function Name: ZwTerminateThread
    Address: AC926080
    Driver Base: AC925000
    Driver End: AC928000
    Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

    Function Name: ZwWriteVirtualMemory
    Address: AC92611C
    Driver Base: AC925000
    Driver End: AC928000
    Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

    Function Name: ZwCreateThreadEx
    Address: 8E6E137A
    Driver Base: 8E6D3000
    Driver End: 8E74E000
    Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys

    ******************************************************************************************
    ******************************************************************************************
    No Kernel Hooks found

    ******************************************************************************************
    ******************************************************************************************
    Hidden files/folders:
    Object: C:\Qoobox\BackEnv\AppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cache.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cookies.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Desktop.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Favorites.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\History.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Music.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\NetHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Personal.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Pictures.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Programs.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Recent.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SendTo.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SetPath.bat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartUp.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SysPath.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Templates.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\VikPev00
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
    Status: Access denied

    See Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any security warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan COMPLETES, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
    I unchecked remove found threats, is that ok?I just ran it, found nothing, but it didn't open any log, when I was done it asked if I wanted the 30 day trial.So, how's your computer running now?Pretty good, it got better last Friday.
    Can we call it clear, or is there another scan, any, we can do, just to be sure?Quote
    Pretty good, it got better last Friday.
    Can we call it clear, or is there another scan, any, we can do, just to be sure?
    No. That's it. Your computer is clean. We can now do some cleanup.

    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    *******************************************************
    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    *************************************************
    To remove all of the tools we used and the files and folders they created do the following:
    Double click OTL.exe.
    • Click the CleanUp button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
    ***************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run UNINTERRUPTED until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    **********************************************
    Go to Microsoft Windows Update and get all CRITICAL updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    1) Java is up to date
    2) Typed in combofix as you requested, could not find anything
    3) Ran OTL, cleared a few things, but had to go into downloads, program files, and uninstall to remove everything
    4) TFC problems, first downloaded it, but had an error. Then downloaded it, get it to run, took nearly 10 minutes, did not finish, due to error.

    Question:
    1) Is my PC safe, and clear?
    2) Do I really need TFC, or can I just use CC Cleaner.
    Is it alarming that it did not work?Quote
    Is my PC safe, and clear?
    Yes.
    Quote
    Do I really need TFC, or can I just use CC Cleaner.
    Yes, you can use CCleaner and also do a disk clean up occasionally on your harddrive
    Quote
    Is it alarming that it did not work?
    Not really.
    I will lock this thread. If you need it re-opened, please send me a pm.
    4272.

    Solve : Can't Update Windows Updates?

    Answer»

    Is there still a problem with updating?Yes. It gets to "installing NUMBER 7 of 86" then freezes.I was speaking to a friend last NIGHT who re-furbishes COMPUTERS for schools and he said for almost a month they have been having trouble downloading updates for Windows 7. He said sometimes if you leave the computer on long enough you will get the updates.I'll give it a try. I'll leave it on all night.Just to give you a update, I restarted my computer and STARTED 80 updates over again. It's been 4 hours and its still at "installing update 1 of 80".

    By the way, my updates are DOWNLOADED, they just don't get installed for some reasonThis appears to be a problem with your computer that, unfortunately, I cannot solve remotely. All I can suggest is that you take a look at some of the suggestions here.
    I upgraded to Windows 10 and up updating problems went away. Just thought I'd pass it along.

    I'm glad for you. Thanks for the update.

    4273.

    Solve : Question - Scan a HDD as an external drive??

    Answer»

    Hi,

    I just want to know this answer:
    If a Computer is infected with Viruses. Does it make a difference if: Instead of scanning it directly (With anti-virus tools), Connect it with a USB IDE SATA cable to another clean Computer, and scan it with anti-virus tools (As an external Drive) ?

    I tried it, and when I run a scan from the infected computer, a FULL scan Microsoft Security Essentials takes like 3 or 4 hours to finish, But when CUSTOM (To choose which drive I want to scan) scanned from another computer, it takes only 1h. (and a FULL Scan (will scan also the HDD of the computer, in addition of the external HDD) takes 8h)

    I don't find any information on that online, except some opinions, but... I want an experienced opinion... or Fact =P



    PS: If I posted in the wrong section, please correct it, or let me know.
    I hope I was clear on my question :s

    Thank you! There is a difference between the transfer speed of direct SATA connection to the motherboard and connection via USB enclosure.
    http://www.tomshardware.com/forum/174836-32-sata-transfer-rate
    Quote

    Quote from above website.

    Test 1: Copying a single 5.7GB avi file between the Lacie and my internal Raptor comparing eSATA with USB2 both reading and writing to the Lacie.

    Test 2: Copying 811 smaller files in 2 directories, totalling 4.07GB between the Lacie Drive and my internal Raptor comparing eSATA with USB both reading and writing to the Lacie.
    Test 1 - eSATA Write 1m 32sec, Read 1m 31sec
    Test 1 - USB2 Write 3m 10sec, Read 3m 39sec
    Test 2 - eSATA Write 1m 00sec, Read 1m 20sec
    Test 2 - USB2 Write 2m 57sec, Read 1m 51sec
    I personally have a USB 2.0 WD external 500GB HDD which takes around twice to thrice as long to complete file transfers when compared to my internal HDD, so.. I wouldn't be surprised at the statistics above. Note that the above statistics use external SATA.
    Here are a few professional links concerning SATA vs USB vs eSATA:
    http://www.wfu.edu/~yipcw/atg/disk/usb3/
    http://blogs.gurulabs.com/dax/2009/07/esata-vs-sata-v.html
    http://www.rt.db.erau.edu/655s08/655webUSBSAT/index.htmYou might also try ClamWin Portable, which runs from a flash drive. If you GET it, update its virus definitions before running a virus scan. Ok, I will try it.

    So, If I run a scan of a HDD (That has an OS of another machine) as an external HDD on another machine, it's good ?Quote from: nasroo7 on December 24, 2011, 01:27:55 PM
    So, If I run a scan of a HDD (That has an OS of another machine) as an external HDD on another machine, it's good ?
    Well, running a scan in such a way may be necessary if the OS on the external HDD has already been seriously compromised by a virus to the extent where it is unusable.Quote from: Transfusion on December 23, 2011, 08:47:03 PM
    There is a difference between the transfer speed of direct SATA connection to the motherboard and connection via USB enclosure.

    Not really. Very few magnetic platter drives come very close to saturating ATA-6, which has a max speed of 133mbps. For SATA, while there is a higher maximum throughput, I doubt even a really fast SSD could fully saturate the 480mbps USB.

    The fact is, though, that the test you quote is somewhat stupidand not really a test. All it proves is that two drives from different manufacturers are likely to have different properties. A better test would be to use the same drive INTERNALLY and EXTERNALLY, rather than testing the speed difference between an external drive (which typically are built using 5200RPM drives) compared to a internal drive. Basically, the test isn't testing the bus speed the devices are connected to at all, merely the speeds of the devices.


    Quote
    I personally have a USB 2.0 WD external 500GB HDD which takes around twice to thrice as long to complete file transfers when compared to my internal HDD
    That's because of the drives, not the bus (USB/SATA) being used. I have several IDE enclosures and I used to have a SATA enclosure and there was no marked difference in transfer speeds between when I used a drive in the enclosure or had them inside a computer (with the exception of when connected to a machine that only had USB 1.1, of course). A slow drive was slow regardless of whether it was plugged into the enclosure or not. And faster drives didn't seem affected by being connected via USB.


    Quote
    Here are a few professional links concerning SATA vs USB vs eSATA:
    http://www.wfu.edu/~yipcw/atg/disk/usb3/
    http://blogs.gurulabs.com/dax/2009/07/esata-vs-sata-v.html
    http://www.rt.db.erau.edu/655s08/655webUSBSAT/index.htm

    Of course the ACTUAL Bus speeds between SATA and USB differ. But as far as I'm aware there aren't any drives made yet that can come close to saturating the USB bandwidth.

    As to the topic, though- it's usually better to scan outside the OS, which includes using the drive as an external in another machine. Primarily because if the system is infected you can't trust it for anything, including scans.I love you, BC, you keep continuing to supplement my knowledge and fill in the myriad of gaps that I have. I sincerely wish you a Merry Christmas!
    I do WONDER why http://techreport.com/articles.x/18077 claims that "Every hard drive we've tested saturates [USB 2.0's quoted 480Mbps.]"
    Even if I had a 5200 RPM external drive which presumably would never be able to saturate USB 2.0 it shouldn't spend twice as much time completing file transfers as my internal 5400 RPM drive...You got me thinking about USB 3.0 drives. That means... manufacturers claim that the transfer speed will be faster due to the fact that the enclosure supports USB 3.0(which BTW has a quoted max speed of 5Gbps, or 600MB/s) but in fact all they have to do is slip a 7200RPM drive in, which will clearly be an improvement over a 5200RPM one? And then charge an extreme premium for the USB 3.0 port?

    EDIT: I just realized 480 Mbps is 60 MegaBytes/second. USB 2.0 is half-duplex. So... only 30 MB/s max in both directions? Any 7200 RPM drive will easily saturate that...Quote
    Even if I had a 5200 RPM external drive which presumably would never be able to saturate USB 2.0 it shouldn't spend twice as much time completing file transfers as my internal 5400 RPM drive...
    It will if the external drive sucks.

    Quote
    You got me thinking about USB 3.0 drives. That means... manufacturers claim that the transfer speed will be faster due to the fact that the enclosure supports USB 3.0(which BTW has a quoted max speed of 5Gbps, or 600MB/s) but in fact all they have to do is slip a 7200RPM drive in, which will clearly be an improvement over a 5200RPM one? And then charge an extreme premium for the USB 3.0 port?
    Not really. While it seems that some drives can in fact saturate USB2 (though I'm not clear what my test with an external enclosure and a EIDE drive shows), it's more likely they can stick with the same internal drive and get a speed boost anyway. I think the RPM speed of the drive influences access time more than speed, also.


    Quote
    EDIT: I just realized 480 Mbps is 60 MegaBytes/second. USB 2.0 is half-duplex. So... only 30 MB/s max in both directions? Any 7200 RPM drive will easily saturate that...
    USB has a number of modes, which includes changing the upstream/downstream bandwidth. However even in that light there are a number of drives that come close to and even exceed USB's quoted maximum as a result of that. I've never actually seen these drives, though, and my only sources are the same types of sites that I tend to avoid (such as the one you linked).


    here are the results of some of the tests I did myself just now. using my C: (internal) drive versus one of my external drives.

    My internal drive had a average transfer rate of around 80MB (Megabytes) a second. This would definitely saturate USB2, so I was wrong about that. testing a external USB enclosed drive, it seemed to max out at around 30MB/s. Though it's hard to say what that means, since like the quoted test, my "test" is tainted since my external drive is a different brand, model, and even interface (my external is EIDE whereas the internal drive is SATA). Maxing out at 30 though seems to work with your theory, and it looks like Drives now do exceed USB2.

    Also, further research sort of clears of a confusion I had, the ATA-6 speed is in fact not 133 Megabits per second, but rather megabytes per second, so PATA is truly a 1-gigabit speed.

    That said, we have to wonder how it would apply in this sort of scenario. Obviously for tasks like transferring files and copying files it will be slower, but the fact is the OP is discussing performing a virus scan on the drive. This will almost always be slower when you run it on the system drive since there are any number of programs hooking drive accesses, such as anti-virus programs, which will slow down any and all disk access in that manner. Also, if the drive is infected you've got the issue that malware can be doing the same thing (much like virut, which will infect files as they are accessed)
    That's a good info here!

    Thank you a lot ! and Merry Christmas to all of you Quote
    Obviously for tasks like transferring files and copying files it will be slower, but the fact is the OP is discussing performing a virus scan on the drive. This will almost always be slower when you run it on the system drive since there are any number of programs hooking drive accesses, such as anti-virus programs, which will slow down any and all disk access in that manner. Also, if the drive is infected you've got the issue that malware can be doing the same thing (much like virut, which will infect files as they are accessed)

    Ok... So actually that answers my question on why it takes longer when the HDD is scanned internally, than when it's scanned externally. It makes sense to me now
    And it means also that it's better to scan an infected HDD externally? (More effective?)


    Quote
    My internal drive had a average transfer rate of around 80MB (Megabytes) a second. This would definitely saturate USB2, so I was wrong about that. testing a external USB enclosed drive, it seemed to max out at around 30MB/s. Though it's hard to say what that means, since like the quoted test, my "test" is tainted since my external drive is a different brand, model, and even interface (my external is EIDE whereas the internal drive is SATA). Maxing out at 30 though seems to work with your theory, and it looks like Drives now do exceed USB2.

    Quote
    There is a difference between the transfer speed of direct SATA connection to the motherboard and connection via USB enclosure.

    Actually, If I manage to transfer data from an internal HDD (diskAlpha) to a second internal HDD (DiskBeta), and then transfer the same data between the same disks, but from an internal HDD (DiskAlpha) to an EXternal HDD (diskBeta)
    The time difference would mean that the SPEED transfer data between SATA to SATA and between SATA to USB2.0 would be the reason? since the data was transferred between the two same HDDs, but with a different road?
    4274.

    Solve : Windows Infected... Trojan.Sharpro Nvidia??

    Answer»

    Does CCleaner save a log somewhere? I have the portable version...ComboFix
    NOTE: The computer freezed during the first time (When it asked me to disable Microsoft Security Essentials)


    ComboFix 11-10-28.04 - Nas 10/28/2011 13:00:56.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3957.2544 [GMT -4:00]
    Running from: c:\users\Nas\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\Install.exe
    c:\programdata\DisplayBackupOnline.dll
    c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}
    c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest
    c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome\xulcache.jar
    c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\defaults\preferences\xulcache.js
    c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\install.rdf
    c:\users\Nas\AppData\Local\{08583A71-F8CF-4D82-9516-4C5A8117F2CB}
    c:\users\Nas\AppData\Local\{08583A71-F8CF-4D82-9516-4C5A8117F2CB}\chrome.manifest
    c:\users\Nas\AppData\Local\{08583A71-F8CF-4D82-9516-4C5A8117F2CB}\chrome\content\overlay.xul
    c:\users\Nas\AppData\Local\{08583A71-F8CF-4D82-9516-4C5A8117F2CB}\install.rdf
    c:\users\Nas\AppData\Local\Activision\ActivisionUpdate\Activisionupdt32.dll
    c:\users\Nas\AppData\Local\APPLE\AppleUpdate\Appleupdt32.dll
    c:\users\Nas\AppData\Roaming\Adobe\plugs
    c:\users\Nas\AppData\Roaming\Adobe\shed
    c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}
    c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest
    c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome\xulcache.jar
    c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\defaults\preferences\xulcache.js
    c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\install.rdf
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-28 )))))))))))))))))))))))))))))))
    .
    .
    2011-10-28 17:08 . 2011-10-28 17:0869000----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7876A915-C731-41F0-A6F2-294A2E344B6F}\offreg.dll
    2011-10-28 17:07 . 2011-10-28 17:07--------d-----w-c:\users\Guest\AppData\Local\temp
    2011-10-28 17:07 . 2011-10-28 17:07--------d-----w-c:\users\Default\AppData\Local\temp
    2011-10-28 06:39 . 2011-10-28 06:39--------d-----w-c:\program files (x86)\Common Files\Java
    2011-10-28 06:37 . 2011-10-28 06:37--------d-----w-c:\users\Nas\AppData\Roaming\Sawer
    2011-10-28 06:36 . 2011-10-28 06:37--------d-----w-c:\users\Nas\AppData\Roaming\Juce VST Host
    2011-10-28 06:24 . 2011-10-07 04:168570192----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7876A915-C731-41F0-A6F2-294A2E344B6F}\mpengine.dll
    2011-10-26 21:09 . 2011-10-26 21:0983456----a-w-c:\windows\SysWow64\srrstr.dll
    2011-10-25 17:54 . 2011-10-25 17:54--------d-----w-c:\users\UpdatusUser
    2011-10-25 17:53 . 2011-10-15 08:53837952----a-w-c:\windows\system32\easyupdatusapiu64.dll
    2011-10-25 17:51 . 2011-10-25 17:54--------d-----w-c:\program files\NVIDIA Corporation
    2011-10-25 17:51 . 2011-10-25 17:51--------d-----w-C:\NVIDIA
    2011-10-25 16:57 . 2011-10-25 16:57--------d-----w-c:\program files (x86)\EA Games
    2011-10-25 05:10 . 2011-10-25 05:18--------d-----w-c:\users\Nas\AppData\Roaming\Download Manager
    2011-10-24 20:52 . 2011-10-24 20:52--------d-----w-c:\users\Nas\AppData\Local\Facebook
    2011-10-22 05:36 . 2011-10-22 05:36--------d-----w-c:\program files (x86)\Visicom Media
    2011-10-19 04:30 . 2011-10-19 04:30--------d-----w-c:\program files (x86)\SubtitlesSynch
    2011-10-16 04:26 . 2011-10-16 04:26--------d-----w-c:\program files\CCleaner
    2011-10-15 04:54 . 2011-10-15 04:54321856----a-w-c:\windows\SysWow64\nvStreaming.exe
    2011-10-13 19:52 . 2011-10-13 19:52--------d-----w-c:\users\Nas\AppData\Roaming\Template
    2011-10-13 01:06 . 2011-09-06 03:033138048----a-w-c:\windows\system32\win32k.sys
    2011-10-13 01:06 . 2011-08-17 05:26613888----a-w-c:\windows\system32\psisdecd.dll
    2011-10-13 01:06 . 2011-08-17 04:1975776----a-w-c:\windows\SysWow64\psisrndr.ax
    2011-10-13 01:06 . 2011-08-17 04:24465408----a-w-c:\windows\SysWow64\psisdecd.dll
    2011-10-13 01:06 . 2011-08-17 05:25108032----a-w-c:\windows\system32\psisrndr.ax
    2011-10-13 01:06 . 2011-08-27 05:37331776----a-w-c:\windows\system32\oleacc.dll
    2011-10-13 01:06 . 2011-08-27 04:26233472----a-w-c:\windows\SysWow64\oleacc.dll
    2011-10-13 01:06 . 2011-08-27 05:37861696----a-w-c:\windows\system32\oleaut32.dll
    2011-10-13 01:06 . 2011-08-27 04:26571904----a-w-c:\windows\SysWow64\oleaut32.dll
    2011-10-11 18:46 . 2010-11-30 15:43601424------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2011-10-11 18:45 . 2011-10-11 18:45917840------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{868B6634-68E0-4C71-AC68-723CB703D751}\gapaengine.dll
    2011-10-10 15:09 . 2011-10-10 15:094550304----a-w-c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
    2011-09-28 23:30 . 2011-09-28 23:30--------d-----w-c:\program files (x86)\HyperCam 2
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-10-28 17:09 . 2010-04-24 21:1545056----a-w-c:\windows\system32\acovcnt.exe
    2011-10-28 06:38 . 2010-07-09 18:58472808----a-w-c:\windows\SysWow64\deployJava1.dll
    2011-10-15 08:53 . 2009-10-03 20:021640768----a-w-c:\windows\system32\nvvsvc.exe
    2011-10-15 08:53 . 2009-10-03 20:01539456----a-w-c:\windows\system32\nvhotkey.dll
    2011-10-15 08:53 . 2009-10-03 20:015067584----a-w-c:\windows\system32\nvsvc64.dll
    2011-10-15 08:53 . 2009-10-03 20:013074368----a-w-c:\windows\system32\nvsvcr.dll
    2011-10-15 08:53 . 2009-10-03 20:01222528----a-w-c:\windows\system32\nvmctray.dll
    2011-10-15 08:53 . 2009-10-03 20:01137536----a-w-c:\windows\system32\nvshext.dll
    2011-10-15 08:53 . 2009-10-03 20:0110406208----a-w-c:\windows\system32\nvcpl.dll
    2011-10-15 08:53 . 2009-10-03 14:322808128----a-w-c:\windows\system32\nvapi64.dll
    2011-10-15 08:53 . 2009-10-03 14:3213205312----a-w-c:\windows\SysWow64\nvd3dum.dll
    2011-10-07 04:16 . 2011-09-14 22:178570192----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-09-14 17:09 . 2009-07-14 02:36152576----a-w-c:\windows\SysWow64\msclmd.dll
    2011-09-14 17:09 . 2009-07-14 02:36175616----a-w-c:\windows\system32\msclmd.dll
    2011-08-31 21:00 . 2010-12-16 05:5425416----a-w-c:\windows\system32\drivers\mbam.sys
    2011-08-12 04:10 . 2011-09-13 14:588862544----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{BD9A08B0-0935-49CB-856B-DB9FEFBA5F11}\mpengine.dll
    2011-08-10 02:15 . 2011-08-10 02:1574752----a-w-c:\windows\SysWow64\RegisterIEPKEYs.exe
    2011-08-10 02:15 . 2011-08-10 02:15161792----a-w-c:\windows\SysWow64\msls31.dll
    2011-08-10 02:15 . 2011-08-10 02:15110592----a-w-c:\windows\SysWow64\IEAdvpack.dll
    2011-08-10 02:15 . 2011-08-10 02:1576800----a-w-c:\windows\SysWow64\SetIEInstalledDate.exe
    2011-08-10 02:15 . 2011-08-10 02:1548640----a-w-c:\windows\SysWow64\mshtmler.dll
    2011-08-10 02:15 . 2011-08-10 02:1586528----a-w-c:\windows\SysWow64\iesysprep.dll
    2011-08-10 02:15 . 2011-08-10 02:1563488----a-w-c:\windows\SysWow64\tdc.ocx
    2011-08-10 02:15 . 2011-08-10 02:15367104----a-w-c:\windows\SysWow64\html.iec
    2011-08-10 02:15 . 2011-08-10 02:1574752----a-w-c:\windows\SysWow64\iesetup.dll
    2011-08-10 02:15 . 2011-08-10 02:1523552----a-w-c:\windows\SysWow64\licmgr10.dll
    2011-08-10 02:15 . 2011-08-10 02:15152064----a-w-c:\windows\SysWow64\wextract.exe
    2011-08-10 02:15 . 2011-08-10 02:15150528----a-w-c:\windows\SysWow64\iexpress.exe
    2011-08-10 02:15 . 2011-08-10 02:151427456----a-w-c:\windows\SysWow64\inetcpl.cpl
    2011-08-10 02:15 . 2011-08-10 02:15420864----a-w-c:\windows\SysWow64\vbscript.dll
    2011-08-10 02:15 . 2011-08-10 02:1535840----a-w-c:\windows\SysWow64\imgutil.dll
    2011-08-10 02:15 . 2011-08-10 02:15142848----a-w-c:\windows\SysWow64\ieUnatt.exe
    2011-08-10 02:15 . 2011-08-10 02:1511776----a-w-c:\windows\SysWow64\mshta.exe
    2011-08-10 02:15 . 2011-08-10 02:15101888----a-w-c:\windows\SysWow64\admparse.dll
    2011-08-10 02:15 . 2011-08-10 02:1589088----a-w-c:\windows\system32\RegisterIEPKEYs.exe
    2011-08-10 02:15 . 2011-08-10 02:15222208----a-w-c:\windows\system32\msls31.dll
    2011-08-10 02:15 . 2011-08-10 02:15173056----a-w-c:\windows\system32\ieUnatt.exe
    2011-08-10 02:15 . 2011-08-10 02:1512288----a-w-c:\windows\system32\mshta.exe
    2011-08-10 02:15 . 2011-08-10 02:15114176----a-w-c:\windows\system32\admparse.dll
    2011-08-10 02:15 . 2011-08-10 02:1591648----a-w-c:\windows\system32\SetIEInstalledDate.exe
    2011-08-10 02:15 . 2011-08-10 02:1549664----a-w-c:\windows\system32\imgutil.dll
    2011-08-10 02:15 . 2011-08-10 02:1548640----a-w-c:\windows\system32\mshtmler.dll
    2011-08-10 02:15 . 2011-08-10 02:15135168----a-w-c:\windows\system32\IEAdvpack.dll
    2011-08-10 02:15 . 2011-08-10 02:15111616----a-w-c:\windows\system32\iesysprep.dll
    2011-08-10 02:15 . 2011-08-10 02:1576800----a-w-c:\windows\system32\tdc.ocx
    2011-08-10 02:15 . 2011-08-10 02:1585504----a-w-c:\windows\system32\iesetup.dll
    2011-08-10 02:15 . 2011-08-10 02:15448512----a-w-c:\windows\system32\html.iec
    2011-08-10 02:15 . 2011-08-10 02:1530720----a-w-c:\windows\system32\licmgr10.dll
    2011-08-10 02:15 . 2011-08-10 02:151492992----a-w-c:\windows\system32\inetcpl.cpl
    2011-08-10 02:15 . 2011-08-10 02:15603648----a-w-c:\windows\system32\vbscript.dll
    2011-08-10 02:15 . 2011-08-10 02:15165888----a-w-c:\windows\system32\iexpress.exe
    2011-08-10 02:15 . 2011-08-10 02:15160256----a-w-c:\windows\system32\wextract.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
    @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
    [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
    2007-06-02 01:08143360----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-10-17 5500800]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
    "ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-10-09 6937216]
    "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624]
    "VolPanel"="c:\program files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe" [2008-12-30 237693]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-5 1132472]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 136176]
    R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-12-22 79360]
    R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-12-22 79360]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 136176]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys


    R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys

    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys

    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys

    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

    R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys

    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

    S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-09-11 140672]
    S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe

    S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
    S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys

    S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys

    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys

    S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys

    S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys

    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys

    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-10-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000Core.job
    - c:\users\Nas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-24 20:52]
    .
    2011-10-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000UA.job
    - c:\users\Nas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-24 20:52]
    .
    2011-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 23:18]
    .
    2011-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 23:18]
    .
    2011-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000Core.job
    - c:\users\Nas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-24 03:45]
    .
    2011-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000UA.job
    - c:\users\Nas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-24 03:45]
    .
    2011-09-11 c:\windows\Tasks\One-Click Tweak.job
    - c:\program files (x86)\Advanced PC Tweaker\OneClick.exe [2011-09-11 15:14]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
    @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
    [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
    2007-06-02 00:52159744----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
    "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.bigseekpro.com/hypercam/{7617EF1E-D4A9-4651-9E2C-B654D3D11399}
    mStart Page = hxxp://www.bigseekpro.com/hypercam/{7617EF1E-D4A9-4651-9E2C-B654D3D11399}
    uInternet Settings,ProxyOverride = ;*.local
    TCP: DhcpNameServer = 65.32.5.111 65.32.5.112
    TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\6427565675966696: DhcpNameServer = 212.27.40.241 212.27.40.242
    TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\C496675626F687D214442383: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\D4F657C616: DhcpNameServer = 65.32.5.111 65.32.5.112
    FF - ProfilePath - c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\
    FF - prefs.js: keyword.URL - hxxp://www.scanquery.com/?tmp=nemo_results_removelink&prt=ScnqryPB&keywords=
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 60394
    FF - prefs.js: network.proxy.type - 0
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
    FF - Ext: PC SYNC 2 Synchronisation Extension: [emailprotected] - c:\program files (x86)\Nokia\Nokia PC Suite 7\bkmrksync
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKCU-Run-DisplayBackupOnline - c:\programdata\DisplayBackupOnline.dll
    Toolbar-Locked - (no file)
    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
    AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
    AddRemove-ASUS_ScreenSaver_GSeries - c:\windows\system32\ASUS_ScreenSaver_GSeries.scr
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýU†j]
    @Class="Shell"
    .
    [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýU†j\OpenWithList]
    @Class="Shell"
    "a"="vlc.exe"
    "MRUList"="a"
    .
    [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\SecuROM\License information*]
    "datasecu"=hex:5f,c0,02,a7,b9,b5,32,30,09,db,e0,b1,67,ec,2d,bf,b4,ca,cd,08,42,
    6c,f9,29,62,04,1f,e3,1f,f2,59,ed,b3,55,88,58,75,cf,c5,1e,0e,24,48,72,eb,39,\
    "rkeysecu"=hex:1e,87,b4,a3,5d,ca,24,e3,33,c6,f6,5f,28,f5,86,96
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Bonjour\mDNSResponder.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
    c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe
    c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
    c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
    .
    **************************************************************************
    .
    Completion time: 2011-10-28 13:14:15 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-10-28 17:14
    .
    Pre-Run: 42,653,626,368 bytes free
    Post-Run: 42,405,965,824 bytes free
    .
    - - End Of File - - BD0511F92914382D46D414936F4C38BB
    HEre is it...
    I finished with those one... But couldn't find a log for CCLeaner... do you know if it saved somewhere?

    Thank youNo need for CCleaner log.


    ESET Online Scan

    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    So, I scanned with ESET.
    The first time, ESET found one thread to remove, but when I wanted to save a log, Windows crashed...
    So I restarted Windows, and did another scan 5min later.... But he found more things...


    C:\Program Files (x86)\Advanced PC Tweaker\AdvancedPCTweaker.exea variant of Win32/Adware.AdvPCTweak application
    C:\Qoobox\Quarantine\C\ProgramData\DisplayBackupOnline.dll.vira variant of Win32/Kryptik.UNZ trojan
    C:\Qoobox\Quarantine\C\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest.virWin32/TrojanDownloader.Tracur.F trojan
    C:\Qoobox\Quarantine\C\Users\Nas\AppData\Local\Activision\ActivisionUpdate\Activisionupdt32.dll.vira variant of Win32/Kryptik.UNZ trojan
    C:\Qoobox\Quarantine\C\Users\Nas\AppData\Local\Apple\AppleUpdate\Appleupdt32.dll.vira variant of Win32/Kryptik.UNZ trojan
    C:\Qoobox\Quarantine\C\Users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest.virWin32/TrojanDownloader.Tracur.F trojan
    C:\Users\Nas\AppData\Local\Google\Chrome\User Data\Default\Default\dlihhkfjijkboimenpffikpdeinlfjnp\contentscript.jsWin32/TrojanDownloader.Tracur.F trojan
    C:\Users\Nas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\34584228-2f069fa4Java/Agent.AC trojan
    C:\Users\Nas\Desktop\SAVE\Nas\Hack\ophcrack-win32-installer-3.3.1.exemultiple threats
    C:\Users\Nas\Downloads\AdvancedPCTweaker.exea variant of Win32/Adware.AdvPCTweak application
    C:\Users\Nas\Downloads\avc-free(2).exeWin32/OpenCandy application
    C:\Users\Nas\Downloads\cnet_mp3gain-win-1_2_5_exe.exea variant of Win32/InstallCore.D application
    C:\Users\Nas\Downloads\cnet_SubtitlesSynchSetup_exe.exea variant of Win32/InstallCore.D application
    C:\Users\Nas\Downloads\Fl.Studio.9.Prensboard.Com.rarWin32/OpenCandy application
    C:\Users\Nas\Downloads\packenergieettechnologieV22011EXIT.rara variant of Win32/Keygen.AS application
    C:\Users\Nas\Downloads\packenergieettechnologieV22011EXIT.rar.001.exea variant of Win32/Keygen.AS application
    C:\Users\Nas\Downloads\scripts_2010_by_leo.zipmultiple threats
    C:\Users\Nas\Downloads\slg.ab.rara variant of Win32/HackTool.Patcher.D application
    C:\Users\Nas\Downloads\software_informer.exeprobably a variant of Win32/SWInformer application
    C:\Users\Nas\Downloads\Fl Studio 9\flstudio_9.0.exeWin32/OpenCandy application
    C:\Users\Nas\Downloads\slg.ab\slg.ab\Patch\Patch.exea variant of Win32/HackTool.Patcher.D application
    C:\Users\Nas\Downloads\slg.abrio\slg.abrio\Patch\Patch.exea variant of Win32/HackTool.Patcher.D application
    C:\Windows\System32\srrstr.dlla variant of Win32/Kryptik.UNZ trojan
    C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].caba variant of Win32/Adware.OneStep.Z application
    C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\upgrade[1].caba variant of Win32/Adware.OneStep.Z application
    C:\Windows\SysWOW64\srrstr.dlla variant of Win32/Kryptik.UNZ trojan
    C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].caba variant of Win32/Adware.OneStep.Z application
    C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\upgrade[1].caba variant of Win32/Adware.OneStep.Z application
    Save these instructions so you can have access to them while in Safe Mode.

    Please click here to download AVP Tool by Kaspersky.
    • Save it to your desktop.
    • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    • Double click the setup file to run it.
    • Click Next to continue.
    • Accept the License agreement and click on next.
    • It will, by default, install it to your desktop folder. Click Next.
    • It will then open a box There will be a tab that says Automatic scan.
    • Under Automatic scan make sure these are checked.
      • Hidden Startup Objects
      • System Memory
      • Disk Boot Sectors.
      • My Computer.
      • Also any other drives (Removable that you may have)[/color]
      Leave the rest of the settings as they appear as default.
      • Then click on Scan at the to right hand Corner.
      • It will automatically Neutralize any objects found.
      • If some objects are left un-neutralized then click the button that says Neutralize all
      • If it says it cannot be neutralized then CHOOSE the delete option when prompted.
      • After that is done click on the reports button at the bottom and save it to file name it Kas.
      • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

        Note: This tool will self uninstall when you close it so please save the log before closing it.
      Hi,

      I'm sorry I didn't reply sooner.
      But actually I already ran this tool on another computer, and the scan took 24h to finish, and because I work with my laptop (From 9am to 8pm), I procrastinated to run it... And now it's been almost two months...
      What should I do ?
      Run it anyway? Or start over?

      Actually, the computer run fine, and there is no visible sign of infection.

      What is your advice?

      Thank you for all your help! You make the world a better place ! Quote
      Actually, the computer run fine, and there is no visible sign of infection.
      Sorry. I misunderstood. In that case we can do some cleanup.

      To uninstall ComboFix

      • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
      • In the field, type in ComboFix /uninstall


      (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

      • Then, press Enter, or click OK.
      • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
      *********************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how OFTEN you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      *********************************************
      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
      **********************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      OK, great!
      I try all of that.

      Do I absolutely have to uninstall combofix?

      And after I run all of that... I'm done with this laptop?
      there is no need of any log posting?

      Quote
      Do I absolutely have to uninstall combofix?

      And after I run all of that... I'm done with this laptop?
      there is no need of any log posting?
      Yes, you should uninstall ComboFix. You no longer need it and it should not be used unless an expert is helping your.
      You are done. There are no other logs to post. I will lock this thread. If you need it re-opened, please send me a pm.
      4275.

      Solve : 'Your computer is not protected!'?

      Answer»

      My friend has just rung and she is really spooked. She was sending an email off to someone, finished that, then a big square came up on the screen. A voice actually spoke and said 'Your computer is not protected. To fix this problem go to LINK removedand disappeared! Has anyone heard of this happening? Should she be really concerned (which she is)?[/color]Probably not a GOOD idea to leave that link there.
      Good idea! I have asked to have the link REMOVED, but hope the query will stay there.If my computer started talking to me, I'd either run a virus scanner or see a doctor. Your friend should start a NEW thread on this site and run a few scans just to make sure.Aha! I have discovered the method. It is an automated Skype call, see link (not dangerous) http://nakedsecurity.sophos.com/2011/09/19/automated-skype-calls-spread-fake-anti-virus-warning-video/ ....n it happening on a You Tube clip. At least it's not a virus.... or seems so. Any time you get a message like "'Your computer is not protected." and it directs you to a link you can be almost 100% sure there some MALWARE involved.No, it seemed to be computer protection software. Just a sales pitch.Quote

      Just a sales pitch
      Anytime we see that it's scareware.
      4276.

      Solve : how do I get driver robot off my computer????

      Answer»

      I do not KNOW who in my family put this program on our desktop (hp windows vista)
      but I did LOOK up what files are in it and wow takes up a lot of space, I don't know how to get it all off. I tried uninstalling it.
      There are so many files and some show up as windows this and that.
      What is this? and how can I get rid of it safely?

      thanks
      Can you SEE it in Start, All Programs. Sometimes they have their own uninstaller. It was probably loaded with some other SOFTWARE.

      4277.

      Solve : Unreal situation with ASPIRE M?

      Answer»

      Hello,

      My problem with laptop acer aspire M is kinda weird. I took the comp from my gf (idk how many days she didnt shutdown it, even weeks or months) and i shutdownit then a few hours later i lunched it and computer started to work slowly. But its unreal slow, its hard to open any FILE, even cmd but SOMETIMES its like he wake up and starting work normally. I tried everything what i know. I cant just format and install windows 7 again COS theres no partition recovery and i don't have recovery disks, also theres a lot of important data.

      What i already discovered:
      - explorer.exe randomly stopping work
      - most ussage is dwm.exe ( i shutdown it and STILL problem)
      - sometimes theres icon with information "intel rst stopped working" and computer then working normally. Rst is Intel Rapid Storage Technology, i tried to shutdown it in mscofing on start but theres still problem.
      - temperature of ram and processor are OK (max 5-30%).
      - if comp working normally (1-2mins) and i open anything like chrome+youtube its like something start work in background and slow him, if i watch hd video then every few seconds my mouse frozen for a 0,5sek or something and i hear that the music in speakers crash.

      What i already done:
      -scanned by avira
      -scanned by malwarebytes
      -scanned by hijackthis (adding logs)
      -scanned by securitycheck (adding logs)
      -scanned by adwclear
      -used ccleaner
      -scanned by hdtune (adding photos cos i cant make printscrean on deadcomp)
      -tryied to find anything in autorunsc microsoft tool that i downloaded but shiet

      Please find any way to help me bros!

      [attachment deleted by admin to conserve space]Looks like that HDD is on it's last legs...

      Pull it out of there and connect it as a slave to a working PC to retrieve any important data...

      4278.

      Solve : Help with installing a free antivirus offline...?

      Answer»

      I need to install an antivirus on a laptop that does not have INTERNET CONNECTION. I need to transfer this file to it via pen drive.

      I have tried various antiviruses like Avast, Bitdefender but these require internet connection during installation. What can I do?If it doesn't have internet connection you shouldn't need an AV. Do you intend to go on-line after the AV is installed? What OS is on that computer?Most, if not all antivirus producers make offline installers available, for EXAMPLE

      Avast:
      https://www.avast.com/download-software

      Bitdefender:
      http://www.bitdefender.co.uk/support/how-to-install-bitdefender-2015-using-the-offline-installation-kit-1330.html

      Eset:
      http://support.eset.com/kb2885/?locale=en_US

      Google "product name offline antivirus installer", to find others, but be aware it is safest to get these things direct from the app official website.

      Save offline installer to a pen drive or burn to a CD-ROM or DVD-ROM to install on offline machine.



      ^Yes you're RIGHT, after this starting this thread I immediately tried GOOGLING one and found Avast on FileHippo.

      Thanks

      4279.

      Solve : Help !! ReImage has taken over our PC?

      Answer»

      Can anyone help me get this fecking ReImage MONSTER off my PC !!
      It has completely taken over our PC and even prevents us from talking via Skype to our son in Florida .

      ReImage seems to grow , very fittingly , like a CANCER !!

      It can't be removed using the usual route of program removal as it doesn't even seem to exist according to the PC searches . Even when I TRY finding programs to try off the HippoDownload site it ReImage somehow BLOCKS every attempt to search for a fix .... It just keeps opening LOADS of different Windows until the PC CRASHES or freezes ...


      Can someone please HELP and send me a PM with some advice ?
      https://malwaretips.com/blogs/remove-reimage-repair/Thanks . I'll give it a try but everything I try to load up or install is immediately taken over by ReImage.

      I have no idea how they're allowed to do this to our PCs . ... If they had a local branch office I'd be in there causing some serious restructuring of their building !Thanks, Allan. Zincubus, you may have to do the uninstall in Safe Mode.Ah ... I'll try that tomorrow if I get chance ... I tried downloading the adwCleaner program but the PC froze as I CLICKED on the link and restarted .

      I actually think the ReImage software has evolved and improved since the days of the advice threads I've been directed to by your fellow forum users .I've tried downloading Hitman pro and CWD CLEANER but ReImage prevents the PC from downloading / installing either /both programs by opening new windows advertising ReImage software options and then FREEZES the PC completely and then restarts the computer !!!Download them on another computer and transfer them to the infected computer.

      4280.

      Solve : Windows 7 virus cant find D drive?

      Answer»

      Hi, I have a dell notebook with Windows 7 Ultimate. Its infected with a virus whic has shut down the firewall and all anti virus programs. the D drive showed 0 files/empty, but when i tried to scan the drive, it was full.
      The D drive is HIDDEN, now I CANT even get it to BOOT = just a black screen. I cant even get it to boot from an external drive using USB port! Help, PLEASE...
      Thanks!
      JMDid you TRY booting in Safe Mode?

      4281.

      Solve : Too many file threats?

      Answer»

      Quote

      I apologise for taking up your time.
      Not a problem. I love doing this. Is everything good with your computer now?Quote
      [.ShellClassInfo]
      [emailprotected]%SystemRoot%\system32\shell32.dll,-21769
      IconResource=%SystemRoot%\system32\imageres.dll,-183

      [.ShellClassInfo]
      [emailprotected]%SystemRoot%\system32\shell32.dll,-21799

      Above are the two ini files on my desktop (called desktop.ini)

      Well yes, but not happy about the two files above being on my desktop really.

      What about the jrt text and esetmart... etc - just delete?

      Just one last question which is relating to Win 10, in Win 7 you could go into msconfig and start and delete anything you don't want STARTING up (some programs PUT themselves on there!) This Win 10 has a different set up - you just disable them?? Here's what I have on my currently, can any of them come off there do you think?

      [attachment deleted by admin to conserve space]Click Start> Computer> right click the C Drive and choose Properties> enter
      Click Disk Cleanup from there.



      Click OK on the Disk Cleanup Screen.
      Click Yes on the Confirmation screen.



      This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
      ***************************************
      This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
      This is a very CRUCIAL step so make sure you don't skip it.
      Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

      Double-click Delfix.exe to start the tool.
      Make sure the following items are checked:
      • Activate UAC (optional; some users prefer to keep it off)
      • Remove disinfection tools
      • Create Registry backup
      • Purge System Restore Points
      • Re-set system settings
      Now click "Run" and wait patiently.
      Once finished a logfile will be created. You don't have to attach it to your next reply.
      ********************************************
      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      Quote
      Click Start> Computer> right click the C Drive and choose Properties> enter
      Click Disk Cleanup from there.

      Click OK on the Disk Cleanup Screen.
      Click Yes on the Confirmation screen.
      I had to find another way of cleaning up as your instructions were not for Windows 10, but everything disappeared as you said.
      I had trouble with WOT, as it does not work with Windows 10, (I got an error message)
      It won't work with Edge https://www.mywot.com/en/forum/58220-mywot-for-windows-10-s-edge-browser and I am not using Chrome or Firefox.That's very possible that some programs won't run on Windows 10. It remains to be seen if they will be updated. OK and thanks, Dave
      You're welcome. I will lock this thread. If you need it re-opened, PLEASE send me a pm.
      4282.

      Solve : Malware Bytes & emergency update?

      Answer»

      my inbox has a message about MB's. emergency update concerning a threat, & they SUGGEST new installs for protection. Is this real, or a scam ? do the suggested updates COST anything ?SOUNDS like a scam. Rule of thumb is if any E-mail gives you a link and TRIES to get you to go to it, it is a scam.

      4283.

      Solve : Malwarebytes Restore Browser Page??

      Answer»

      I have recently installed Malwarebytes and ran a couple of scans with it last NIGHT. It has only found two PUPs (That I qurantined) and nothing else so nothing really serious. I try to BROWSE with Firefox this morning and I recieved this page.

      https://www.malwarebytes.org/restorebrowser/index.html?gd=&ctid=CT3319613&octid=EB_ORIGINAL_CTID&ISID=MAD8C5E6E-38AD-43F4-8882-886428E16D57&SearchSource=55&CUI=&UM=5&UP=SP6F33A9C3-4797-4240-8BB9-45CB8480CBC0&SSPV=

      It tells me that I potentially have infections on my browser that has made changes to my system. It has given me instructions on manually altering them but I decided it would be better to seek advice from more experienced users here who may interpert these instructions better than me and know what to do.

      Is this something I should not ignore? If not, what would occur if I decide to let these potential infections in my Firefox browser stay?

      What other browsers do yhoou have? Do they work?
      Iff you install FireFox again, it should save your settings.I have no other browsers on this PC. I do have a laptop that has both Firefox and Google Chrome but I do not use that one as much as this PC.

      Do you reccomend uninstalling and then a re-install? Since you posted in our malware forum I suggest you ignore advice from anyone except Super Dave, our malware specialist.Ok. Should I PM him?No, you should wait until he responds.You can EITHER FOLLOW the advice or uninstall and re-install FF. It was just a warning that the infections may have altered the settings in FF.Ok thanks.Let me know if you have more problems.

      4284.

      Solve : Please help me clean my daughters laptop?

      Answer»

      You're welcome. I will LOCK this THREAD. If you NEED it re-opened, PLEASE send me a pm.

      4285.

      Solve : Free Virus Protection.?

      Answer»

      Dell desktop PC running Windows 8.1 with malwarebytes.

      My free Mcafee virus protection is about to run out, has anyone got a link to a decent free virus protection.

      Many THANKS.Windows 8.1 comes with its own AV called Windows Defender. Just uninstall McAfee and enable WD and you're good to go.Cheers for speedy reply, all done and SORTED, is there any other protection worth downloading to run along side it or should that be ok. Thanks,You can INSTALL MalwareBytes from here. There is a free trial period which enables MBAM to ACTIVELY scan your computer full-time. After the trial period is over you will need to scan your computer periodically.

      4286.

      Solve : Help with RCA Apollo?

      Answer»

      Hi I bought a cheap RCA appolo 2 in 1 to use for small time things, t caught a nasty virus and won't work anymore. So I let it sit, until my vaio got broken last NIGHT. Now I need some help with RCA tablet/laptop. I don't remember what virus it had but this is where I'm at, all the help I got online FAILED and it got to the point I turned it off once and when I booted it back up it gives me a blank black screen after the logo. Now if I touch the screen or move the mouse you can see the clicker with an HOURGLASS next to it so stuff is happening there for sure. But nothing else. So I tried to reset it, and then to totally reset it. It works to almost the end and then gives me and error saying it can't be reset. I had never made a save point on it either so I can't load it back to a previous point. Can anyone help me with this?? Please. Can you boot in Safe Mode?I deleted my post. Sorry.Quote from: Geek-9pm on MAY 31, 2016, 05:07:36 PM

      I deleted my post. Sorry.
      I know you regulars are TRYING to help and it's not a problem for me.
      4287.

      Solve : Phone call from Microsoft 2nd time??

      Answer»

      I received a phone call today (same type of call as a couple of months ago) from someone claiming that Microsoft has been receiving several error reports from my computer. He guided me to my event viewer log to show me the errors etc. 2853 of them as you can see in the attached screen shot. Then he guided me to:

      https://secure.logmeinrescue.com/Customer/Code.aspx

      Then he asked me to enter a 6 digit code into the box and I refused, then hung the phone up.

      This just smells fishy to me. Could this be legit or some scammer trying to gain ACCESS to my computer?

      Funny thing is that I got this same type call (even from the same person I believe) a couple of months ago when I was running Windows 7. I have since upgraded to Win 10 with no problems.

      And if this is legit, then how do I prevent all these errors being created and sent to Microsoft?

      As always, thanks for any help.

      Mike



      [attachment deleted by admin to conserve space]Also my CALLER ID reports this call as being an individual (name is displayed) in 443 area code. I have the full name and number if needed.It is a scam. They know nothing about your system and they aren't Microsoft. The events are standard log MESSAGES written by MANY Windows components. The scam involves installing malware onto your system (backdoor remote-access trojans, I presume) in order to (presumably, again) get details like your bank information by looking through the data on your PC. Your phone number wouldn't be in the error reports! That's what I expected and I'm glad I didn't bite the bait. But I'm sure there are others that will. I've got this caller ID information so should I report it, and if so how / where?

      Thanks BC!This is a really well known scam. The callers use random dialling systems. The caller doesn't know you or your computer. There is no point in reporting it to anyone. The call centre is in India or the Philippines. Nobody will do anything.Area code 443 is from the Maryland state but it most CERTAINLY is a scam.The scammers often use caller ID spoofing so the victim sees an area code in their own country.

      4288.

      Solve : Infection damaged functionality of internet?

      Answer»

      So I believe I cleared it all out because the internet is the only issue so maybe the damage was left over. I can only RUN the internet on the Tor BROWSER now. When I tried mini TOOLBOX it says this
      "the procedure entry point DnsGetPolicyTableInfo could not be located in the dynamic link library C:/Windows/SYSTEM32/NETIOHLP.DLL"
      "the procedure entry point DNSResolverOp could not be located in the dynamic link library C:\Windows\SysWOW64\ipconfig.exe"

      I tried disabling the connection and reenabling it. I also tried reinstalling the NETWORK drivers.

      I want to avoid refreshing/reseting my computer if I can..partly to be more an advanced user as I'm always LOOKING to learn new things on the computer and also because it's a complete pain to reinstall everything
      What was your initial problem?

      4289.

      Solve : zone alarm software not compatible with Vista Home Basic ??

      Answer»

      Zone Alarm SECURITY suite works on my XP PC right now, but will not work with my Vista PC even if it says Vista ready. Does that mean that I NEED to upgrade to Home Premium or ULTIMATE Vista maybe ? I talked to ZA. support they said to DOWNLOAD their lasted updated version which I did , but got the same results. I all ready bought this second archive ZA. version, so it would be great to get it run like my other XP ZA version running now If you can't get it to work on Vista you could always download and install MicroSoft Security Essentials ( below) It's free and very good. It's all I use on all my computers.
      MicroSoft Security Essentials All versions and all LANGUAGES.

      4290.

      Solve : Seems as though Firefox is now being targeted by phishers?

      Answer»

      Just sharing this here to bring to the attention of all. I suspect the attachment has a payload to it to infect Firefox or the system as a whole, notice the URL and patch are not from Mozilla but instead eekumyoutube ( dot ) org. I was at Wowhead looking up a Reins of the swift Spectral Tiger Mount when all of a sudden one of the ads in the corner of wowhead took over and brought me to what you see in this screenshot. This is the first time ever i have seen Firefox targeted to try to trick someone into running a so called "patch". System I am on has no infections. AVG is clean and Malwarebytes shows clean to, so thats why I am thinking there is a rogue ad associated with wowheads website that trying to get people to click and infect themselves if on firefox. Perhaps this phishing is using the browser detection script in which depending on browser they have a number of different payloads to infect you with.

      I took a break from programming in C++ and checked out FACEBOOK and then saw this that caught my attention and then the ultra rare mount I decided to look up and then thats when I got hit with this redirect from wowhead. This link here is the article that I was checking out which was kind of interesting. http://www.gamespot.com/gallery/15-crazy-world-of-warcraft-facts-that-will-impress/2900-678/?ftag=ACQa2186e3&vndid=1852765721&ttag=gs-fb-834&nan_pid=1852765721

      Decided to go back to this URL path to see if I can look further into it and its now hidden as if its a 1 time shot, dynamic URL path link, 1 time try to infect and then kill the path possibly to hide its rogue intentions of this website. Interesting! Second screenshot shows me trying to get back to it to poke AROUND and its gone.




      [attachment deleted by admin to conserve space]This is the type of stuff that IMO makes using adblock/uBlock worth violating the implicit social contracts of website advertisements.Another attempt to infect me. This came thru from facebook. This time I wanted to see what the payload was and so I agreed to download it, but I didnt run it. I then ran virus scan with AVG on it as well as malwarebytes and it says the file is safe. NICE!!! Not going to run that EXE because I know better, but its flying under the radar of antivirus as well as malwarebytes in patch EXE form. Perhaps once it infects it would then detect it. Not going to run it to find out.

      More screenshots and different site with same type of emergency patch junk. This time I viewer the HTML source to see what additional is going on with it. A browser detect is present as seen in source to page.

      Note: File size 338k from other site and 482k from this one...

      [attachment deleted by admin to conserve space]Opened up the EXE in a hex editor to see whats inside without running using FlexHex.

      Screenshots of some of its intent. If anyone wants the Hex dump to dig into I have a 15MB PDF of it too. Just saying in CASE anyone out that is interested in this sort of thing.

      [attachment deleted by admin to conserve space]pic 2 of hex

      [attachment deleted by admin to conserve space]last pic of SECTION of hex that caught my attention.

      [attachment deleted by admin to conserve space]putting in the same URLs, I can't get the page to load at all. First site is gone now entirely and the second one is only a blank page.

      I'd be surprised of the program wasn't a .NET Executable. It seems oddly common to use a .NET program for this sort of thing.

      It's actually quite common to post such programs as "tools" or "utilities" on game forums. It's common for Minecraft, for example, a user will post tools claiming to give the person full admin access to any server, for example, then steal private information. The fun part is that since they are .NET they are fairly easy to decompile; and while the more clever ones will encrypt the password it's dead-simple to just remove the decryptor and run it separate from the malicious software to get things like E-mail passwords, as they need to have SMTP passwords in the file to send their sweet sweet private info to. In one case the user had even used their own personal E-mail, (connected to paypal, amazon, Steam, Facebook, etc.) so I went ahead and E-mailed his family members from his account confessing some rather questionable feelings. Let's just say things must have been VERY awkward between himself and his sister for a while. Quote

      In one case the user had even used their own personal E-mail, (connected to paypal, amazon, Steam, Facebook, etc.) so I went ahead and E-mailed his family members from his account confessing some rather questionable feelings.

      Laughing so hard, but yes in order to authenticate the info would be in the source. Shaking my head why they didnt just use an alias to stay hidden. Although to have an alias paypal I suppose they would have had to have had a stolen identity or some means of creating a alias that appears to be a real person with the rabbit hole going deeper into someone opening an account with a bank with fake id / stolen identity etc.

      Does .Net hide better against antimalware and antivirus's?

      Maybe I'm wrong, but I thought the basis of .Net was to make for better healthier programs that wont BSOD systems etc. Memory managements and tighter execution layer controls etc. So I always thought that if you want to make a program that is going to be naughty it was best to code it up in something that wasnt based around .Net that more readily would allow for you to target memory addresses outside of where the program should be operating etc and overflow conditions etc.Quote from: DaveLembke on July 05, 2016, 01:40:29 PM
      Laughing so hard, but yes in order to authenticate the info would be in the source. Shaking my head why they didnt just use an alias to stay hidden. Although to have an alias paypal I suppose they would have had to have had a stolen identity or some means of creating a alias that appears to be a real person with the rabbit hole going deeper into someone opening an account with a bank with fake id / stolen identity etc.

      For the most part they seem to be teenagers. I'm not certain what their goals are but in terms of Minecraft they were just trying to steal username/passwords. I don't know how those are valuable given that they can just be password reset and the MC username/password doesn't give access to the connected E-mail (or even let you know what that e-mail is).

      Quote
      Does .Net hide better against antimalware and antivirus's?
      The .net framework includes a lot of LIBRARY functions for features such as encryption. Typically the .NET program will have an encrypted resource which it decrypts, saves as an executable, and runs. Sometimes that inner executable is a straight-up RAT but other times it's another .NET program with the actual payload (eg. trying to read a password file and E-mail it).

      Quote
      Maybe I'm wrong, but I thought the basis of .Net was to make for better healthier programs that wont BSOD systems etc. Memory managements and tighter execution layer controls etc. So I always thought that if you want to make a program that is going to be naughty it was best to code it up in something that wasnt based around .Net that more readily would allow for you to target memory addresses outside of where the program should be operating etc and overflow conditions etc.
      Only driver software can BSOD. Running a .NET Executable doesn't "sandbox" it in any way beyond what would happen for a typical executable. unsafe{} and unchecked{} code blocks can be used to run C# code that uses pointers, pointer arithmetic, unbounded arithmetic operations, unchecked array access, etc. Win32 processes cannot access memory outside of their virtual address space- only driver software can access physical memory directly in that manner.

      Those abilities don't really matter except for exploits. If you run an executable it can read any file accessible to your user account which will include things like saved passwords for databases, Internet Explorer, Firefox profiles, Outlook, etc. and it can send an E-mail with that info if it wants. (Software firewall might see the E-mail I suppose).
      4291.

      Solve : IE webrep loader?

      Answer»

      How can I DELETE IE webrep loader I have tried a lot from the WEB and NONE of them seem to work.What are you using for AV?
      I'm using avast, I think that's where it came from.Quote from: harry 48 on July 19, 2016, 02:08:03 PM

      I'm using avast, I think that's where it came from.
      That's where it came from. You can always switch to MicroSoft SECURITY Essentials.Thanks Dave I might do that, I ran ccleaner from here last night and it cleared it out, have not used it for a LONG time.
      4292.

      Solve : Online Shopping Trouble?

      Answer»

      I have been having problems with ONLINE shopping. The last TWO orders I placed never arrived at the mail. After that I got a totally random audio message telling me to call the phone number provided and not to shop online until I did. This was while visiting a PORNOGRAPHY website.You could try calling the number but do not GIVE them any personal information. If it is legit they should already have all the information. You should also contact the company where you placed your purchases and INQUIRE about your orders.

      4293.

      Solve : Cannot enter to some websites?

      Answer»

      I cannot enter to some websites except FACEBOOK and Google websites etc. But it normal when I using internet with my other DEVICES in same 4G wifi router. Do you think that it is a malware issue? PPZ help me to fix this.Your post is not clear.

      1) Are you saying you can ONLY get into Facebook and Google?

      2) What do you mean by "other devices"?

      3) What happens when you try other sites?

      4) Have you tried another browser?

      5) What is new or different since the last time everything worked properly (ie, new hw, new sw, virus, error, etc)?

      You need to provide as much INFORMATION as possible before we can offer intelligent assistance.

      4294.

      Solve : Files ending in .enc?

      Answer»

      The problem now is - I am in the middle of a newsletter done on publisher 2003, if I try to open it in publisher 2010 it is not up to DATE - in fact none of my 2003 newsletter will open now it is not installed. Hmmm. What to do - the newsletter is DUE to go out today or tomorrow Ok, good luck with that.Strange things happen, after I re-installed M/Soft Professional 2003, I then re-installed it, and all the problems vanished.

      The one thing that bugs me, is I can't EASILY find M/S Outlook Publisher 2003. By searching, it is in c: ProgramData-Microsoft-Windows-Start Menu- Programs-0Microsoft Office - Publisher 2003 - but once I shut the search - I can't find it anywhere - ProgramData is not shown for some reason. When I try to open the newsletter, it automatically opens in 2010 Publisher, but tells me to browse for what I want - and that's when I cant find the above thread (c: ProgramData-Microsoft-Windows-Start Menu- Programs-0Microsoft Office - Publisher 2003)

      If you could please tell me how to locate it to make it my preferred program, I would be very grateful. Other than that, consider the thread CLOSED, and many thanks for your help. (DAVE)Is it not in All Programs?Thanks, I've found a way around it now, longer, from All Programs.

      Can you close this thread now and thanks again for your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

      4295.

      Solve : Forgive me for "bumping my thread, but: I lost track of Allan?

      Answer»

      I wanted to tell Allan just how wonderful his help was.
      My computer is running like new and my printer is working again.
      I know I am suppose to post this on the 'end' of my THREAD ; but I can't find it...
      So THANKS ALLAN I feel almost so grateful I thought of SENDING money; almost...
      And the teck that I got when I called abouit Malware Bytes, said I should THROW my puter out...
      THANKS again,
      Ivan CopasFor the future with help finding a thread, click the PROFILE link.
      Under your profile picture you will see Show POSTS. The newest post is at the top.All I did was point you in the right direction, but you're welcome.

      4296.

      Solve : Is windows live mail dead??

      Answer»

      I have been using WINDOWS live mail for a long time.
      Will I be forced to learn another?
      Mine won't work all of a sudden. Help!

      CopasWell, I think mine still works. In fact our family has two accounts. But MS has combined some services and it may look DIFFERENT. Notices the attachment.
      I tried to sign in to www.live.com and it decided to LOG me into the Hotmail account. (attachment below.)


      [attachment deleted by admin to conserve space]Mine started working; but it may be spoofing me. I open my mail with a quick launch and when it wouldn't open the first time I opened a copy of yahoo mail so I may have conmfused myself.
      Now when it opens it looks like my old Windows mail.
      Don't PAY too much attention to me; i'm easily conmfused...
      Cheers,
      CopasQuote

      Don't pay too much attention to me; i'm easily conmfused...
      Me too! The Windows Live Mail client will continue to work with OTHER email services but not with Outlook.com (Hotmail) because Outlook.com will STOP supporting the DeltaSync protocol that WLM uses to communicate with it. Even then, you can change WLM to access Outlook.com via IMAP and it will work then.

      I am still using WLM 2012 to access my Hotmail account and everything is still working but I suppose it's only a matter of time before it stops working. Once it stops working, I will probably switch to Thunderbird as my email client.
      4297.

      Solve : How to dissociate an already-hacked computer from your real identity..??

      Answer»

      Let's say that you have a computer that is hiding behind a dedicated TOR Ethernet hotspot.

      So let's assume the computer got hacked by web browser exploit.

      So it is hacked, but it is still connected via a Tor Ethernet.

      Therefore, the hacker can see WHAT you are doing, but not WHO you are, i.e. your real IP.

      So... I want to operate in this environment.

      What kinds of things would I do to stop this laptop from being tied to me..?

      I will give you a LIST of things I thought of... I would like you to add to this list or correct anything I got wrong.

      1. Laptop manufacturer

      2. System spec

      3. Wipe/re-install the BIOS and HDD from any previous attacks

      4. Lists of programs installed. Perhaps only install a web browser and nothing else

      5. Don't visit sites in your ordinary BROWSING routine on clearnet

      6. Typing style / speed / vocabulary / language / typos, i.e. forensic linguistics

      7. Time of the day that you use the computer.. clock on the machine..

      8. Physically remove the webcam, mic

      9. Physically remove the WiFi chip, so it can't scan for nearby networks and devices. So the only connection is directly by Ethernet to the Tor hotspot

      10. Don't type your real name, or LOG into any accounts tied to your real name.

      What do you think..?I read this as:

      Quote

      Let's say that you have a computer that is hiding behind a dedicated Tor Ethernet hotspot.

      So let's assume the computer got hacked by web browser exploit say I put remote software on this system for remote control from elsewhere

      So it is hacked, but it is still connected via a Tor Ethernet.

      Therefore, the hacker can see WHAT you are doing, but not WHO you are, i.e. your real IP.

      So... I want to operate in this environment.

      What kinds of things would I do to stop this laptop from being tied to me..? I want to do illegal ACTIVITIES but trying to hide this in a question that maybe someone will answer and help me hide myself when I illegally do something.

      I will give you a list of things I thought of... I would like you to add to this list or correct anything I got wrong. Help me perfect my ways of hiding my illegal behavior.

      1. Laptop manufacturer

      2. System spec

      3. Wipe/re-install the BIOS and HDD from any previous attacks

      4. Lists of programs installed. Perhaps only install a web browser and nothing else

      5. Don't visit sites in your ordinary browsing routine on clearnet

      6. Typing style / speed / vocabulary / language / typos, i.e. forensic linguistics

      7. Time of the day that you use the computer.. clock on the machine..

      8. Physically remove the webcam, mic

      9. Physically remove the WiFi chip, so it can't scan for nearby networks and devices. So the only connection is directly by Ethernet to the Tor hotspot

      10. Don't type your real name, or log into any accounts tied to your real name.

      What do you think..?

      Code: [Select]What do you think..?
      My thoughts are that your a wanna be hacker, and a weak black hat trying to find a way to avoid getting caught. We cant help with this hiding and very questionable "SHADY" use.
      4298.

      Solve : Cannot get rid of pop-up?

      Answer»

      I have tried ccleaner, adware cleaner, superantispyware, malwarebytes but it's still here/ where did it come from.

      [attachment deleted by admin to conserve space]What do you mean" cannot get rid of it? What happens when you click "Don't allow" ?Theres a SQUARE you tick which says don't show this again but it makes no difference still pops up.

      I ran all above no good and I cannot find it anywhere in the pc.Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.SUPERDAVE.It's goneThere now, that wasn't so hard. See you Harry.
      Quote from: SuperDave on September 28, 2016, 05:15:04 PM

      There now, that wasn't so hard. See you Harry.

      That's why your a genius

      As the man said " i'll be back "Quote from: harry 48 on September 29, 2016, 12:23:31 PM
      That's why your a genius

      As the man said " i'll be back "
      It's good to see you're still around. How is life on the green isle?It's great, I'm fully retired now and enjoying it, how's life in Briton's colony Quote from: harry 48 on September 29, 2016, 01:19:17 PM
      It's great, I'm fully retired now and enjoying it, how's life in Briton's colony
      We call it Canada and we're about to DUMP the royalty. Everything is GOIND great. Retired for 15 yrs. and having a ball.Sure your future King and Queen are over to see how you are all keeping.

      My brother LIVES just outside Edmonton.
      4299.

      Solve : Got a problem in my folder that i cant open?

      Answer» C:\ProgramData is always closing everytime i open it, i thing its a kind of VIRUS, anyone knows how to remove it?
      i cant open regedit and task manager too.And everytime i PUT the word ProgramData or programdata in anywhere like browser, NOTEPAD, mword etc, it always closed, like the word ProgramData and Task Manager is BLOCK in my pcOh its fine now, thanks, i just restart my pc, thanks, already thank you in that Thank Geek-9pm button hehe, thanks ^_^
      4300.

      Solve : no connection?

      Answer»

      ppData\Roaming\Kingsoft\office6\update\down\wpsupdate.exea variant of Win32/KingSoft.D potentially unwanted applicationcleaned by deleting
      C:\Users\Owner\Documents\FILMS\ParaNorman.2012.720p.BRRip.x264.AAC.DiVERSiTY\FFSetup3.9.5.0.exea variant of Win32/FusionCore.I potentially unwanted applicationdeleted
      E:\AdwCleaner\Quarantine\C\Program Files (x86)\GetPrivate\gpup.exe.vira variant of Win32/Techsnab.B potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Program Files (x86)\GetPrivate\tasks.dll.vira variant of Win32/Tasks.A potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProUninstaller.exe.vira variant of Win32/Adware.SpeedingUpMyPC.AL applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\Frank\AppData\Local\GCC\Modules\InSes.dll.virWin32/GigaClicks.AM potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\Frank\AppData\Local\simple_new_tab\simple_new_tab.dll.virWin32/AdWare.Snoozer.A applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\Frank\AppData\Local\Temp\OCS\ocs_v71a.exe.vira variant of Win32/DownloadSponsor.A potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\Frank\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\minibarchrome.exe.vira variant of Win32/Toolbar.Iminent.O potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\Frank\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.virWin32/Systweak.G potentially unwanted applicationdeleted
      E:\AdwCleaner\Quarantine\C\Users\frank-pc\AppData\Roaming\GetPrivate\gp_upd.exe.vira variant of Win32/Techsnab.B potentially unwanted applicationcleaned by deleting
      E:\AdwCleaner\Quarantine\C\Users\frank-pc\AppData\Roaming\GetPrivate\tasks.dll.vira variant of Win32/Tasks.A potentially unwanted applicationcleaned by deleting
      Please give me a update on how your computer's working now.Morning Dave I think you have cracked it whatever you have done, my computer seems to be running far BETTER. the trouble I was having with Bit defender
      keep popping up and not being able to uninstall it. seems to have disappeared, so everything working ok .I am not sure about what antivirus to use though ,is windows defender enough. anyway you have done your job (as usual)

      Thanks once again Dave you saved me again (bet your glad to se the back of me). Have a good day.Quote

      is windows defender enough.
      It works for me on all my computers. Most of the crap going around is malware which WD protects against.

      Click START> Computer> right click the C Drive and choose Properties> enter
      Click Disk Cleanup from there.



      Click OK on the Disk Cleanup Screen.
      Click Yes on the Confirmation screen.



      This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the FREE space in C drive)
      ***************************************
      This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally USING some older restore point) and it'll make some other minor adjustments...
      This is a very crucial step so make sure you don't skip it.
      Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

      Double-click Delfix.exe to start the tool.
      Make sure the following items are checked:
      • Activate UAC (optional; some users prefer to keep it off)
      • Remove disinfection tools
      • Create Registry backup
      • Purge System Restore Points
      • Re-set system settings
      Now click "Run" and wait patiently.
      Once finished a logfile will be created. You don't have to attach it to your next reply.
      ********************************************
      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!