

InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
4401. |
Solve : Is E-excelleration or Stopsign good?? |
Answer» My parents are paying for stopsign and she was wondering if this was a good program? I was telling her how you helped me. What are the best ones out there to catch everything for those of us who don't know that much about computers. We are just wondering if you could point us in a direction. |
|
4402. |
Solve : hard drive filling up? |
Answer» was told to post here since i might have virus or something. |
|
4403. |
Solve : Trojan,Adware,Malware? |
Answer» Thank you for your time in advance. I just got this computer from another person, and I followed the Malware Removal Guide on this website to a T. I have fully updated versions of AVG, Online Armor, SUPER Anti-Spyware, Malwarebytes anti-malware. Again I've followed that guide to a T. Since I am not an expert at this, how do I know if my computer is 100% clean and safe to use? I have sensitive data that I need this computer for, but I'm not going to start until I know it is 100% clean. I also have the logs for anti-spyware, MBAM, and hijackthis ready and waiting on my desktop. Thank you for your time and help.If you don't know the history of the computer, the only way to know that it is absolutely clean is to do a re-format and re-install the Operating System. The computer may have had some serious infections that may have compromised the security of the machine. I've included the warning below that we give to those whose computers have been affected. This is very important especially if you're going to use this computer for financial transactions. We can run scans and check the logs but we can't guarantee it's security.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Here are the ESET scan results C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfgn.class-234f3403-1f6066ff.classprobably a variant of Java/TrojanDownloader.OpenStream trojancleaned by deleting - quarantined C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-746825f5-16fe8516.zipmultiple threatsdeleted - quarantined C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-516dc14a-5e884b29.zipprobably a variant of Win32/Agent trojandeleted - quarantined C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv645.jar-750ad2c1-6189b599.zipmultiple threatsdeleted - quarantined C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\R77SF69V\scn3[1].jsJS/TrojanDownloader.FakeAlert.NAB trojancleaned by deleting - quarantined It looks like your computer is clean. If there's nothing else, let's do some clean-up * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. =============================== Download OTC by OldTimer and save it to your desktop. 1. Double-click OTC to run it. 2. Click the CleanUp! button. 3. Select Yes when the "Begin cleanup Process?" prompt appears. 4. If you are prompted to Reboot during the cleanup, select Yes 5. OTC should delete itself once it finishes, if not delete it yourself. =============================== Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ================================ Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
4404. |
Solve : fake windows security page? |
Answer» Could you please delete ComboFix from your desktop. It's supposed to work with Vista. Let's try downloading it again.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.[/b]
Scan saved at 8:28:00 AM, on 6/6/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18904) Boot mode: Normal Running processes: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll O1 - Hosts: ::1 localhost O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files (x86)\SGPSA\SearchAssistant.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Calorie Count Plus Toolbar - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\PROGRA~2\ccptb\ccptb.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Calorie Count Plus Toolbar - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\PROGRA~2\ccptb\ccptb.dll O4 - HKLM\..\Run: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed LAUNCHER] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe /Minimized O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [iLike] C:\Program Files (x86)\iLike\1.2.16\ilikesidebar.exe /checkforupdate O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: CurseClientStartup.ccip O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Logitech SetPoint.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe O23 - Service: lxdfCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxdfserv.exe O23 - Service: lxdf_device - - C:\Windows\system32\lxdfcoms.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SAS Core Service (SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\system32\STacSV64.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- End of file - 12415 bytes Please go to VirSCAN.org FREE on-line scan service (If more than one file needs scanned they must be done separately and logs posted for each one) 1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page. Code: [Select]C:\Program Files\SGPSA\ie3sh.exe 2. At the upload site, click once inside the window next to Browse. 3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. 4. Click on the Upload button. This will perform a scan across multiple different virus scanning engines. Your file will possibly be entered into a queue which normally takes less than a minute to clear. Important: Wait for all of the scanning engines to complete. 5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard. 6. Paste the contents of the Clipboard in your next reply. =========================== Did you try running ComboFix again? Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file) O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. Combofix takes me to a page for geek police asking me to register for forum use... and as before vira scan will not let me paste using control +V nor the old fashioned way of just right clicking to paste... BOTH instances are greyed out. I will do the hyjack thing again.Ok. Forget about ComboFix and try this: Download OTL to your desktop. * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * When the window appears, underneath Output at the top change it to Minimal Output. * Check the boxes beside LOP Check and Purity Check. * Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy and pate the contents of these files, one at a time, into your next reply. Note: You may need two or more posts to fit them all in.TL logfile created on: 6/6/2010 7:43:06 PM - Run 1 OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\christal\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free 8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 283.34 Gb Total Space | 175.17 Gb Free Space | 61.82% Space Free | Partition Type: NTFS Drive D: | 14.75 Gb Total Space | 7.97 Gb Free Space | 54.05% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: CHRISTAL-PC Current User Name: christal Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company) PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.) PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe () PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) PRC - C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) SRV:64bit: - (BthServ) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (AgereModemAudio) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems) SRV:64bit: - (STacSV) -- C:\Windows\SysNative\STacSV64.exe (IDT, Inc.) SRV:64bit: - (lxdf_device) -- C:\Windows\SysNative\lxdfcoms.exe ( ) SRV:64bit: - (lxdfCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdfserv.exe () SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (npggsvc) -- C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.) SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (lxdf_device) -- C:\Windows\SysWow64\lxdfcoms.exe ( ) SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | ---D | M] SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof () ========== Driver Services (SafeList) ========== DRV:64bit: - (Lbd) -- C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB) DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek ) DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (BTHPORT) -- C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation) DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) -- C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation) DRV:64bit: - (BthEnum) -- C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation) DRV:64bit: - (BTHUSB) -- C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation) DRV:64bit: - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation) DRV:64bit: - (RTSTOR) -- C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.) DRV:64bit: - (SiFilter) -- C:\Windows\SysNative\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.) DRV:64bit: - (SiRemFil) -- C:\Windows\SysNative\DRIVERS\SiRemFil.sys (Silicon Image, Inc.) DRV:64bit: - (Si3531) -- C:\Windows\SysNative\DRIVERS\Si3531.sys (Silicon Image, Inc) DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.) DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.) DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.) DRV:64bit: - (NETw5v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation) DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems) DRV:64bit: - (UMPass) -- C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation) DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (usbvideo) USB Video Device (WDM) -- C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation) DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) -- C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation) DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.) DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.) DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation) DRV:64bit: - (NETw4v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation) DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.) DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.) DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.) DRV:64bit: - (UVCFTR) -- C:\Windows\SysNative\Drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation) DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (BCM43XV) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation) DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2 IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data] "VistaSp2" = 81 51 63 B3 05 27 CA 01 [binary data] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{018F2688-3B85-4961-9B20-8D80113AA792}" = lport=445 | protocol=6 | dir=in | app=system | "{02004DB0-A953-485D-9CB2-0CB6D9FB486E}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 | "{08643C05-553D-4F93-A8C3-BB5CE32F659F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{16D45D6E-1930-4950-B1A9-A84C82FC4377}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{199ED1AC-A398-4C60-B3F9-E84BC042F614}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{1A93C711-5374-4108-B058-93E09BCB0148}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{1FB44374-74FF-4C52-AC1A-A84F0EA35DFB}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{2216986F-8490-4ACA-A930-D984947498EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2370027C-B2D9-4EEF-89E3-943FDF773FB0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{23DA0C2C-8687-4DF2-940C-72CE6378A66C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2607EC0B-F5CD-4791-BC93-574476980CF4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2D202A91-807E-4856-BFC1-F6CD9BFAD113}" = lport=10244 | protocol=6 | dir=in | app=system | "{327C8253-C22F-47F5-AD0A-EB90F4F099C8}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{359A734F-2BEB-4696-A1FE-23CE3F8E1890}" = lport=137 | protocol=17 | dir=in | app=system | "{36038A39-E85A-4C0F-9679-EFD21FF37123}" = lport=138 | protocol=17 | dir=in | app=system | "{36C87270-6BA9-49C4-851C-C7F2F77A1BD2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{401E6089-4DCD-4770-AB24-3B021BF416A3}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{4130BBF7-D67B-4F3E-B548-DE529EF971C5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4BED0BE5-68BF-44C9-8853-4C59E90EEA1E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{51C77E64-4F38-489F-9495-6DE7B81BE094}" = lport=10244 | protocol=6 | dir=in | app=system | "{6B06D71A-BB1B-4284-B09E-1B7AC703F775}" = lport=139 | protocol=6 | dir=in | app=system | "{6DCC3E73-71C7-428A-A697-1F67CEE05533}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{6F75A199-9237-4F63-9096-6635DCD56261}" = rport=10244 | protocol=6 | dir=out | app=system | "{7030D9DD-7810-4477-8B53-5F1DFD1B26F9}" = rport=138 | protocol=17 | dir=out | app=system | "{72E93761-5963-4D8C-9632-A333445FC9DA}" = lport=2869 | protocol=6 | dir=in | app=system | "{78C988E2-F1E4-4214-8C1D-2ACF0146D1D9}" = rport=445 | protocol=6 | dir=out | app=system | "{7F9DC1B5-DD32-48B5-A46E-87DC5433BDA4}" = rport=10244 | protocol=6 | dir=out | app=system | "{83907F7F-08E5-457F-9559-FE7569FDD4B2}" = lport=3390 | protocol=6 | dir=in | app=system | "{870D5452-50DA-4908-A7D2-62D7B4D69998}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8C768901-0669-424E-AB5D-23091AF2B13A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [emailprotected],-28539 | "{8D28730A-5BE9-4826-BB5F-F44EDA4EDF9F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{93A24FDB-447A-4661-8F2F-CAEEDDEF50F1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{98A4744D-114B-4DFD-88F5-47DAEE05F8CD}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{A6E1F317-9D42-4948-A361-7018F985D5B3}" = rport=139 | protocol=6 | dir=out | app=system | "{AEB723E4-8BBE-48D5-AF7A-5A45D75428CA}" = lport=9420 | protocol=6 | dir=in | name=akamai network manager | "{B5A34DC5-A21E-402B-84B3-FFDF8E22D692}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D24330F8-9CA9-474F-B6AC-EF3C14882657}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D453BBDA-0A6D-4C92-81D1-D465B4D2B0A4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D51CBD42-4267-435B-9614-3BBF17699780}" = rport=137 | protocol=17 | dir=out | app=system | "{DB128F4E-9443-4C5C-B537-EAAC24384C8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{DFA6066D-C9C7-4C24-A410-C9F9F43B72B8}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{E0A13B46-3B08-407E-A342-285EFAE082DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{ED1508CC-D2F5-46B0-AC49-9DB9DBB3D874}" = lport=5000 | protocol=17 | dir=in | name=akamai network manager | "{F5EBE828-ED52-4AEE-B5E1-6976476C9C9D}" = lport=3390 | protocol=6 | dir=in | app=system | "{F70D102C-A3FC-4025-ABF8-EBD94639DD74}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0FA19479-159E-4F8B-A181-3AF1C7714F0B}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxdfcoms.exe | "{176928C1-0872-4E95-992D-009F1FDC81E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{1D4698D0-D73D-4A06-868B-8505C3F7F1FC}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{1E23F6D9-0ACE-4B63-A4F6-C321FF6F07B7}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfamon.exe | "{20951D0C-45A2-406D-B069-970321D3C850}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "{3549372B-02EB-447B-A536-55D93C8A6516}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfjswx.exe | "{36F18110-25B7-4C25-9583-D017EBC7FD43}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | "{42458B3B-3F8F-4CF1-B6A2-E7C5D1E2C4A0}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{4AF88C93-E78C-4791-A5C9-4FD1E08B10C3}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "{4DA7F2FC-D919-4994-8614-4452F8D188CF}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{5141C9EC-D5A2-4F48-AF4E-BDEF1FB6724D}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe | "{57007F84-B333-4DAD-AF54-C289EFEC758E}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{5CD7D776-3C94-4E86-8656-0E12877C0AF3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{606031B5-2FA7-451E-AE12-693A14DE70A4}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | "{63C3240C-9C66-4B61-87B3-DED6DBFBCE50}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{749B947B-A023-473A-9640-E787C646A73E}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdftime.exe | "{74A17DE9-C954-464F-90A7-FC12161C3C22}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{79B9B7A3-E7CF-4812-800B-FFDCE078453D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{7AD06813-D418-4B9A-AE16-4FA3B38975C2}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfmon.exe | "{7C987659-0F92-4528-869F-915689FB8601}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{7F512E54-86F5-4CEE-AD1A-14B15C38AAF8}" = protocol=17 | dir=in | app=c:\windows\system32\lxdfcoms.exe | "{7F5987A1-410A-4CB1-BE98-2BB6FB449B55}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\frun.exe | "{8137BF57-1B23-4372-9913-26605C1E4CAE}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{8287E80D-C9E5-4C3D-B135-8C5D24BEC809}" = protocol=17 | dir=in | app=c:\windows\system32\lxdfcfg.exe | "{8519AB2F-31B6-48E4-B247-A83BA37FEF35}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | "{8A822B07-A07C-4BF0-A94F-8A2FAF23C2C1}" = protocol=58 | dir=out | [emailprotected],-28546 | "{8AAC1F04-53E2-4D11-A608-A0DF321703CF}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{9C9884C0-BFD3-4F1D-91A8-506AC94AAA6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{A5319875-9864-4290-B399-FB316B1AA4C3}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "{A74F24AE-78EC-4972-A724-547207FFD681}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{AD8020EA-4AC7-4942-9317-533595AA5F2A}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | "{AF635B43-6720-4FF8-BA8E-8A5E13346B20}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{B1E5B761-56FA-46A7-B15C-35CD71876993}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{B86DA11C-0BD0-4323-BE9C-9D9902DDCB37}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfmon.exe | "{BBD8111B-3EF9-4D95-8EEC-66D491D6E385}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxdfcoms.exe | "{CE1EECA4-7EC3-4CC5-B12E-65266294C182}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfjswx.exe | "{D040D1B1-4BF4-4693-83B8-E72690DEFFDF}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe | "{D3857ACA-9849-4D84-8702-4FD9A7004AE2}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfamon.exe | "{D4F85714-3825-48BE-9CC4-32D4D9E9375B}" = protocol=6 | dir=in | app=c:\windows\system32\lxdfcoms.exe | "{D86AB65E-3B3D-43B4-8039-89DF2886580B}" = protocol=1 | dir=in | [emailprotected],-28543 | "{D8F73BD4-F78E-403D-BD99-C6EAA2175EF7}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{D8FBFD1B-27D8-4BF0-BA8D-F2FF8CDFB4CF}" = protocol=1 | dir=out | [emailprotected],-28544 | "{D93871D1-0EE4-4B57-A1BC-EC38C6AEBA74}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{E7D77EFB-1EE0-4BCF-B927-C00F98733934}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{EC8AF866-5C8F-49CE-9AFF-33CEB3947787}" = protocol=6 | dir=in | app=c:\windows\system32\lxdfcfg.exe | "{ECD049FA-CADF-4750-916A-131074685E95}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "{EE63EBC9-96CB-4F91-AADA-0C1CD4D2AD16}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{F0F66782-BC17-4B79-947C-031F429D7EFF}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\frun.exe | "{F7521E49-EE30-4886-A455-334F5B2DD901}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdftime.exe | "{FBAFC9D9-6E09-4F04-A269-683B4AAA4C19}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{FC426CB0-5E4F-43F8-B2CF-05796EB02FD8}" = protocol=58 | dir=in | [emailprotected],-28545 | "{FD76F04C-B588-40AB-A4CA-98CA87909301}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | "TCP Query User{0295F370-36ED-41F5-A59C-5DA507EA08FB}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe | "TCP Query User{04A80907-7DFD-4E5B-9CAD-7C1F6376524A}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe" = protocol=6 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe | "TCP Query User{2034B9D4-08A7-4DC6-BBF1-AEBEE7BE9A64}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "TCP Query User{2B6F2197-F16D-46BA-807A-FB97F3F2438F}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "TCP Query User{3C7A2B0E-D0FF-4277-90B5-5B8CF2E760DC}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe | "TCP Query User{6ABBB54B-96DF-429B-AEA8-7DD09A5CE241}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe" = protocol=6 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe | "TCP Query User{AF813B86-CD0F-4D8B-9A13-B5742FE69A80}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe | "TCP Query User{CB945C38-56AF-4EB8-9829-8F6EA6C17D80}C:\users\christal\desktop\ddi_cb.exe" = protocol=6 | dir=in | app=c:\users\christal\desktop\ddi_cb.exe | "TCP Query User{CC680EE5-990C-4DCF-A5C4-0E67DDC49D64}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{CF07B12E-8288-4794-9B39-6F1CF5F3AEE4}C:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe | "TCP Query User{D10AC1D1-415E-41E6-A9AE-408BDD859129}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe | "UDP Query User{18E23A06-4688-4C10-8594-3E7A12ADBA3E}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe" = protocol=17 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe | "UDP Query User{2B62C20B-5D11-4F29-AE51-6BD59BD09CA0}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe" = protocol=17 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe | "UDP Query User{32DC9B8C-CC6D-41D2-B6C5-89F6009A0E1C}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe | "UDP Query User{51D54237-BACB-43F0-AB6E-06BD22EC48A3}C:\users\christal\desktop\ddi_cb.exe" = protocol=17 | dir=in | app=c:\users\christal\desktop\ddi_cb.exe | "UDP Query User{525A2B4C-B5E5-43C9-9404-82C07725ADA0}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{896BCD68-F38C-425D-BA51-36AF8326DBF2}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe | "UDP Query User{9058C6A4-0FAF-4B28-A59A-A1B0C5C2CC15}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "UDP Query User{97AD2B18-0520-4D47-9D6C-5364F954404C}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe | "UDP Query User{C30C57AB-079E-4108-A0A8-BFF8DF2A8666}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "UDP Query User{EE3A05DC-D794-4C40-8FA7-9B94815EFDDE}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe | "UDP Query User{F5D6CC3E-01FE-4CA9-B512-E94F07DFFA73}C:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5400 "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64) "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager "{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64 "{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper "Agere Systems Soft Modem" = Agere Systems HDA Modem "Lexmark 6500 Series" = Lexmark 6500 Series "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Security Essentials" = Microsoft Security Essentials "NVIDIA Drivers" = NVIDIA Drivers "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup PACKAGE (x64) "{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime "{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0 "{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20 "{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0 "{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1 "{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore "{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001 "{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book "{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA "{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink "{626C034B-50B8-47BD-AF93-EEFD0FA78FF4}" = Character Builder "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail "{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista "{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse "{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}" = AGEIA PhysX v7.11.13 "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar "{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger "{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3 "{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK "{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook "{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI "{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar "{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations "{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery "{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page "{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS "{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Ad-Aware" = Ad-Aware "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "BookSmart® 2.6.0 2.6.0" = BookSmart® 2.6.0 2.6.0 "ccptb" = Calorie Count Plus Toolbar "Digital Editions" = Adobe Digital Editions "FMOD Designer" = FMOD Designer "HijackThis" = HijackThis 2.0.2 "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (2.0.0.3)" = Mozilla Firefox (2.0.0.3) "SystemRequirementsLab" = System Requirements Lab "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "World of Warcraft" = World of Warcraft "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Mail" = Yahoo! Internet Mail "Yahoo! Mail Advisor" = Yahoo! Mail Advisor "Yahoo! Software Update" = Yahoo! Software Update ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "090215de958f1060" = Curse Client "NCsoft-Aion" = Aion ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 6/6/2010 5:38:52 PM | Computer Name = christal-PC | Source = WinMgmt | ID = 10 Description = Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1010 Description = Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = Error - 6/6/2010 6:41:46 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = Error - 6/6/2010 6:41:47 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = Error - 6/6/2010 6:41:48 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = Error - 6/6/2010 6:41:49 PM | Computer Name = christal-PC | Source = Perflib | ID = 1005 Description = Error - 6/6/2010 6:41:49 PM | Computer Name = christal-PC | Source = Perflib | ID = 1018 Description = Error - 6/6/2010 6:41:50 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008 Description = [ Media Center Events ] Error - 3/19/2010 11:18:21 PM | Computer Name = christal-PC | Source = McrMgr | ID = 107 Description = [ System Events ] Error - 6/6/2010 7:18:59 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:22:02 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:25:05 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:28:07 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:31:10 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:34:14 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:37:16 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:40:19 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:43:21 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = Error - 6/6/2010 7:46:23 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333 Description = < End of report > OTL logfile created on: 6/6/2010 7:43:06 PM - Run 1 OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\christal\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free 8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 283.34 Gb Total Space | 175.17 Gb Free Space | 61.82% Space Free | Partition Type: NTFS Drive D: | 14.75 Gb Total Space | 7.97 Gb Free Space | 54.05% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: CHRISTAL-PC Current User Name: christal Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company) PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.) PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe () PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) PRC - C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) SRV:64bit: - (BthServ) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (AgereModemAudio) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems) SRV:64bit: - (STacSV) -- C:\Windows\SysNative\STacSV64.exe (IDT, Inc.) SRV:64bit: - (lxdf_device) -- C:\Windows\SysNative\lxdfcoms.exe ( ) SRV:64bit: - (lxdfCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdfserv.exe () SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (npggsvc) -- C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.) SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (lxdf_device) -- C:\Windows\SysWow64\lxdfcoms.exe ( ) SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | ---D | M] SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof () ========== Driver Services (SafeList) ========== DRV:64bit: - (Lbd) -- C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB) DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek ) DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (BTHPORT) -- C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation) DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) -- C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation) DRV:64bit: - (BthEnum) -- C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation) DRV:64bit: - (BTHUSB) -- C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation) DRV:64bit: - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation) DRV:64bit: - (RTSTOR) -- C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.) DRV:64bit: - (SiFilter) -- C:\Windows\SysNative\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.) DRV:64bit: - (SiRemFil) -- C:\Windows\SysNative\DRIVERS\SiRemFil.sys (Silicon Image, Inc.) DRV:64bit: - (Si3531) -- C:\Windows\SysNative\DRIVERS\Si3531.sys (Silicon Image, Inc) DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.) DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.) DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.) DRV:64bit: - (NETw5v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation) DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems) DRV:64bit: - (UMPass) -- C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation) DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (usbvideo) USB Video Device (WDM) -- C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation) DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) -- C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation) DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.) DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.) DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation) DRV:64bit: - (NETw4v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation) DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.) DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.) DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.) DRV:64bit: - (UVCFTR) -- C:\Windows\SysNative\Drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation) DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (BCM43XV) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation) DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2 IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginen ame: "Fast Browser Search" FF - prefs.js..browser.search.order.1: "Fast Browser Search" FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search" FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/" FF - prefs.js..browser.search.defaultEngine: "Yahoo" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..browser.search.defaultenginen ame: "Yahoo" FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&type=&p=" FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/10/24 11:32:22 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/02 22:55:42 | 000,000,000 | ---D | M] [2009/12/13 11:45:31 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions [2009/10/24 11:33:39 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2008/08/18 06:53:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010/05/31 09:50:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions [2010/05/31 09:50:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2009/10/24 11:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected] [2009/10/24 11:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected] [2009/10/24 11:32:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected] [2009/08/18 17:26:26 | 002,619,266 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\components\1249345.dll [2007/03/12 05:01:33 | 000,066,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\jar50.dll [2007/03/12 05:01:34 | 000,054,376 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\jsd3250.dll [2007/03/12 05:01:36 | 000,034,952 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\myspell.dll [2007/03/12 05:01:38 | 000,046,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\spellchk.dll [2007/03/12 05:01:40 | 000,172,144 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\xpinstal.dll [2010/05/31 09:50:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll [2009/10/24 11:32:41 | 000,003,700 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fast.png [2009/10/24 11:32:40 | 000,001,963 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fast.xml O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,736 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found. O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files (x86)\SGPSA\SearchAssistant.dll (Make The Web Better, LLC) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( ) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll (Yahoo! Inc) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( ) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( ) O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.DLL (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) O4 - HKLM..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe File not found O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.) O4 - HKCU..\Run: [iLike] C:\Program Files (x86)\iLike\1.2.16\ilikesidebar.exe File not found O4 - HKCU..\Run: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe File not found O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks) O4 - Startup: C:\Users\christal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object) O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control) O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab (Image Uploader Control) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: CabBuilder http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 68.237.161.12 O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\christal\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg O24 - Desktop BackupWallPaper: C:\Users\christal\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004/04/30 04:01:00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (lsdelete) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010/06/06 19:41:38 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Users\christal\Desktop\OTL.exe [2010/06/06 18:27:45 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW [2010/06/05 17:45:24 | 000,069,152 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys [2010/06/02 22:33:00 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS [2010/06/02 17:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro [2010/06/02 17:41:04 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Users\christal\Desktop\HijackThisInstaller.exe [2010/06/02 06:35:45 | 000,000,000 | ---D | C] -- C:\Users\christal\AppData\Roaming\SUPERAntiSpyware.com [2010/06/02 06:35:45 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2010/06/02 06:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\SASCORE [2010/06/02 06:35:37 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2010/06/02 06:34:37 | 008,924,856 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\christal\Desktop\SUPERAntiSpyware.exe [2010/05/31 09:53:43 | 000,157,696 | ---- | C] (The RaProducts Team: Paul McLain and Fred de Vries) -- C:\Users\christal\Desktop\JavaRa.exe [2010/05/31 09:50:44 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010/05/31 09:50:44 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010/05/31 09:50:44 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010/05/31 09:50:44 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010/05/30 20:19:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Antimalware [2010/05/30 20:18:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials [2010/05/28 18:44:29 | 000,000,000 | -HSD | C] -- C:\found.000 [2010/05/18 18:21:46 | 000,000,000 | ---D | C] -- C:\Users\christal\Documents\My Digital Editions [2010/05/09 20:04:12 | 000,000,000 | ---D | C] -- C:\Users\christal\Documents\BookSmartData [2010/05/09 20:04:00 | 000,000,000 | ---D | C] -- C:\Users\christal\.blurb [2010/05/09 20:02:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BookSmart [2008/06/15 11:43:17 | 001,200,128 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfserv.dll [2008/06/15 11:43:17 | 000,950,272 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfusb1.dll [2008/06/15 11:43:17 | 000,647,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfpmui.dll [2008/06/15 11:43:17 | 000,565,248 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdflmpm.dll [2008/06/15 11:43:17 | 000,356,352 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfinpa.dll [2008/06/15 11:43:17 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfiesc.dll [2008/06/15 11:43:17 | 000,053,248 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfprox.dll [2008/06/15 11:43:15 | 000,663,552 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfhbn3.dll [2008/06/15 11:43:14 | 000,860,160 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfcomc.dll [2008/06/15 11:43:14 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfcomm.dll [135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/06/06 19:43:13 | 002,359,296 | -HS- | M] () -- C:\Users\christal\ntuser.dat [2010/06/06 19:42:53 | 000,000,440 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6C0934CF-0A85-42F1-A2BE-C48A6A068357}.job [2010/06/06 19:41:46 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\christal\Desktop\OTL.exe [2010/06/06 19:38:20 | 000,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010/06/06 19:38:20 | 000,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010/06/06 18:30:52 | 000,000,828 | ---- | M] () -- C:\Users\christal\Desktop\World of Warcraft.lnk [2010/06/06 17:40:23 | 000,028,124 | ---- | M] () -- C:\Users\christal\AppData\Roaming\nvModes.001 [2010/06/06 17:38:39 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010/06/06 17:38:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010/06/05 22:03:34 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010/06/05 22:03:29 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000001.regtrans-ms [2010/06/05 22:03:29 | 000,065,536 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TM.blf [2010/06/05 22:03:20 | 003,340,508 | -H-- | M] () -- C:\Users\christal\AppData\Local\IconCache.db [2010/06/05 17:41:42 | 000,069,152 | ---- | M] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys [2010/06/05 17:21:02 | 000,028,124 | ---- | M] () -- C:\Users\christal\AppData\Roaming\nvModes.dat [2010/06/04 23:00:15 | 001,208,320 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mbb [2010/06/04 23:00:15 | 000,686,080 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mb [2010/06/02 22:38:54 | 000,001,888 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2010/06/02 18:40:29 | 000,000,104 | ---- | M] () -- C:\Users\christal\Desktop\Recycle Bin - Shortcut.lnk [2010/06/02 18:03:24 | 000,867,892 | ---- | M] () -- C:\Users\christal\Desktop\SecurityCheck.exe [2010/06/02 17:41:23 | 000,001,939 | ---- | M] () -- C:\Users\christal\Desktop\HijackThis.lnk [2010/06/02 17:41:06 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Users\christal\Desktop\HijackThisInstaller.exe [2010/06/02 06:35:40 | 000,001,767 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2010/06/02 06:34:46 | 008,924,856 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\christal\Desktop\SUPERAntiSpyware.exe [2010/05/31 09:50:32 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010/05/31 09:50:32 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010/05/31 09:50:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010/05/31 09:50:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010/05/30 21:36:04 | 000,000,736 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfud.bin [2010/05/30 21:35:48 | 000,000,736 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfss.bin [2010/05/30 20:18:57 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk [2010/05/28 21:58:45 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\EasyShare Registration Task.job [2010/05/28 18:31:50 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000002.regtrans-ms [2010/05/28 17:00:38 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TMContainer00000000000000000001.regtrans-ms [2010/05/28 17:00:38 | 000,065,536 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TM.blf [2010/05/18 18:24:07 | 000,001,334 | ---- | M] () -- C:\Users\christal\Desktop\vegS 4 DUMB.acsm [2010/05/18 18:21:34 | 000,002,024 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Digital Editions.lnk [2010/05/17 17:47:30 | 000,000,168 | ---- | M] () -- C:\Users\christal\AppData\Roaming\wklnhst.dat [2010/05/09 20:03:52 | 000,001,763 | ---- | M] () -- C:\Users\Public\Desktop\BookSmart.lnk [2010/05/07 23:02:19 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TMContainer00000000000000000002.regtrans-ms [135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/06/02 22:38:54 | 000,001,888 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2010/06/02 18:40:29 | 000,000,104 | ---- | C] () -- C:\Users\christal\Desktop\Recycle Bin - Shortcut.lnk [2010/06/02 18:03:21 | 000,867,892 | ---- | C] () -- C:\Users\christal\Desktop\SecurityCheck.exe [2010/06/02 17:41:23 | 000,001,939 | ---- | C] () -- C:\Users\christal\Desktop\HijackThis.lnk [2010/06/02 06:35:40 | 000,001,767 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2010/05/31 09:53:43 | 000,245,103 | ---- | C] () -- C:\Users\christal\Desktop\JavaRa.def [2010/05/30 20:18:57 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk [2010/05/28 17:05:23 | 000,524,288 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000002.regtrans-ms [2010/05/28 17:05:23 | 000,524,288 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000001.regtrans-ms [2010/05/28 17:05:23 | 000,065,536 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TM.blf [2010/05/18 18:22:56 | 000,001,334 | ---- | C] () -- C:\Users\christal\Desktop\vegS 4 DUMB.acsm [2010/05/18 18:21:34 | 000,002,024 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Digital Editions.lnk [2010/05/09 20:03:52 | 000,001,763 | ---- | C] () -- C:\Users\Public\Desktop\BookSmart.lnk [2009/08/27 06:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll [2009/08/27 06:22:21 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2008/12/24 09:36:14 | 000,339,968 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll [2008/12/24 09:36:14 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll [2008/06/15 11:43:17 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxdfcomx.dll [2008/06/15 11:43:17 | 000,348,160 | ---- | C] () -- C:\Windows\SysWow64\lxdfinst.dll [2008/01/20 22:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll [2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll [2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll ========== LOP Check ========== [2008/06/09 19:58:32 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Acreon [2010/04/13 06:58:17 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\ccptb [2009/08/26 07:08:21 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\GetRightToGo [2010/03/18 05:52:28 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\iLike [2008/06/30 06:49:31 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Lexmark Productivity Studio [2008/10/05 20:04:35 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\SampleView [2009/04/25 12:59:49 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Skinux [2008/06/30 06:48:01 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Template [2009/05/21 23:03:16 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Windows Live Writer [2010/05/28 21:58:45 | 000,000,406 | ---- | M] () -- C:\Windows\Tasks\EasyShare Registration Task.job [2010/06/05 22:03:37 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2010/06/06 19:42:53 | 000,000,440 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6C0934CF-0A85-42F1-A2BE-C48A6A068357}.job ========== Purity Check ========== < End of report > Add or Remove Programs 1. Click on the Windows Start button and click on the Control Panel 2. In the Control Panel window, double-click Add or Remove Programs icon. In Vista, Programs and Features 3. When the Add or Remove Programs window has fully populated, check for Java(TM) 6 Update 4 Java(TM) 6 Update 5 Java(TM) 6 Update 7 SGPSA and uninstall them. ================================== I'd like us to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. If you want to help, please go here. Superdave.No threats were found using EST so they only left me with the option of pushing finish.That looks good. If there are no other issues, let's do some clean-up. Download OTC by OldTimer and save it to your desktop. 1. Double-click OTC to run it. 2. Click the CleanUp! button. 3. Select Yes when the "Begin cleanup Process?" prompt appears. 4. If you are prompted to Reboot during the cleanup, select Yes 5. OTC should delete itself once it finishes, if not delete it yourself. ================================ Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. =============================== Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ================================ Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! OK, I have downloaded all you have suggested. What remains on my desktop? I have super antispyware Hyjack this TFC Eset is still installed malwarebytes microsoft security essentials spyware doctor pc tools firewall Wot security check spyware blaster Of the above which ones do I need to uninstall?Uninstall HJT, ESET, TFC, Security Check. You may keep SAS and MBAM, if you wish. Update them and run it on a regular basis. SpywareBlaster needs to be updated every so often. I usually do mine about once a month. All the rest are need and can stay. |
|
4405. |
Solve : Antivirus for WIn 7? |
Answer» Which antivirus is best for WIndows 7? |
|
4406. |
Solve : Operating system problems? |
Answer» i tried and got the same error...i tried to update then delete and got the same message to please wait while it deletes all Mcafee......I am gonna leave my system on THRU out the nite to see what happens with the message, maybe it needs some time to delete all programs. my connection seems to have a sudder to it?What does this mean? Download Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a FOLDER named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.Ok.....SuperdaveResults of screen317's Security Check version 0.99.4 Windows XP Service Pack 3 Internet Explorer 7 Out of date! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Norton 360 McAfee SecurityCenter ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java(TM) 6 Update 20 Adobe Flash Player 10.0.45.2 Adobe Reader 9.3.2q ```````````````````````````````` Process Check: objlist.exe by Laurent Norton ccSvcHst.exe ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` sudder= my internet seems to be skipping..The Security Check shows these two programs: Norton 360 McAfee SecurityCenter. Are these both Anti-Virus programs? If yes, one of them will have to be disabled because running two or more AV programs at once is a no-no. Is your computer still taking a long while to boot? |
|
4407. |
Solve : MalwareBytes paid version? |
Answer» Does anyone have the paid version of MalwareBytes and if so, how is the updating? The reason I ask is apparently I've been spoiled with the virus programs, etc. automatically updating. I had been using the free version of SuperAntiSpyware and got tired of having to update it manually. I checked the settings, etc. and saw that with the paid version it would update at startup and every 8 hours. It had such good reviews so I trusted it and made the mistake of purchasing it. But, AFTER I had purchased it, I found out that if you're not online when it tries to update, you're out of LUCK. If you get an update, you have to do it manually. I had assumed it would try again if I wasn't online when it tried but I was wrong. How does the purchased version of MalwareBytes update work? Do I have to be online at the right time with it or if I'm not, will it try again later? I was no better off with the paid version of SuperAntiSpyware and I don't want to make that mistake again. THANKS for your time.I don't understand. When you do go online SAS will ALWAYS notify there is an update if there is one more current than what you are running. All you have to do is click on update. Why PURCHASE another product?Quote from: Allan on June 07, 2010, 09:35:21 AM I don't understand. When you do go online SAS will always notify there is an update if there is one more current than what you are running. All you have to do is click on update. Why purchase another product?If I wanted an update of the definitions or the program, I had to do it manually or it wouldn't get done. Mine has never notified me of any updates being available. If I get it, I have to do it myself and that was why I wanted it. I thought it would update automatically or at least that's what it claimed to do. I went to their forum and asked about it and there were several others having the same PROBLEM. They told me to get a support ticket which is what I did and they couldn't help me either. I had found where Malwarebytes has a scheduler for their updates. I was hoping someone could tell me if it does what it claims to do. I can't tell by the free version and I don't want to purchase another one and then find out it doesn't do what they say it will.I've never had a problem with SAS notifying me of updates.Quote from: Allan on June 07, 2010, 11:50:34 AM I've never had a problem with SAS notifying me of updates.My problem is that it will not update and they were advertising it to "automatically update" but it will not do it. Also, there are others that are having the same problem. It has notified me once or twice about the program updates but I still had to manually update it myself. But, it has never notified me of spyware definition updates and if I get them, I have to do it manually so why bother purchasing when you're not any better off than using the free version. And that was the reason I purchased it so it would automatically update it instead of me having to do it each time.If you go to their websites you will see there is more functionality in the paid versions, not just the automatic updates. My OS is scheduled for automatic updates but if my computer is not on at that time, I will get a message that there are updates waiting the next time I turn on my computer. The way around this it to leave your computer on 24/7 which is a bad practice, green planet wise. Quote from: SuperDave on June 07, 2010, 05:13:53 PM If you go to their websites you will see there is more functionality in the paid versions, not just the automatic updates. My OS is scheduled for automatic updates but if my computer is not on at that time, I will get a message that there are updates waiting the next time I turn on my computer. The way around this it to leave your computer on 24/7 which is a bad practice, green planet wise.If I had left my computer on AND connected to the internet 24/7, SuperAntispyware Pro would have updated but I don't do that and I'm not going to start it now. It didn't even notify me that there were updates waiting. I was just hoping someone could tell me that Malwarebytes Pro worked better than this. I didn't want to purchase it and THEN find out it wasn't any better. Thanks for your time.I was using MalwareBytes home version for the last 3 months or so and I thought it was doing a good job of keeping my computer clean. Then I noticed my computer was behaving really slowly whenever I was online so I decided to scan it with Emsisoft Anti-malware software. I was shocked at how much crap it found on my computer and on my external drive. I have to say I would really recommend that anyone that thinks they have a problem try the Emsisoft software because it seems to be very good. As long as they can keep up with creating new definitions then I think the app is a keeper. |
|
4408. |
Solve : Computer freezes when a new window is opened? |
Answer» Hi... I posted this in the hardware section and was told to poast here instead: Hi, sorry but I cannot get onto my computer at all now. I just say your post and have not been able to do anything. When I turn the power on the computer starts to boot up and then the screen goes blank and the monitor says "monitor going to sleep" and it starts over. It just continues to cycle through and never actually starts. I borrowed a friends laptop but i have tons of things that I need on my compter. Help please! Kari, the first thing I would suggest is that you slave your harddrive to another functioning computer and copy the files that you need to a DVD. If you can't do this yourself, I'm sure you could find a friend that knows enough about computers to help you. Be sure to scan the files before you use them on another computer. Then, you will probably have to take the computer to a repair shop because it looks like this is a hardware problem. Have you checked all the cables to ensure that nothing has become DISCONNECTED? Did you try booting with the Rescue CD in place? |
|
4409. |
Solve : Anyone want some AV software or a firewall tested?? |
Answer» Quote from: tgp1994 on June 10, 2010, 09:45:17 AM Well, ya, of course I ran them Some of the installers I tried just popped up a meaningless error message, while others ran, taking about 90%+ of the CPU, but still ended up doing nothing. What did you expect them to "do"? Well, I was mainly looking for a trojan that would download other viruses, expanding the POSSIBLITIES for me to get screwed over I mean, what kind of a virus would just run at 90% CPU, or just pop up an error message and be done with?Quote from: tgp1994 on June 10, 2010, 01:04:57 PM I was mainly looking for a trojan that would download other viruses How do you know that they didn't? Anyhow, most real-world malware apps are not WRITTEN purely and simply just to infect people's computers, for the pure joy of causing mischief. They often have some purpose such as joining your pc to a botnet, turning it into a spam relay, or a number of other THINGS, all of which they do silently and behind the scenes. If you are doing all this in a VMWare virtual machine, I sure hope you aren't sharing any folders with the host OS... Well, I suppose the more malware I have, the better. Mischief sounds good to me. And definetly no, I am not doing FOLDER sharing. In some cases, I'll disconnect the virtual network adapter after downloading a virus (to see if it is) just for good measure. |
|
4410. |
Solve : APPLICATION IS EXECUTED. THE FILE XXXXXX MAY BE INFECTED!? |
Answer» THIS IS THE OTL.TXT
============================================== I'd like us to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt IM DYING WAITING FOR THE ESET TO FINISH BUT AS SOON AS I FINISH IT ILL POST THE LOG! FYI INTERNET IS WORKING NOW AND NO MORE IRRITATING POP OUTS! THANK U VERY MUCH! XDAll processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hsfe8owijfisjhgs7ye39gjsoighsd7y3eu deleted successfully. File not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\M5T8QL3YW3 deleted successfully. File not found. ========== FILES ========== File\Folder C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe () not found. File\Folder C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe () not found. File\Folder C:\Users\Bernabe's\49253DE2FC99A4DABO1A8E6088.TMP not found. ========== COMMANDS ========== C:\windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Error: Unable to interpret <[clearrestorepoints]> in the current context! [EMPTYTEMP] User: All Users User: AppData User: Bernabe's ->Temp folder emptied: 1492001980 bytes ->Temporary Internet Files folder emptied: 92372857 bytes ->Java cache emptied: 4616576 bytes ->Google Chrome cache emptied: 348239320 bytes ->Flash cache emptied: 85369 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8729698 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,856.00 mb OTL by OldTimer - Version 3.2.5.3 log created on 06022010_202449 Files\Folders moved on Reboot... C:\Users\Bernabe's\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\windows\temp\JET7AAB.tmp not found! Registry entries deleted on Reboot... Im sorry, I cant find the log for the ESET. After it scanned i didnt found the "list of found threats" beacause i think it scanned no threats at all. And i tried to find it on my computer but i cant find the log file. Is it ok if I dont give you the log? And for the files that you made me download pls tell me what to do with them?Quote And for the files that you made me download pls tell me what to do with them?If it is the programs that we used, we'll get to cleaning those up later. Let's just try another scan. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows: •Double-click on drweb-cureit.exe and then click Start •An information notice will appear, click OK. •This starts a short scan that will scan the files currently running in memory. •If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version •If or when something is found, click the Yes button when it asks you if you want to cure it. •Once the short scan has finished, Click Settings > Change Settings •Under the Scanning tab UNcheck Heuristic analysis and click OK •Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start. •Click Yes to all if it asks if you want to cure/move any file(s). •When the scan is done. •In the Dr.Web CureIt menu on top left, click File and choose Save report list. •Save the DrWeb.csv report to your Desktop. •Exit Dr.Web Cureit. •Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot. * After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad * Copy and paste that log in the next reply. the dr. web is taking so long... XDAfter it scanned i clicked "file" and tried to click "save report list" but it wont let me. It scanned 376326 files in all. And it says at the bottom "Done-no viruses found." Ok. That sound good. If there are no other issues, it's time for some clean-up To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. ========================================== To remove all of the tools we used and the files and folders they created, please do the following: Double click OTC.exe. Click the CleanUp! button. If you are prompted to Reboot during the cleanup, select Yes. The tool will delete itself once it finishes. Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually. =========================================== Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. =================================== Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Can i just delete them manually cause i cant find OTC.exe and for the control pannel I cant find "System Maintenance".THANK U ^^Quote Can i just delete them manually cause i cant find OTC.exe and for the control panel I cant find "System Maintenance". Sorry. That should read double-click OTL.exe. That's the tool we used to get that long report. As for System Maintenance, I know very little about Windows 7 so I just did that part about resetting your Restore Point from what I found on the net. Please check your computer on how to turn off and then turn back on your System Restore.I have the same problem as stated here however I can not even get rkill to run on my computer. I have tried downloading all 4 version listed in the first step and non of them run. Any suggestions? Thanks. |
|
4411. |
Solve : Cannot Install HijackThis? |
Answer» Please download SystemLook from one of the links below and save it to your Desktop.
smb.sys atapi.sys
Log created at 18:59 on 22/06/2010 by Dawn (ADMINISTRATOR - Elevation successful) ========== filefind ========== SEARCHING for "smb.sys" C:\Windows\System32\drivers\smb.sys--a--- 66560 bytes[18:02 17/09/2009][04:45 11/04/2009] 031E6BCD53C9B2B9ACE111EAFEC347B6 C:\Windows\winsxs\x86_microsoft-windows-nbsmb_31bf3856ad364e35_6.0.6001.18000_none_5f6a9133f7f64138\smb.sys--a--- 66560 bytes[02:25 21/01/2008][02:25 21/01/2008] 40E0C1EA4D5CEB087E04F34560980418 Searching for "atapi.sys" C:\Windows\ERDNT\cache\atapi.sys--a--- 21560 bytes[22:55 14/06/2010][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys--a--- 19944 bytes[18:03 17/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys--a--- 19048 bytes[10:25 02/11/2006][09:49 02/11/2006] 4F4FCB8B6EA06784FB6D475B7EC7300F C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys--a--- 21560 bytes[02:23 21/01/2008][02:23 21/01/2008] 2D9C903DC76A66813D350A562DE40ED9 C:\Windows\System32\drivers\atapi.sys------ 21560 bytes[02:23 21/01/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys--a--- 21560 bytes[02:23 21/01/2008][02:23 21/01/2008] 2D9C903DC76A66813D350A562DE40ED9 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 96DC4E1A9F90CCD489950A8935425C59 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys--a--- 19944 bytes[18:03 17/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4 -=End Of File=-Re-running ComboFix to remove infections:
FCopy:: C:\Windows\System32\drivers\smb.sys | C:\Windows\winsxs\x86_microsoft-windows-nbsmb_31bf3856ad364e35_6.0.6001.18000_none_5f6a9133f7f64138\smb.sys Reboot::
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.836 [GMT -4:00] Running from: c:\users\Dawn\Downloads\ComboFix.exe Command switches used :: c:\users\Dawn\Desktop\CFScript.txt.lnk SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Resident AV is active . ((((((((((((((((((((((((( Files Created from 2010-05-24 to 2010-06-24 ))))))))))))))))))))))))))))))) . 2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Public\AppData\Local\temp 2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Default\AppData\Local\temp 2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Bewn\AppData\Local\temp 2010-06-24 00:10 . 2010-06-24 00:11--------d-----w-C:\32788R22FWJFW 2010-06-23 20:41 . 2009-11-08 14:5599176----a-w-c:\windows\system32\PresentationHostProxy.dll 2010-06-23 20:41 . 2009-11-08 14:5549472----a-w-c:\windows\system32\netfxperf.dll 2010-06-23 20:41 . 2009-11-08 14:55297808----a-w-c:\windows\system32\mscoree.dll 2010-06-23 20:41 . 2009-11-08 14:55295264----a-w-c:\windows\system32\PresentationHost.exe 2010-06-23 20:41 . 2009-11-08 14:551130824----a-w-c:\windows\system32\dfshim.dll 2010-06-21 01:44 . 2010-06-21 01:44--------d-----w-c:\program files\ESET 2010-06-15 23:05 . 2010-06-15 23:05--------d-----w-c:\program files\Windows Portable Devices 2010-06-15 20:19 . 2009-09-10 02:0092672----a-w-c:\windows\system32\UIAnimation.dll 2010-06-15 20:19 . 2009-09-10 02:013023360----a-w-c:\windows\system32\UIRibbon.dll 2010-06-15 20:19 . 2009-09-10 02:001164800----a-w-c:\windows\system32\UIRibbonRes.dll 2010-06-15 20:18 . 2009-09-25 01:33369664----a-w-c:\windows\system32\WMPhoto.dll 2010-06-15 20:18 . 2009-09-24 22:54258048----a-w-c:\windows\system32\winspool.drv 2010-06-15 20:18 . 2009-09-25 01:27634880----a-w-c:\windows\system32\drivers\dxgkrnl.sys 2010-06-15 20:18 . 2009-09-25 01:2737888----a-w-c:\windows\system32\cdd.dll 2010-06-15 20:16 . 2009-10-01 01:0230208----a-w-c:\windows\system32\WPDShextAutoplay.exe 2010-06-15 20:16 . 2009-10-01 01:0231232----a-w-c:\windows\system32\BthMtpContextHandler.dll 2010-06-15 20:16 . 2009-10-01 01:0181920----a-w-c:\windows\system32\wpdbusenum.dll 2010-06-15 20:16 . 2009-10-01 01:0160928----a-w-c:\windows\system32\PortableDeviceConnectApi.dll 2010-06-15 20:16 . 2009-10-01 01:022537472----a-w-c:\windows\system32\wpdshext.dll 2010-06-15 20:16 . 2009-10-01 01:02334848----a-w-c:\windows\system32\PortableDeviceApi.dll 2010-06-15 20:16 . 2009-10-01 01:0287552----a-w-c:\windows\system32\WPDShServiceObj.dll 2010-06-15 20:16 . 2009-10-01 01:01546816----a-w-c:\windows\system32\wpd_ci.dll 2010-06-15 20:16 . 2009-10-01 01:01160256----a-w-c:\windows\system32\PortableDeviceTypes.dll 2010-06-15 20:16 . 2009-10-01 01:01350208----a-w-c:\windows\system32\WPDSp.dll 2010-06-15 20:16 . 2009-10-01 01:01196608----a-w-c:\windows\system32\PortableDeviceWMDRM.dll 2010-06-15 20:16 . 2009-10-01 01:01100864----a-w-c:\windows\system32\PortableDeviceClassExtension.dll 2010-06-15 20:14 . 2009-10-08 21:074096----a-w-c:\windows\system32\oleaccrc.dll 2010-06-15 20:14 . 2009-10-08 21:08555520----a-w-c:\windows\system32\UIAutomationCore.dll 2010-06-15 20:14 . 2009-10-08 21:08234496----a-w-c:\windows\system32\oleacc.dll 2010-06-15 01:40 . 2010-05-04 05:5571680----a-w-c:\windows\system32\iesetup.dll 2010-06-15 01:40 . 2010-05-04 05:55109056----a-w-c:\windows\system32\iesysprep.dll 2010-06-15 01:40 . 2010-05-04 04:31133632----a-w-c:\windows\system32\ieUnatt.exe 2010-06-15 01:40 . 2010-01-06 15:391696256----a-w-c:\windows\system32\gameux.dll 2010-06-15 01:40 . 2010-01-06 15:3828672----a-w-c:\windows\system32\Apphlpdm.dll 2010-06-15 01:40 . 2010-01-06 13:304240384----a-w-c:\windows\system32\GameUXLegacyGDFs.dll 2010-06-15 01:40 . 2010-05-01 14:132037248----a-w-c:\windows\system32\win32k.sys 2010-06-15 01:10 . 2010-06-15 01:46--------d-----w-c:\users\Dawn\AppData\Local\Microsoft Games 2010-06-14 22:57 . 2010-06-24 00:28--------d-----w-c:\users\Dawn\AppData\Local\temp 2010-06-14 22:57 . 2010-06-24 00:27--------d-----w-c:\users\Ben\AppData\Local\temp 2010-06-13 18:49 . 2010-06-13 18:49388096----a-r-c:\users\Dawn\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-06-13 18:13 . 2010-06-13 18:37--------d-----w-c:\program files\Trend Micro 2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\users\Dawn\AppData\Roaming\Malwarebytes 2010-06-13 04:01 . 2010-04-29 19:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\programdata\Malwarebytes 2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-06-13 04:01 . 2010-04-29 19:3920952----a-w-c:\windows\system32\drivers\mbam.sys 2010-06-12 23:55 . 2010-06-12 23:5563488----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-06-12 23:55 . 2010-06-12 23:5552224----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-06-12 23:55 . 2010-06-12 23:55117760----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com 2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\programdata\SUPERAntiSpyware.com 2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\program files\SUPERAntiSpyware 2010-06-12 23:32 . 2010-06-12 23:32--------d-----w-c:\program files\CCleaner 2010-06-07 02:47 . 2010-06-07 02:47411368----a-w-c:\windows\system32\deployJava1.dll 2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\ca-ES 2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\eu-ES 2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\vi-VN 2010-05-31 01:49 . 2010-05-31 01:49--------d-----w-c:\windows\system32\EventProviders 2010-05-28 18:18 . 2010-05-28 18:18--------d-----w-c:\windows\Sun 2010-05-28 03:39 . 2010-05-28 03:39--------d-----w-c:\users\Dawn\AppData\Roaming\vlc 2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\users\Dawn\AppData\Local\Graboid_Inc 2010-05-28 03:35 . 2010-05-28 03:40--------d-----w-c:\users\Dawn\AppData\Local\Graboid 2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\users\Dawn\AppData\Roaming\MozillaControl 2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\program files\Mozilla ActiveX Control v1.7.12 2010-05-28 03:34 . 2010-05-28 03:34--------d-----w-c:\program files\VideoLAN 2010-05-28 03:33 . 2010-05-28 03:44--------d-----w-c:\program files\Graboid 2010-05-25 20:06 . 2010-04-23 14:132048----a-w-c:\windows\system32\tzres.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-15 23:04 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2010-06-15 23:04 . 2006-11-02 10:25665600----a-w-c:\windows\inf\drvindex.dat 2010-06-15 23:03 . 2010-06-15 23:030---ha-w-c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-06-15 23:02 . 2008-12-27 05:07--------d-----w-c:\program files\Microsoft Silverlight 2010-06-07 02:48 . 2008-11-25 20:22--------d-----w-c:\program files\Common Files\Java 2010-06-07 02:47 . 2008-11-25 20:22--------d-----w-c:\program files\Java 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Calendar 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Sidebar 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Journal 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Collaboration 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Photo Gallery 2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Defender 2010-05-31 01:46 . 2008-12-08 01:44--------d-----w-c:\programdata\Viewpoint 2010-05-29 03:12 . 2009-03-17 02:445972----a-w-c:\users\Ben\AppData\Local\d3d9caps.dat 2010-05-28 03:46 . 2009-03-03 02:13--------d-----w-c:\users\Dawn\AppData\Roaming\Apple Computer 2010-05-26 17:06 . 2010-06-15 01:4134304----a-w-c:\windows\system32\atmlib.dll 2010-05-26 14:47 . 2010-06-15 01:41289792----a-w-c:\windows\system32\atmfd.dll 2010-05-21 18:14 . 2009-10-03 14:42221568------w-c:\windows\system32\MpSigStub.exe 2010-05-20 20:32 . 2010-05-20 20:32666112----a-w-c:\users\Ben\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv306hw-1004220-0-main.dll 2010-05-04 23:46 . 2010-05-04 23:44--------d-----w-c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2010-05-04 23:46 . 2010-05-04 23:44--------d-----w-c:\program files\iTunes 2010-05-04 23:44 . 2010-05-04 23:44--------d-----w-c:\program files\iPod 2010-05-04 23:44 . 2009-03-03 02:08--------d-----w-c:\program files\Common Files\Apple 2010-05-04 23:42 . 2010-05-04 23:42--------d-----w-c:\program files\Apple Software Update 2010-05-04 22:58 . 2010-05-04 22:58--------d-----w-c:\users\Dawn\AppData\Roaming\Roxio 2010-05-04 22:45 . 2010-05-04 22:44--------d-----w-c:\program files\QuickTime 2010-05-04 05:59 . 2010-06-15 01:41916480----a-w-c:\windows\system32\wininet.dll 2010-04-28 19:45 . 2010-04-28 19:4573000----a-w-c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe 2010-04-15 00:30 . 2009-05-19 01:05143976----a-w-c:\users\Dawn\AppData\Roaming\Move Networks\uninstall.exe 2010-04-15 00:30 . 2009-10-15 00:505642688----a-w-c:\users\Dawn\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll 2010-04-05 17:01 . 2010-06-15 01:4167072----a-w-c:\windows\system32\asycfilt.dll 2009-11-02 20:15 . 2009-11-02 20:15119808----a-w-c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2008-11-25 20:42 . 2008-11-25 20:4276--sh--r-c:\windows\CT4CET.bin 2008-11-25 21:51 . 2008-11-25 21:508192--sha-w-c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( [emailprotected]_22.53.16 ))))))))))))))))))))))))))))))))))))))))) . + 2010-06-23 20:41 . 2009-11-08 14:5599176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.1.6001.18242_none_f290a8a118b9134c\PresentationHostProxy.dll + 2010-06-22 20:02 . 2010-03-30 11:5999176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.0.6002.22377_none_2cb6816f90457914\PresentationHostProxy.dll + 2010-06-22 20:02 . 2010-04-05 12:1999176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.0.6002.18236_none_2c57240a7708502f\PresentationHostProxy.dll + 2010-06-15 20:16 . 2009-10-01 01:0140448 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdusb.sys + 2010-06-15 20:16 . 2009-10-01 01:0161952 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpus.dll + 2010-06-15 20:16 . 2009-10-01 01:0168608 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpip.dll + 2010-06-15 20:16 . 2009-10-01 01:0178336 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpbt.dll + 2010-06-15 20:16 . 2009-10-01 01:0133280 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdconns.dll + 2010-06-15 01:40 . 2010-04-12 12:2217256 c:\windows\winsxs\x86_wcf-m_svc_mon_sup_dll_31bf3856ad364e35_6.0.6002.22380_none_a7f79e1e62233116\ServiceMonikerSupport.dll + 2010-06-15 01:40 . 2010-04-12 12:2117256 c:\windows\winsxs\x86_wcf-m_svc_mon_sup_dll_31bf3856ad364e35_6.0.6002.18239_none_a7ad138948d4e9a6\ServiceMonikerSupport.dll + 2010-06-23 20:41 . 2009-11-08 14:5511600 c:\windows\winsxs\x86_netfx-mscorees_dll_31bf3856ad364e35_6.1.6001.18242_none_e15f1c362a176592\mscorees.dll + 2010-06-23 20:41 . 2009-11-08 14:5549472 c:\windows\winsxs\x86_netfx-fw_netfxperf_dll_31bf3856ad364e35_6.1.6001.18242_none_5c993a771a2304b1\netfxperf.dll + 2010-06-15 01:39 . 2010-03-25 11:5430544 c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6002.22372_none_adfdfb72a63b9516\aspnet_wp.exe + 2010-06-15 01:39 . 2010-03-25 11:5330544 c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6002.18232_none_c4c7a10a8c97cfb4\aspnet_wp.exe + 2010-06-15 20:16 . 2009-10-01 01:0287552 c:\windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.0.6002.18112_none_130696d2c3f64ac4\WPDShServiceObj.dll + 2010-06-15 20:16 . 2009-10-01 01:0230208 c:\windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.0.6002.18112_none_130696d2c3f64ac4\WPDShextAutoplay.exe + 2010-06-15 20:16 . 2009-10-01 01:0160928 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceConnectApi.dll + 2010-06-15 20:16 . 2009-10-01 01:0181920 c:\windows\winsxs\x86_microsoft-windows-wpd-busenumservice_31bf3856ad364e35_6.0.6002.18112_none_79dbda7dc92efc79\wpdbusenum.dll + 2010-06-15 20:19 . 2009-09-10 02:0092672 c:\windows\winsxs\x86_microsoft-windows-uianimation_31bf3856ad364e35_7.0.6002.18108_none_7edc01bff7a1cb45\UIAnimation.dll + 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.22164_none_2de0cf8ef1d7d6cc\printfilterpipelineprxy.dll + 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.18060_none_2d53319bd8bdd1a6\printfilterpipelineprxy.dll + 2010-06-15 01:41 . 2010-04-05 17:1467072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6002.22377_none_78f4d4e8cf978645\asycfilt.dll + 2010-06-15 01:41 . 2010-04-05 17:0167072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6002.18236_none_78957783b65a5d60\asycfilt.dll + 2010-06-15 01:41 . 2010-04-05 16:2867072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6001.22665_none_77173258d26ae282\asycfilt.dll + 2010-06-15 01:41 . 2010-04-05 16:0767072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6001.18454_none_76976349b9461049\asycfilt.dll + 2010-06-15 20:18 . 2009-09-25 01:2737888 c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_7.0.6002.18107_none_9f26906a6b93696c\cdd.dll + 2010-06-15 01:40 . 2010-05-04 06:3071680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\iesetup.dll + 2010-06-15 01:40 . 2010-05-04 06:3055808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\iernonce.dll + 2010-06-15 01:40 . 2010-05-04 05:5571680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\iesetup.dll + 2010-06-15 01:40 . 2010-05-04 05:5555808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\iernonce.dll + 2010-06-15 01:40 . 2010-05-04 04:5813312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23019_none_dfbeba5109ad11a7\msfeedssync.exe + 2010-06-15 01:40 . 2010-05-04 06:3055296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23019_none_dfbeba5109ad11a7\msfeedsbs.dll + 2010-06-15 01:40 . 2010-05-04 04:3013312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18928_none_df297713f0983e5c\msfeedssync.exe + 2010-06-15 01:40 . 2010-05-04 05:5655296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18928_none_df297713f0983e5c\msfeedsbs.dll + 2010-06-15 01:40 . 2010-05-04 06:3164512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\WininetPlugin.dll + 2010-06-15 01:40 . 2010-05-04 06:3025600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\jsproxy.dll + 2010-06-15 01:40 . 2010-05-04 05:5964512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\WininetPlugin.dll + 2010-06-15 01:40 . 2010-05-04 05:5525600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\jsproxy.dll + 2010-06-15 01:41 . 2010-05-26 17:1023552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\lpk.dll + 2010-06-15 01:41 . 2010-05-26 17:0972704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\fontsub.dll + 2010-06-15 01:41 . 2010-05-26 17:0810240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\dciman32.dll + 2010-06-15 01:41 . 2010-05-26 17:0834304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\atmlib.dll + 2009-07-15 14:05 . 2009-06-15 14:5223552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\lpk.dll + 2010-01-13 12:56 . 2009-10-19 13:3572704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\fontsub.dll + 2009-07-15 14:05 . 2009-06-15 14:5110240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\dciman32.dll + 2010-06-15 01:41 . 2010-05-26 17:0634304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\atmlib.dll + 2010-06-15 01:41 . 2010-05-26 16:2023552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\lpk.dll + 2010-06-15 01:41 . 2010-05-26 16:1972704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\fontsub.dll + 2010-06-15 01:41 . 2010-05-26 16:1810240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\dciman32.dll + 2010-06-15 01:41 . 2010-05-26 16:1734304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\atmlib.dll + 2010-01-13 12:56 . 2009-10-19 14:2472704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\fontsub.dll + 2009-07-15 14:05 . 2009-06-15 15:2010240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\dciman32.dll + 2010-06-15 01:41 . 2010-05-26 16:1634304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\atmlib.dll + 2010-06-15 20:16 . 2009-10-01 01:0231232 c:\windows\winsxs\x86_microsoft-windows-d..thmtpcontexthandler_31bf3856ad364e35_7.0.6002.18112_none_302fc434dcfbe04c\BthMtpContextHandler.dll + 2010-06-15 01:40 . 2010-01-06 16:0128672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.22303_none_8474f2d5770488ce\Apphlpdm.dll + 2010-06-15 01:40 . 2010-01-06 15:3828672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.18179_none_83a5a66c5e1a477e\Apphlpdm.dll + 2010-06-22 20:03 . 2010-04-16 16:0828672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.22672_none_8241d12f7a17ddea\Apphlpdm.dll + 2010-06-22 20:03 . 2010-04-16 16:0528672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.18461_none_81c2022060f30bb1\Apphlpdm.dll + 2010-06-15 20:16 . 2009-10-01 01:0150688 c:\windows\winsxs\x86_bthmtpenum.inf_31bf3856ad364e35_6.0.6002.18112_none_01d56cf0911e704e\bthmtpenum.sys + 2010-06-15 01:40 . 2010-04-12 12:2332768 c:\windows\winsxs\msil_system.servicemodel.washosting_b77a5c561934e089_6.0.6002.22380_none_a725653cfb4fe6ae\System.ServiceModel.WasHosting.dll + 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\winsxs\msil_system.servicemodel.washosting_b77a5c561934e089_6.0.6002.18239_none_bded3d82e1adee9e\System.ServiceModel.WasHosting.dll + 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\System32\printfilterpipelineprxy.dll - 2009-09-17 18:02 . 2009-04-11 06:2826112 c:\windows\System32\printfilterpipelineprxy.dll + 2010-06-23 20:41 . 2009-11-08 14:5511600 c:\windows\System32\MUI\0409\mscorees.dll - 2010-04-02 18:38 . 2010-02-23 04:5413312 c:\windows\System32\msfeedssync.exe + 2010-06-15 01:40 . 2010-05-04 04:3013312 c:\windows\System32\msfeedssync.exe - 2010-04-02 18:38 . 2010-02-23 06:3455296 c:\windows\System32\msfeedsbs.dll + 2010-06-15 01:40 . 2010-05-04 05:5655296 c:\windows\System32\msfeedsbs.dll + 2010-06-15 01:40 . 2010-05-04 05:5964512 c:\windows\System32\migration\WininetPlugin.dll - 2010-04-02 18:38 . 2010-02-23 06:3964512 c:\windows\System32\migration\WininetPlugin.dll + 2010-06-15 01:40 . 2010-05-04 05:5525600 c:\windows\System32\jsproxy.dll - 2010-04-02 18:38 . 2010-02-23 06:3425600 c:\windows\System32\jsproxy.dll - 2010-04-02 18:38 . 2010-02-23 06:3355808 c:\windows\System32\iernonce.dll + 2010-06-15 01:40 . 2010-05-04 05:5555808 c:\windows\System32\iernonce.dll + 2010-06-15 20:16 . 2009-10-01 01:0140448 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdUsb.sys + 2010-06-15 20:16 . 2009-10-01 01:0161952 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpUS.dll + 2010-06-15 20:16 . 2009-10-01 01:0168608 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpIP.dll + 2010-06-15 20:16 . 2009-10-01 01:0178336 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpbt.dll + 2010-06-15 20:16 . 2009-10-01 01:0133280 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdConns.dll + 2010-06-15 20:16 . 2009-10-01 01:0150688 c:\windows\System32\DriverStore\FileRepository\bthmtpenum.inf_201caa7f\BthMtpEnum.sys + 2009-11-28 02:58 . 2010-06-17 23:5316384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-11-28 02:58 . 2010-06-01 22:4816384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-11-28 02:58 . 2010-06-17 23:5332768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-11-28 02:58 . 2010-06-01 22:4832768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-11-28 02:58 . 2010-06-01 22:4816384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-11-28 02:58 . 2010-06-17 23:5316384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll - 2009-09-17 18:02 . 2009-02-18 18:3832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll + 2010-06-15 01:40 . 2010-04-12 12:2117256 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll + 2010-06-15 01:39 . 2010-03-25 11:5330544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2010-06-15 20:14 . 2010-06-15 20:1449936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe - 2010-04-16 13:04 . 2010-04-16 13:0449936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe - 2010-04-16 13:04 . 2010-04-16 13:0435600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2010-06-15 20:14 . 2010-06-15 20:1435600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2010-06-15 20:11 . 2010-06-15 20:1149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll + 2010-06-23 23:44 . 2010-06-23 23:4460928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\81ab082be2597d562533493d955b20fa\UIAutomationProvider.ni.dll + 2010-06-16 00:54 . 2010-06-16 00:5460928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\71446066f8f87652fa7303395df566cc\UIAutomationProvider.ni.dll + 2010-06-23 23:46 . 2010-06-23 23:4637888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\8f17237b1a97a723837bede4c5b10085\System.Windows.Presentation.ni.dll + 2010-06-23 23:46 . 2010-06-23 23:4636864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\6b60acb027ae9b015ffc61dcba421bd3\System.Web.DynamicData.Design.ni.dll + 2010-06-16 00:58 . 2010-06-16 00:5894208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\e3da89cc15807bd5c9747b4ba394cd41\System.ComponentModel.DataAnnotations.ni.dll + 2010-06-16 00:58 . 2010-06-16 00:5882944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\ef965cf9c5c75294aef56d47f4b0eb26\System.AddIn.Contract.ni.dll + 2010-06-16 00:56 . 2010-06-16 00:5644032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\6fb97ad4786df4e2a5c0edaa3a284de8\stdole.ni.dll + 2010-06-16 00:58 . 2010-06-16 00:5847104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\f56c075fa1f45464ede198e36e79d617\PresentationFontCache.ni.exe + 2010-06-23 23:45 . 2010-06-23 23:4547104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\c57f58acdfc796bc888fcb6603715537\PresentationFontCache.ni.exe + 2010-06-16 00:54 . 2010-06-16 00:5439424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\76a79903753244ecd4bedb4b607da4b8\PresentationCFFRasterizer.ni.dll + 2010-06-23 23:44 . 2010-06-23 23:4439424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\44ecfa244cf6aa4212e23ba22349a240\PresentationCFFRasterizer.ni.dll + 2010-06-16 00:58 . 2010-06-16 00:5879872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\ec37fe0ddb66e6ed277cc9c83c39e134\napcrypt.ni.dll + 2010-06-16 00:54 . 2010-06-16 00:5455296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\3aa49e133664e428e319de2e6a008335\Microsoft.Vsa.ni.dll + 2010-06-16 00:53 . 2010-06-16 00:5315872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\84dda64a3e7cec7239ede8d5e48b5847\Microsoft.VisualC.ni.dll + 2010-06-16 00:55 . 2010-06-16 00:5574752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\f156806d82a796faf4968b2cb872141d\Microsoft.Build.Framework.ni.dll + 2010-06-16 00:57 . 2010-06-16 00:5765024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2990c6a100dc31f3a36bd8c2afafa92b\Microsoft.Build.Framework.ni.dll + 2010-06-16 00:57 . 2010-06-16 00:5768608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\f4e3668f28222716aef5866686aec3cc\loadmxf.ni.exe + 2010-06-23 23:44 . 2010-06-23 23:4468608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\6d929408f21f2b81b51dff132a83c60e\loadmxf.ni.exe + 2010-06-16 00:56 . 2010-06-16 00:5657856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\9e40e4d9ddeac7b337afb0ab2a45b7c7\ehiUserXp.ni.dll + 2010-06-16 00:56 . 2010-06-16 00:5655296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiReplay\53c8ef024a64e5e6c4a1a4e23db7c753\ehiReplay.ni.dll + 2010-06-16 00:56 . 2010-06-16 00:5623552 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtCOM\3c3b9f210946ad30b80aef7c2c61bec1\ehiExtCOM.ni.dll + 2010-06-23 23:45 . 2010-06-23 23:4539424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\8289c53c4bb2b134feb8e6da972fd492\ehExtCOM.ni.dll + 2010-06-16 00:56 . 2010-06-16 00:5639424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\49b927a353d3c2aa8cc6e5e27836adf7\ehExtCOM.ni.dll + 2010-06-16 00:56 . 2010-06-16 00:5614336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\8b295851a21fc513dcb5dbcd9b5385e6\dfsvc.ni.exe + 2010-06-16 00:53 . 2010-06-16 00:5325600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1bcbcac5237f54c73628936552c55b69\Accessibility.ni.dll - 2009-09-17 18:02 . 2009-02-18 18:3832768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll + 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll + 2010-06-15 20:14 . 2009-10-08 21:074096 c:\windows\winsxs\x86_microsoft-windows-oleaccrc_31bf3856ad364e35_6.0.6002.18156_none_7ae05aee84ac8b45\oleaccrc.dll + 2010-06-23 20:43 . 2010-04-14 17:536656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.dll + 2010-06-15 01:40 . 2010-01-06 13:312560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.22303_none_0e955139088d9e83\AcRes.dll + 2010-06-22 20:03 . 2010-04-16 14:162560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.22672_none_0c622f930ba0f39f\AcRes.dll + 2009-03-06 01:30 . 2010-06-21 12:212632 c:\windows\System32\WDI\ERCQueuedResolutions.dat + 2010-06-23 02:26 . 2010-06-23 20:512048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2010-06-14 22:32 . 2010-06-14 22:322048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2010-06-14 22:32 . 2010-06-14 22:322048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-06-23 02:26 . 2010-06-23 20:512048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-06-23 20:41 . 2009-11-08 14:55295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.1.6001.18242_none_37f9c545bf07d41a\PresentationHost.exe + 2010-06-22 20:02 . 2010-03-30 11:59295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.0.6002.22377_none_721f9e14369439e2\PresentationHost.exe + 2010-06-22 20:02 . 2010-04-05 12:19295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.0.6002.18236_none_71c040af1d5710fd\PresentationHost.exe + 2010-06-22 20:02 . 2010-03-30 11:59130408 c:\windows\winsxs\x86_wpf-presentationhostdll_31bf3856ad364e35_6.0.6002.22377_none_7236d7fc36759770\PresentationHostDLL.dll + 2010-06-22 20:02 . 2010-04-05 12:19129896 c:\windows\winsxs\x86_wpf-presentationhostdll_31bf3856ad364e35_6.0.6002.18236_none_71d77a971d386e8b\PresentationHostDLL.dll + 2010-06-15 20:16 . 2009-10-01 01:01839168 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpdr.dll + 2010-06-15 20:16 . 2009-10-01 01:01226816 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtp.dll + 2010-06-15 20:16 . 2009-10-01 01:01227840 c:\windows\winsxs\x86_wpdfs.inf_31bf3856ad364e35_6.0.6002.18112_none_27ca7fa9cfc85a60\wpdfs.dll + 2010-06-15 01:40 . 2010-04-12 12:22970752 c:\windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783\System.Runtime.Serialization.dll + 2010-06-15 01:40 . 2010-04-12 12:21970752 c:\windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73\System.Runtime.Serialization.dll + 2010-06-15 01:40 . 2010-04-12 12:22442368 c:\windows\winsxs\x86_wcf-system.identitymodel_b03f5f7f11d50a3a_6.0.6002.22380_none_0ebeb2ba5a6f811c\System.IdentityModel.dll + 2010-06-15 01:40 . 2010-04-12 12:20438272 c:\windows\winsxs\x86_wcf-system.identitymodel_b03f5f7f11d50a3a_6.0.6002.18239_none_25868b0040cd890c\System.IdentityModel.dll + 2010-06-15 01:39 . 2010-03-25 11:54436048 c:\windows\winsxs\x86_netfx-web_engine_dll_b03f5f7f11d50a3a_6.0.6002.22372_none_1fb465ed51de1b9c\webengine.dll + 2010-06-15 01:39 . 2010-03-25 11:53435024 c:\windows\winsxs\x86_netfx-web_engine_dll_b03f5f7f11d50a3a_6.0.6002.18232_none_367e0b85383a563a\webengine.dll + 2010-06-15 20:11 . 2009-09-04 06:59388920 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.22219_none_fcfe427e14d1391e\SOS.dll + 2010-06-15 20:11 . 2009-09-04 06:59388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.18107_none_13cb1683fb2a8c7f\SOS.dll + 2010-06-23 20:41 . 2009-11-08 14:55297808 c:\windows\winsxs\x86_netfx-mscoree_dll_31bf3856ad364e35_6.1.6001.18242_none_7d658e19f5139de5\mscoree.dll + 2010-06-15 20:11 . 2009-09-04 06:58989528 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.22219_none_142ffabd20dc5d09\mscordacwks.dll + 2010-06-15 20:11 . 2009-09-04 06:58989000 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.18107_none_2afccec30735b06a\mscordacwks.dll + 2010-06-15 20:16 . 2009-10-01 01:01546816 c:\windows\winsxs\x86_microsoft.windows.h..ler.wpd-driverclass_31bf3856ad364e35_6.0.6002.18112_none_6a8bd86c653628e0\wpd_ci.dll + 2010-06-15 20:16 . 2009-10-01 01:01134144 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledevicesqm_31bf3856ad364e35_7.0.6002.18112_none_46439f2b6f000426\sqmapi.dll + 2010-06-15 20:16 . 2009-10-01 01:01160256 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceTypes.dll + 2010-06-15 20:16 . 2009-10-01 01:01100864 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceClassExtension.dll + 2010-06-15 20:16 . 2009-10-01 01:02334848 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceApi.dll + 2010-06-15 20:17 . 2009-09-25 02:07189440 c:\windows\winsxs\x86_microsoft-windows-windowscodecext_31bf3856ad364e35_7.0.6002.18107_none_86efc43840ac1e52\WindowsCodecsExt.dll + 2010-06-15 20:17 . 2009-09-25 02:10974848 c:\windows\winsxs\x86_microsoft-windows-windowscodec_31bf3856ad364e35_7.0.6002.18107_none_89dfaf462924c1eb\WindowsCodecs.dll + 2010-06-15 20:16 . 2009-10-01 01:01196608 c:\windows\winsxs\x86_microsoft-windows-w..ewmdrmcompatibility_31bf3856ad364e35_6.0.6002.18112_none_aeefe03423bfee4f\PortableDeviceWMDRM.dll + 2010-06-15 20:16 . 2009-10-01 01:01350208 c:\windows\winsxs\x86_microsoft-windows-w..cationcompatibility_31bf3856ad364e35_6.0.6002.18112_none_7007d7d4dbaec336\WPDSp.dll + 2010-06-23 20:43 . 2010-04-14 17:54293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22670_none_dc3b2eff7065f9a1\psisdecd.dll + 2010-06-23 20:43 . 2010-04-14 17:47293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18459_none_dbd032c0573008dd\psisdecd.dll + 2010-06-15 20:14 . 2009-10-08 21:08555520 c:\windows\winsxs\x86_microsoft-windows-uiautomationcore_31bf3856ad364e35_6.0.6002.18156_none_b1ceff3f3f65520f\UIAutomationCore.dll + 2010-06-23 20:43 . 2010-04-14 17:54428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22670_none_e0b60d45a7bcf5f6\EncDec.dll + 2010-06-23 20:43 . 2010-04-14 17:46428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18459_none_e04b11068e870532\EncDec.dll + 2010-06-15 20:17 . 2009-09-25 01:48351232 c:\windows\winsxs\x86_microsoft-windows-printing-xpsprint_31bf3856ad364e35_7.0.6002.18107_none_9f011af59951f340\XpsPrint.dll + 2010-06-15 20:17 . 2009-09-25 02:04321024 c:\windows\winsxs\x86_microsoft-windows-photometadatahandler_31bf3856ad364e35_7.0.6002.18107_none_bdcd592c6d8ad7f7\PhotoMetadataHandler.dll + 2010-06-15 20:18 . 2009-09-25 01:33369664 c:\windows\winsxs\x86_microsoft-windows-photo-image-codec_31bf3856ad364e35_7.0.6002.18107_none_9297a600cdc57a69\WMPhoto.dll + 2010-06-15 20:18 . 2009-09-24 22:55258048 c:\windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6002.22197_none_9543bd3e2f3469c3\winspool.drv + 2010-06-15 20:18 . 2009-09-24 22:54258048 c:\windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6002.18088_none_94c5f0a9160dc75f\winspool.drv + 2010-06-15 20:17 . 2009-09-24 22:55667648 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.22164_none_2de0cf8ef1d7d6cc\printfilterpipelinesvc.exe + 2010-06-15 20:17 . 2009-09-24 22:54667648 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.18060_none_2d53319bd8bdd1a6\printfilterpipelinesvc.exe + 2010-06-15 20:14 . 2009-10-08 21:08234496 c:\windows\winsxs\x86_microsoft-windows-oleacc_31bf3856ad364e35_6.0.6002.18156_none_6c3b296e1fad2902\oleacc.dll + 2010-06-15 20:18 . 2009-09-25 01:27634880 c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_7.0.6002.18107_none_9f26906a6b93696c\dxgkrnl.sys + 2010-06-15 01:41 . 2010-05-04 06:30164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.23019_none_481337e6dd0a172b\ieui.dll + 2010-06-15 01:41 . 2010-05-04 05:55164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18928_none_477df4a9c3f543e0\ieui.dll + 2010-06-15 01:40 . 2010-05-04 06:30109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.23019_none_ff02e517e8e79415\iesysprep.dll + 2010-06-15 01:40 . 2010-05-04 05:55109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.18928_none_fe6da1dacfd2c0ca\iesysprep.dll + 2010-06-15 01:40 . 2010-05-04 04:59173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\ie4uinit.exe + 2010-06-15 01:40 . 2010-05-04 04:30173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\ie4uinit.exe + 2010-06-15 01:41 . 2010-05-04 06:31129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.23019_none_2b1475a0bb6f3e25\sqmapi.dll + 2010-06-15 01:41 . 2010-05-04 05:58129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18928_none_2a7f3263a25a6ada\sqmapi.dll + 2010-06-15 01:41 . 2010-05-04 06:31206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.23019_none_1a973373430e2393\occache.dll + 2010-06-15 01:41 . 2010-05-04 05:58206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.18928_none_1a01f03629f95048\occache.dll + 2010-06-15 01:41 . 2010-05-04 06:32638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe + 2010-06-15 01:40 . 2010-05-04 04:59133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\ieUnatt.exe + 2010-06-15 01:41 . 2010-05-04 06:00638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe + 2010-06-15 01:40 . 2010-05-04 04:31133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\ieUnatt.exe + 2010-06-15 01:41 . 2010-05-04 06:30197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.23019_none_2afdfb3cc92410b5\IEShims.dll + 2010-06-15 01:41 . 2010-05-04 05:55197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18928_none_2a68b7ffb00f3d6a\IEShims.dll + 2010-06-15 01:41 . 2010-05-04 06:30247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.23019_none_739fafa6797baa47\ieproxy.dll + 2010-06-15 01:41 . 2010-05-04 05:55247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18928_none_730a6c696066d6fc\ieproxy.dll + 2010-06-15 01:41 . 2010-05-04 06:30599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.23019_none_4357559369617280\msfeeds.dll + 2010-06-15 01:41 . 2010-05-04 05:56599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.18928_none_42c21256504c9f35\msfeeds.dll + 2010-06-15 01:41 . 2010-05-04 06:30743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.23019_none_1f15d8176ec16c09\iedvtool.dll + 2010-06-15 01:41 . 2010-05-04 05:55743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.18928_none_1e8094da55ac98be\iedvtool.dll + 2010-06-15 01:40 . 2010-05-04 06:30184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.23019_none_20344ff620f8e82a\iepeers.dll + 2010-06-15 01:40 . 2010-05-04 05:55184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.18928_none_1f9f0cb907e414df\iepeers.dll + 2010-06-15 01:41 . 2010-05-04 06:30387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.23019_none_57c137c08668408f\iedkcs32.dll + 2010-06-15 01:41 . 2010-05-04 05:55387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18928_none_572bf4836d536d44\iedkcs32.dll + 2010-06-15 01:41 . 2010-05-04 06:31919040 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\wininet.dll + 2010-06-15 01:41 . 2010-05-04 05:59916480 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\wininet.dll + 2010-06-15 01:41 . 2010-05-04 06:30611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.23019_none_c43671ebab5db8a4\mstime.dll + 2010-06-15 01:41 . 2010-05-04 05:56611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.18928_none_c3a12eae9248e559\mstime.dll + 2010-06-15 01:41 . 2010-05-26 14:54289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\atmfd.dll + 2010-06-15 01:41 . 2010-05-26 14:47289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\atmfd.dll + 2010-06-15 01:41 . 2010-05-26 14:35289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\atmfd.dll + 2010-06-15 01:41 . 2010-05-26 14:25289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\atmfd.dll + 2010-06-23 20:43 . 2010-04-14 16:27253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22670_none_4ba6b5206e120937\ehvid.exe + 2010-06-23 20:43 . 2010-04-14 16:15253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18459_none_4b3bb8e154dc1873\ehvid.exe + 2010-06-23 20:43 . 2010-04-14 17:52522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22670_none_cf021320e2be175a\ehui.dll + 2010-06-23 20:43 . 2010-04-14 17:45522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18459_none_ce9716e1c9882696\ehui.dll + 2010-06-23 20:43 . 2010-04-14 17:52105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22670_none_27068e6d7b50798e\ehPresenter.dll + 2010-06-23 20:43 . 2010-04-14 17:45105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18459_none_269b922e621a88ca\ehPresenter.dll + 2010-06-23 20:43 . 2010-04-14 19:00278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22382_none_2fd4fb80cf8bbccc\ehPlayer.dll + 2010-06-23 20:43 . 2010-04-14 18:23278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18242_none_2f769e65b64dad3e\ehPlayer.dll + 2010-06-23 20:43 . 2010-04-14 17:52278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22670_none_2df758f0d25f1909\ehPlayer.dll + 2010-06-23 20:43 . 2010-04-14 17:45278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18459_none_2d8c5cb1b9292845\ehPlayer.dll + 2010-06-23 20:43 . 2010-04-14 17:52373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22670_none_2f79d14e8378639a\ehglid.dll + 2010-06-23 20:43 . 2010-04-14 17:45373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18459_none_2f0ed50f6a4272d6\ehglid.dll + 2010-06-23 20:43 . 2010-04-14 17:20173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.exe + 2010-06-23 20:43 . 2010-04-14 17:11173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18459_none_33fce2ffda1a968b\McrMgr.exe + 2010-06-23 20:43 . 2010-04-14 17:52254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22670_none_14f56ee8b90922f1\ehReplay.dll + 2010-06-23 20:43 . 2010-04-14 17:45254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18459_none_148a72a99fd3322d\ehReplay.dll + 2010-06-23 20:43 . 2010-04-14 19:03180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6002.22382_none_d03f3d66e04a56b8\cbva.dll + 2010-06-23 20:43 . 2010-04-14 18:25180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6002.18242_none_cfe0e04bc70c472a\cbva.dll + 2010-06-23 20:43 . 2010-04-14 17:54180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22670_none_ce619ad6e31db2f5\cbva.dll + 2010-06-23 20:43 . 2010-04-14 17:46180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18459_none_cdf69e97c9e7c231\cbva.dll + 2010-06-15 20:17 . 2009-09-25 01:33829440 c:\windows\winsxs\x86_microsoft-windows-directx-warp10_31bf3856ad364e35_7.0.6002.18107_none_ddc19bafdeb30271\d3d10warp.dll + 2010-06-15 20:17 . 2009-09-25 01:30481792 c:\windows\winsxs\x86_microsoft-windows-directx-dxgi_31bf3856ad364e35_7.0.6002.18107_none_2ddc701ea6935db8\dxgi.dll + 2010-06-15 20:17 . 2009-09-25 01:31519680 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d11_31bf3856ad364e35_7.0.6002.18107_none_e31646a255b2bb52\d3d11.dll + 2010-06-15 20:17 . 2009-09-25 01:30190464 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10_31bf3856ad364e35_7.0.6002.18107_none_e3165d6a55b2a1b1\d3d10core.dll + 2010-06-15 20:17 . 2009-09-25 01:31218112 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10.1_31bf3856ad364e35_7.0.6002.18107_none_438775313198baea\d3d10_1core.dll + 2010-06-15 20:17 . 2009-09-25 01:31161280 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10.1_31bf3856ad364e35_7.0.6002.18107_none_438775313198baea\d3d10_1.dll + 2010-06-15 20:17 . 2009-09-25 01:31486912 c:\windows\winsxs\x86_microsoft-windows-directx-d3d10level9_31bf3856ad364e35_7.0.6002.18107_none_d6bc647e27993a91\d3d10level9.dll + 2010-06-15 20:17 . 2009-09-25 01:27793088 c:\windows\winsxs\x86_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_7.0.6002.18107_none_f80806179955d90c\FntCache.dll + 2010-06-15 20:17 . 2009-09-25 01:31828928 c:\windows\winsxs\x86_microsoft-windows-d2d_31bf3856ad364e35_7.0.6002.18107_none_9afade8fe3f79d22\d2d1.dll + 2010-06-15 20:17 . 2009-09-25 01:33195584 c:\windows\winsxs\x86_microsoft-windows-d..x-directxdiagnostic_31bf3856ad364e35_7.0.6002.18107_none_17218ffde5ca9cc0\dxdiagn.dll + 2010-06-15 20:17 . 2009-09-25 01:32252928 c:\windows\winsxs\x86_microsoft-windows-d..x-directxdiagnostic_31bf3856ad364e35_7.0.6002.18107_none_17218ffde5ca9cc0\dxdiag.exe + 2010-06-15 20:17 . 2009-09-25 01:38847360 c:\windows\winsxs\x86_microsoft-windows-component-opcom_31bf3856ad364e35_7.0.6002.18107_none_9694f99f3a97a698\OpcServices.dll + 2010-06-15 20:17 . 2009-09-25 01:35135680 c:\windows\winsxs\x86_microsoft-windows-c..nt-xpsrasterservice_31bf3856ad364e35_7.0.6002.18107_none_0dfb54ccb407a2d9\XpsRasterService.dll + 2010-06-15 20:17 . 2009-09-25 01:36280064 c:\windows\winsxs\x86_microsoft-windows-c..ent-xpsgdiconverter_31bf3856ad364e35_7.0.6002.18107_none_064a6d5573576b79\XpsGdiConverter.dll + 2010-06-15 01:40 . 2010-01-06 16:01173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22303_none_0e995261088a03df\AcXtrnal.dll + 2010-06-15 01:40 . 2010-01-06 16:01542720 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22303_none_0e995261088a03df\AcLayers.dll + 2010-06-15 01:40 . 2010-01-06 15:38173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18179_none_0dca05f7ef9fc28f\AcXtrnal.dll + 2010-06-15 01:40 . 2010-01-06 15:38542720 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18179_none_0dca05f7ef9fc28f\AcLayers.dll + 2010-06-22 20:03 . 2010-04-16 16:08173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22672_none_0c6630bb0b9d58fb\AcXtrnal.dll + 2010-06-22 20:03 . 2010-04-16 16:08541696 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22672_none_0c6630bb0b9d58fb\AcLayers.dll + 2010-06-22 20:03 . 2010-04-16 16:05173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18461_none_0be661abf27886c2\AcXtrnal.dll + 2010-06-22 20:03 . 2010-04-16 16:05541696 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18461_none_0be661abf27886c2\AcLayers.dll + 2010-06-15 01:40 . 2010-01-06 16:01458752 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.22303_none_0e985217088aea88\AcSpecfc.dll + 2010-06-15 01:40 . 2010-01-06 15:38458752 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.18179_none_0dc905adefa0a938\AcSpecfc.dll + 2010-06-22 20:03 . 2010-04-16 16:08459776 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.22672_none_0c6530710b9e3fa4\AcSpecfc.dll + 2010-06-22 20:03 . 2010-04-16 16:05459776 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.18461_none_0be56161f2796d6b\AcSpecfc.dll + 2010-06-15 01:41 . 2010-03-04 12:53258048 c:\windows\winsxs\msil_system.security_b03f5f7f11d50a3a_6.0.6002.22354_none_851a050be8358bb4\System.Security.dll + 2010-06-15 01:41 . 2010-03-04 12:53258048 c:\windows\winsxs\msil_system.security_b03f5f7f11d50a3a_6.0.6002.18222_none_9be4d87dce90ac67\System.Security.dll + 2010-06-15 01:40 . 2010-04-12 12:22970752 c:\windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41\System.Runtime.Serialization.dll + 2010-06-15 01:40 . 2010-04-12 12:21970752 c:\windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531\System.Runtime.Serialization.dll + 2010-06-15 01:40 . 2010-04-12 12:22970752 &nbsPlease try again. The CFScript was spelled like this: c:\users\Dawn\Desktop\CFScript.txt.lnk\ Go to My Documents folder, click Tools > Folder Options. Click the View tab. Find "Hide extensions for known file types" and uncheck that. Click Apply, then OK. Then, for CFScript.txt rename it to only say CFScript.txt Then drag it in to ComboFix like I instructed earlier. |
|
4412. |
Solve : Some sort of malware happened, and now my computer can't connect to the internet? |
Answer» About a week and a half ago, I was downloading a toolbar and some malware[at least I'm farily certain it's a malware.] infected my desktop; which now cannot connect to the INTERNET. I'm writing this on my laptop. |
|
4413. |
Solve : Recommendations for Internet Security Software Please? |
Answer» I'd like some RECOMMENDATIONS for the BEST internet security software, either free or not. My NORTON subscription is about to run out and I've had trouble renewing it. At this point, I'm ready to TRY a new supplier. |
|
4414. |
Solve : Rootkit, Winsock Error, Redirected Searches, Task Bar color change? |
Answer» Here is the RootRepeal Log.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Wow, 33 items found, was this expected? [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=a0d5c9e1b047ac48af0108484ba6a6e9 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-06-10 05:13:14 # local_time=2010-06-09 10:13:14 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 4507239 4507239 0 0 # compatibility_mode=3073 16777213 80 92 0 11094560 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=77165 # found=33 # cleaned=33 # scan_time=8895 C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ubxo.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Documents and Settings\Default User\Start Menu\Programs\Startup\gyqig.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Documents and Settings\Jon\Application Data\Kuyzwe\omzun.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Documents and Settings\Jon\Application Data\Sun\Java\Deployment\cache\6.0\46\2ef6a5ae-29c19df4a variant of Java/TrojanDownloader.Agent.NBE trojan (deleted - quarantined)00000000000000000000000000000000C C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\43120580-4af80629a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\30feb821-6a642e70a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\5473416c-2e86c9caa variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\63\43e0867f-1c23f9a1probably a variant of Win32/Agent trojan (deleted - quarantined)00000000000000000000000000000000C C:\Program Files\Unlocker\eBay_shortcuts_1016.exea variant of Win32/Adware.ADON application (deleted - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\system32\mirepcmw.dll.vira variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\imapi.sys.virWin32/Olmarik.ZC trojan (cleaned - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP36\A0018169.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022896.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022906.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026253.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026255.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026256.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029852.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029853.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029883.dlla variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030305.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030306.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032444.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032446.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032447.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035015.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035016.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036642.sysWin32/Olmarik.ZC trojan (cleaned - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036698.dlla variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039289.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039290.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039291.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039292.exea variant of Win32/Adware.ADON application (deleted - quarantined)00000000000000000000000000000000C [recovering disk space - old attachment deleted by admin]The most of these are duplicates and most were in System RESTORE. * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above PROCEDURE will: * Delete the following: * ComboFix and its associated files and folders. * RESET the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ============================== Download OTC by OldTimer and save it to your desktop. 1. Double-click OTC to run it. 2. Click the CleanUp! button. 3. Select Yes when the "Begin cleanup Process?" prompt appears. 4. If you are prompted to Reboot during the cleanup, select Yes 5. OTC should delete itself once it finishes, if not delete it yourself. If there are any tools/programs left, install them or delete them. ============================== Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ================================= Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - SEARCH & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!I have been away for a couple days. Just finished your LAST suggestions. Thank you so much. The computer is running really well and I am very happy with the results. You turned a source of frustration and anger into a workable and enjoyable experience. I learned as I went and really appreciate your help. |
|
4415. |
Solve : topic locked? |
Answer» what/s it mean when a "topic is locked" i asked aquestion about au.exe but got a reply that it/s been locked by "super dave " who/s super daveYou should post a question once only. Second or third threads ASKING the same question will get locked. |
|
4416. |
Solve : Can't remove rogue malware? |
Answer» Please delete this one: ALCMTR.EXE C\WINDOWS It is spyware installed with Realtek AC97 Audio.OK..IHOPE I removed everything properly from HIJACK THIS step. Not all of them were on the scan all but I think I deleted all of he ones tht matches your list. Here is the new log, just in case: |
|
4417. |
Solve : W32.Silly FDC.. what to do? plz? |
Answer» Hi great CH members. I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.You'll have to elaborate little bit more on the above. Meanwhile... *** You need to update Java: http://java.sun.com/javase/downloads/index.jsp Java Runtime Environment (JRE) 6 Update 6 Uninstall all previous versions of Java through Add\Remove. *** Disable Windows Defender, as it'll interfere with cleaning process: * Open Windows Defender * Click Tools * Click General Settings * Scroll down to Real Time Protection Options * Uncheck Turn on Real Time Protection * After you uncheck this, click on the Save button * Close Windows Defender 1. Print this post out, since you won't have an access to it, at some point. 2. Close all windows, except for HijackThis. 3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed): - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) - *O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot - *O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe - *O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') - O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) - O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) - O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing) - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 4. Click on Fix checked button. 5. Restart computer. 6. Post new HijackThis log.Hi Sir, Concerning Java, which one to download (windows offline installion or windows online installion)? and which platform to choose (Windows , windows x64) Shall I uninstall all previous versions of java after updating java? Thanks for being tolerant with me. Normally, I install off-line. Select Windows (not 64), and, yes, uninstall all previous versions.Hi again, After clicking on Fix checked button, a new window of HJT suddenly appears stating that an unexpected error has occured at procedure: - O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) - O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) - O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing) - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll Error #5 Invalid procedure call or argument Besides, after fixing finished, a window appears telling that HJT is not running correctly. This is the new HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:54:18 ص, on 26/06/08 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16681) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\WerCon.exe C:\Program Files\TOSHIBA\Utilities\KeNotify.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Windows\RtHDVCpl.exe C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user') O4 - Global Startup: Bluetooth Manager.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing) O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- End of file - 11254 bytes Quote from: Broni on JUNE 20, 2008, 06:38:39 PM QuoteI've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.You'll have to elaborate little bit more on the above. Ok .. When opening the C driver, I'd see empty and transparent folders like: $Recycle.Bin , shortcut of Documents and Settings, System Volume Information... Inside Program Data Folder on C again, you'd find shortcuts of Application Data, Desktop, Document, Favouarite, Start menue, Templates. Again they are all empty. And i'd see files like: autoexec.bat, config.sys , IO.sys .... and the like. Once opening Username Folder, I'd find files like: ntuser.dat.log1 , ntuser.dat.log2, ntuser.dat (BLF file), ntuser.dat (Regtrans-ns file), and ntuser.ini (config setting) Once opening any folder containg a movie, I'd see $$Jet.THM$$.cache (cache file) I'd find similar folders and files everywhere. Mostly they are shortcuts or empty folders. Once I tried deleting them, it's said that they contain a system file like desktop.ini and i cant remove them. This is what makes me post here. My laptop was just brand clean but out of the blue these bugging folders are everywhere. My Best Regards, |
|
4418. |
Solve : I have a worm? |
Answer» have to upload ONE more updateResults of screen317's Security Check version 0.99.4 |
|
4419. |
Solve : Uninstalling AVG? |
Answer» Hi all, I really want to uninstall AVG 8.0.437 (FREE edition), but it wouldn't: everytime I lunch the program's uninstaller (or using the Windows Add/Remove PROGRAMS) it always tells me Uninstall failed, 1 error occured, and that is... |
|
4420. |
Solve : MP3, VIDEOS, MUSIC? |
Answer» Hi everyone, i really need your help, how can i get rid of this kind of virus: MP3, VIDEOS, MUSIC.
|
|
4421. |
Solve : Sas log, missing taskbar, start menu, no sound, can't copy, etc.. error 372, vba? |
Answer» THANKS SUPERDAVE, i WENT AHEAD and reinstalled windows xp SP3. thanks | |
4422. |
Solve : how do I find out what programs are trying to acces the internet through my comp? |
Answer» Quote and can't WAIT to make it my default browser again, but do you think it is unsafe? II really can't say anything about Google Chrome. You should post this question on the software forum. I'm sure you will get MANY opinions there. Quote Also, just out of curiosity, what browser do you use?I use IE 8 as my default but occasionally I use FireFox. Quote I would appreciate having an alternative (other than firefox and internet EXPLORER).You could always try Opera. |
|
4423. |
Solve : VMWare image maybe infected? |
Answer» hello how can i clean virus/trojan from VMWare image? Same as with ordinary installation - install and/or run antivirus program. if i install antivirus on VMWare Image, I have to UPDATE it. what about sharing Drive,which OS installed, and scan it on my PC? from My Network Place? Quote from: k_mohsen on July 07, 2010, 12:06:26 PM if i install antivirus on VMWare Image, I have to update it.Yes... and? Quote what about sharing Drive,which OS installed, and scan it on my PC? from My Network Place?The moment you share the drive is the moment you expose your PC to the spread of any malware that is in the image file to the host machine. Besides, I can't think of any AV program that can scan a network path anyway. I have Windows 7 64 bit (host OS) which has Avira Free antivirus. I run XP 32 bit (guest OS) in a VMWare virtual machine and it has its own Avira installed. |
|
4424. |
Solve : Possible Rootkit - need verification? |
Answer» A REINSTALL is the only true way to ever know everything is gone. With the changing results on each scan I would advise to go forward with it. Chalk it up to a learning experience. Nothing is truly free, a high percentage of cracks and such install EXTRA baggage unknowingly to users. Identity theft is not uncommon but they will steal anything they can INCLUDING all of your software keys.First of all I would like to thank you for all you help ! The replies were fast, accurate and easy to understand That's support. |
|
4425. |
Solve : My computer really freaked out last night!? |
Answer» I booted up and logged on to the web, then I started getting Trojan warnings from my McAffee. I got off the web and my desk top picture went away to a default?( blue) with something wanting me to download some anti spyware stuff. I think I picked the bug up on a torrent site. Why would people act like they are sharing things, just to load this junk?Those torrent sites can be risky, thats for sure, if I use them I try to stick to Demonoid, pretty safe site....Your Hijack log looks clean from my untrained eye but you should wait for one of the Malware experts to check it out. BTW, what are you using for protection beside McAfee and AVG Antispyware?snap well to prevent anything else from getting throught get comodo Firewall http://www.personalfirewall.comodo.com/Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode. To ENTER Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * OPEN SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are CHECKED (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and REMOVAL is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RECONNECT TO THE INTERNET RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Post new HijackThis log.Hello Broni, I followed your instructions. 1. In safe mode I ran the SuperAntispyware. Full scan. It found nothing! 2. In normal mode, I ran MalwareBytes. Full scan. It found nothing! 3. In normal mode, I ran HJT. The log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:30:59 PM, on 6/19/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Eraser\Eraser.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [StxTrayMenu] "F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: VPN Client.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Hydraquip.com O17 - HKLM\Software\..\Telephony: DomainName = Hydraquip.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Hydraquip.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Hydraquip.com O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: Seagate Sync Service - Unknown owner - F:\ceedo\Program Files\Seagate\Sync\SeaSyncServices.exe (file missing) -- End of file - 6079 bytes My uneducated guess is that the scans from yesterday did the trick.? JimIt looks like.... Your computer is clean 1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html. Run CCleaner. 2. Turn off System Restore: - Windows XP: 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore". 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. - Windows Vista: 1. Click Start. 2. Right-click the Computer icon, and then click Properties. 3. Click on System Protection under the Tasks column on the left side 4. Click on Continue on the "User ACCOUNT Control" window that pops up 5. Under the System Protection tab, find Available Disks 6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:") 7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this. 8. Click OK 3. Restart computer. 4. Turn System Restore on. 5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program 6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html Hey Broni, Thanks for all of your help. You and the other volunteers here do an outstanding service for us lay people out there and is very much appreciated. Thanks again, JimYou're welcome:) Computer doing OK? |
|
4426. |
Solve : Request Assistance: Trojan and Virus deletion failure? |
Answer» You're WELCOME |
|
4427. |
Solve : AVG advice please? |
Answer» At present I have AVG Antispyware version 7.5.1.43 free edition and also AVG Anti virus version 7.5.519 free edition.. |
|
4428. |
Solve : Can Anybody help?? |
Answer» I have a toshiba laptop with windows xp home edition. I THINK I may have a virus or some malware due to SEVERAL things. When i LOAD internet explorer pages only part of the page will load(icons, text boxes, etc remain blank). When I search for something on a search engine the page comes up completely blank. Mozilla Firefox works fine. Also all basic programs run slow and freeze on a regular basis. I have windows live onecare and it can not find any viruses or spyware. Any advice on what the problem might be?What information should I add when submitting a question?The problem has been occurring for several WEEKS. It has been getting worse. First, it was just slow, then the internet pages started not loading, then search engines stopped working. I have service pack two installed but not 3 because my computer would not start with it installed. There are 64 gb on my computer with 16 used. IM using IE 7.Close IE. |
|
4429. |
Solve : Need advice about Anti Virus/Spyware that installed on computer? |
Answer» After lurking around in this forum, I've learned that it's best to have only 1 of anti virus and 1 of anti spyware install on the computer. But I saw all of this program being installed on my daughter PC; Nod32, Spybot-Search & Destroy, HijackThis, Ad-Aware, (SmitfraudFix, VundoFix, these two were installed recently to get rid of trojans, should I uninstalled them?) and Error Repair Professional. |
|
4430. |
Solve : computer needs windows reinstalled? |
Answer» YEP In that CASE, we'll NEED that WINDOWS CD. |
|
4431. |
Solve : problem after running first spybot S & D? |
Answer» Took them about 6 YEARS to DECIDE it isn't. I downloaded a tool that is SUPPOSED to find the verification number; it isn't accepted |
|
4432. |
Solve : Hi There, Suggestions ? Bogus Microsoft Trojan Virus Scan / Phishing Site? |
Answer» Symptons:
Thank you in advance for any ideas or suggestions! [/list]Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any PROBLEMS while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RECONNECT TO THE INTERNET RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the PROMPTS to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the LATEST version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can ALSO be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log.I will do this. thank you!Attached is the complete log file. Is it obvious how I let it in? Should I switch to SAFARI? thank you again! [recovering disk space -- attachment deleted by admin]All I need is HJT log.Hi Broni, what is the HRT log? I only see the mbam log.Quote 3. Download HijackThis: |
|
4433. |
Solve : Explorer.exe auto closing? |
Answer» Hey, heres my situation. Every time i open explorer.exe, or when the comp starts, it closes right back out. Then it tries to open back up, and then closes back out over and over until i close it out manually. I think theres a program doing it but i dont know. Logfile of HijackThis v1.99.1Let me clarify. Shutting down happens to Windows Explorer only? Otherwise computer is working OK? Advanced Windows Care is pretty good program, and I believe, it creates backup. Also, your HJT version is outdated. Download HijackThis from here: http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download Click on Download HijackThis Installer POST HijackTHis log.Only windows explorer (explorer.exe) closes out by itself. And everything else is fine. Thanks for the tip about that HJT thing i saw 2 things that are probably malware already Im probably gonna delete those and tell u what i get in a minute, but i might just wait for ur opinion since ur online now. Heres the new log: Quote Logfile of Trend Micro HijackThis v2.0.2Don't play with HJT, unless you're 100% sure what you're doing. I'll reply shortly.You have few nasties there. Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options MAKE sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RECONNECT TO THE INTERNET RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Post new HijackThis log.doing now thankswell i guess theres no need to post that log, u fixed it thanks alot man have a good oneLack of symptoms does not gurantee all of the malware is gone. It is advised to continue posting any requested logs until given the all clear by a Malware Removal Specialist.As evil said.... |
|
4434. |
Solve : Online Malware Removal?? |
Answer» I am about to replace my old IBM Thinkpad with a new one from Lenovo. I WOULD like to copy data and some applications from the old machine to the new one. But I do not wish to import malware that may be buried in the old machine into the new one. Is there an online service to which I could upload any files to be transferred and which would subject them to a thorough, guaranteed malware removal process? I could upload any files to be transferred and which would subject them to a thorough, guaranteed malware removal process? These clean what they find.
Thank you very much for the information provided in your reply to my POST. Most appreciated. Bill Breidenbach |
|
4435. |
Solve : Internet Explorer - Firefox.? |
Answer» I'm using FIREFOX as my browser and like it. Can I DELETE Internet EXPLORER? |
|
4436. |
Solve : Rootkit? |
Answer» I'm not evil. Girls are evil!! |
|
4437. |
Solve : Missing Desktop icons and toolbar? |
Answer» everytime i START up my pc i get an error explorer.exe 0x0000006. i can only use the task manager to navigate. heres my HIJACKTHIS log btw |
|
4438. |
Solve : "Privacy components"? |
Answer» window entitled "privacy components" keeps popping up on PC; what is this? is it POSSIBLE to DISABLE this window?That is a ROGUE Security Program. |
|
4439. |
Solve : Malware/Spyware problems (logs attatched)? |
Answer» ok my computer is actually running pretty fast now! thanks!
. The above procedure will:
---------- Use the Secunia Software INSPECTOR to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, SPAM, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
4440. |
Solve : pc is slower after installing 3 GB RAM? |
Answer» I recently installed 3 GB RAM and my pc which has windows vista on an acer 5100 notebook,was running great when I first put in the new RAM. It is now so slow a turtle could run faster than it. Is the problem in the websites I go to and or is it the hard drive? I think it is cluttered with junk from all these websites and adware I don't know. Where can I and how much to fix this issue? I'm about to get fed up with the darn thing. Any help would be great thanks.If you think it's a malware issue then go HERE and WORK steps 2 and 4. If step 4 doesn't turn up anything then it likely isn't a malware issue.I'm a beginner don't forget. I don't know what it is. That's what I asked for so still do the steps anyway? Thanks.It should be easy to rule in or out malware by running the MalwareBytes scan. Where do I get the Malwarebytes scan at?Go to Evilfantasy's 1st reply, click "Here" it is blue in color, then once you are at that page, Where do I get the Malwarebytes scan at?also, in addition to malwarebyte, you can go get a-squared free for a second opinion, as programs don't detect everything 100%. Here's the link to get a-squared free. HTTP://filehippo.com/download_asquared/ This is just if you want a second opinion to DOUBLE check and like Malwarebyte software, they both update everyday so should be good.Please don't install a=squared. We need logs. Without them we don't know what we are dealing with or how to fix it. @joepinger - You have to read my replies carefully. All of the information you need will always be there.Quote from: evilfantasy on March 13, 2009, 06:13:40 AM Please don't install a=squared. We need logs. Without them we don't know what we are dealing with or how to fix it. I never said you needed it, i meant if you wanted A-Squared free later, as a double check afterwards when malware cleaning process is done. |
|
4441. |
Solve : Malware Biten.? |
Answer» I am getting an run time error o, and 440 when I try to start up MALWAREBYTES. Tried to uninstall but error messages POP up and cannot uninstall from add and remove. ALSO this happened after I ran a Hijackthis log and deleted a wotdll something or other. windows PROCESS log tool recommended to delete it.Update, I downloaded malwarebytes again and updated it. solved problem. |
|
4442. |
Solve : Please review logs. Cleaning up laptop and following your steps? |
Answer» i'm cleaning up my wife's lap top. i have followed all steps as instructed. she is running vista. oh, i didn't disable teatimer because i dont know if its on this system. i couldnt find the "padlock" icon on my system tray. so let me know what steps i need to take next.
[attachment deleted by admin]Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixhere is combo fix logs. Also i'm not used to her lap top but should i be running windows defender with superantivirus? i have them both enabled. [attachment deleted by admin]Download the Norton Removal Tool (SymNRT) to your Desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart.
---------- Use the ESET Online Antivirus Scanner This scanner REQUIRES Internet Explorer 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. MAKE sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.i used the norton removal from the desktop and it worked fine. I ran it again as requested then i removed the it from the desktop. I have tried teh ESET link but it is not working. I have intsalled the active X as it requested but it isnt doing anything. I click the start but it shows a message on the small box on the screen. It says it cannot Error: Cannot intialize OnlineScanner. Administrator rights required. I'm not sure how to get around this problem.Try this instead. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
I will wait for a reply before making another scan because it takes about two to three hours to run this scan. Try running i tin Safe Mode. |
|
4443. |
Solve : Noob in need of some major help.? |
Answer» So basically EVERY day that I log onto my laptop, My Spy Sweeper virus protection pops up saying something about "A Potentially Harmful File has been QUARANTINED" or something to that extent and EVERYDAY it's EXACTLY the same thing: Virusburst Fakealert. So I go to the quarantined files and delete it but it keeps coming back. |
|
4444. |
Solve : My Houdini computer? |
Answer» Yesterday, I downloaded Stopzilla (it seems to be a good utility) Now once in awhile I have a problem keeping PAGES open. I open a PAGE and it downloads and then disappears automatically. It doesn't happen with all the websites;however, it is annoying. I input the URL again, and the same thing happens. It starts to load and either it disappears during the load or shortly after the page comes up. I wanted to remove the Stopzilla file but I thought I ask first. I checked Spybot S/D & Adaware. They come clean so I just am at wits end. |
|
4445. |
Solve : Pretty sure I might have something nasty? |
Answer» So, let's start from the beginning. I went to FPSbanana.com to download a map for Team Fortress 2. I usually don't need to do that, but the server that I was playing on didn't upload the map, so I had to do so manually. So I click 'Download' and then this fake online scanner 'scanned' my computer and said that I had some odd viruses. I closed out of it, knowing that it was fake, but ever since after that, I've been getting lower FPS in games and everything loads slower. I might just be paranoid, but here are my logs. Machine specs ? ? 9600 GS Core 2 Duo (2.0 GHz) 4GB of RAM 320GB Hard DriveDo you think opening up my laptop and cleaning out my fans would help?That online virus scanner said that I didn't have a virus. I'm thinking about just formatting.Quote from: Popolop on March 12, 2009, 01:45:21 PM Do you think opening up my laptop and cleaning out my fans would help? I don't think that is very wise to open a laptop. unless you now what you are doing that is. Try making a post in the Windows forum. This isn't a malware issue and nobody is seeing this thread in this forum. |
|
4446. |
Solve : Voices in background at startup? |
Answer» As soon as I start-up windows, I hear a few clicks like as if I pushed enter to go to a new URL, then VOICES come on like a movie advertisement. It's not a RADIO pick-up, either. I JUST INSTALLED windows xp and then this... |
|
4447. |
Solve : autorun.inf worm removal? |
Answer» Hello again,
Should I do all this on the Desktop PC with the flash drive attached to clean those out to or, is there a different procedure for the autorun.inf worm?? Sorry I missed that the first time through. Use this for any flash drive you have used on the infected computer. Flash Drive Cleanup Download Flash Disinfector by sUBs and save it to your Desktop.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection. Will be awaiting the RSIT log...quote author=PatriciaW link=topic=78698.msg518498#msg518498 date=1236883936] I was wondering the same thing myself. I followed everything I was suppose to do and still no reply.. I SEE they answer others with hijack logs.... If they won't answer and don't have the knowledge why make it SOUND like they do in the first place? waste of my time going through all that stuff and then no ONE will help me anyway. False advertising I might add... Free computer help for EVERYONE.. I will go else where from now on and tell others to do the same. Have you tried majorgeeks.com??? That's where I am heading.. good luck with your situation.. [/quote] take your time and wait this time , not like above , help is not at hand for every-one on tap , harryYup, leave the attitude at the door, lady. Trust me you will have a much longer wait at MG's. They usually have at the least a 3 day turn around on the first reply. And their pre-steps are much more involved. Good luck!!Evil fantasy thank you for your help even after my attitude on the other post. Its just frustrating not being able to fix things on my own.. I haven't had any computer training I learn as i go. no one was born with this knowledge. it's taught to you. Even big companies get a virus so for Dias to act like I'm an idiot for getting a virus is uncalled for if he can't help me then don't answer posts that wasn't addressed to him. . I have never posted to a forum before and didn't understand why you skipped me and helped others that posted after me once again sry bout the attitude and thanks for the help. here are the logs you asked for... [attachment deleted by admin]Quote from: evilfantasy on March 12, 2009, 01:28:47 PM Sorry I missed that the first time through. Antivir found a worm while downloading it..so i didn't open it.I found out it's a false positive.. so I am trying it again...Many of the tools I will have you use will be flagged by Avira. The way they work is similar to that of malware. Fight fire with fire... Don't let Dias bother you. He is somewhat likable once you figure out he has that attitude with everyone. Right Dias? Be right back. Looking at the logs now.Quote from: evilfantasy on March 13, 2009, 10:57:59 AM Don't let Dias bother you. He is somewhat likable once you figure out he has that attitude with everyone. Right Dias? More or less. I just can't stand people who come on here badmouthing the "service" they get (or don't get), and/or expecting to be at the head of the queue. I still find the title of this thread objectionable. OK back to business now. Everyone can play nicely long enough to take care of this I hope. Do you know what this is? Quote O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing) If not then please scan it. Please go to VirusTotal.com (If more than one file needs scanned they must be done separately and logs posted for each one) 1. Copy the file path in the below Code box: Code: [Select]C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe2. At the upload site, click once inside the window next to Browse. 3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. 4. Next click Send File Your file will POSSIBLY be entered into a queue which normally takes less than a minute to clear. This will perform a scan across multiple different virus scanning engines. Important: Wait for all of the scanning engines to complete. 5. Copy and then Paste the link to the results in the next reply.I tried to scan the file and it said path don't exist. I'm pretty sure it's an old music file I transferred via the USB flash drive. The date on the file is from 2006 and I didn't have this laptop at that time.I scanned it with antivir and the malwarebytes neither of them detected anything. I was working on the desk top most of the afternoon. I have dial up so everything takes forever to download and i have to keep switching the TELEPHONE cord to whichever computer i am working on.. lol anything else i need to do?? thanks again.. Quote from: PatriciaW on March 13, 2009, 02:28:25 PM I have dial up so everything takes forever to download and i have to keep switching the telephone cord to whichever computer i am working on.. lol anything else i need to do?? thanks again.. I will try to use all small tools so it doesn't take too long to download. Do you want to get rid of that service since you don't use it anymore or do you need it? Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there)
Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis.Ok.. here is a new log from hijackthis. which service were you asking about??? my dial up or something else? [attachment deleted by admin] |
|
4448. |
Solve : New computer horrible performance. Infected?? |
Answer» Your welcome!!!
I use Cyberdefender anti-virus all of the time. I GOT the free anti-virus scanner first off there WEBSITE which found a lot of stuff on my system and got rid of the spyware and Trojans. I also had viruses, so I bought the upgrade which got rid of everything on my system. The version that you pay for comes with 24/7 computer help, which I have used twice and they were very helpful. Does that help?Second forum you have posted in one of my malware removal threads about using CyberDefender hankfarkas. I'm going to start treating it as spam and removing them. CyberDefender has very questionable sales tactics. Very similar to that of rouge software. |
|
4449. |
Solve : http://liveantimalwareproscan.com WINDOWS or SCAM?? |
Answer» So, I'm reading my emails. I never EVER open an email from an unknown sender, I just delete them. I clicked on a trusted email from a company that I do surveys for and instantly my browser closed and another opened! |
|
4450. |
Solve : Please help ... unrecognized Windows files ... don't know if I can reboot? |
Answer» I have:
---------- Use the In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.I've been running this Kaspersky scan for a couple hours now. It was scanning slowly, but was scanning. For about the past 40 minutes or so its been stuck at 69% and is stuck at the same number of files scanned 43,232. It says there is one threat, one infected object. I believe this is the point where it stopped but I don't know for certain because I wasn't watching it constantly. It says ... now scanning: HALAPIC.DL_ and location: C:\cmdcons Do you think its stuck and no longer running? Or should I let it run overnight and see what happens? Thanks! If it doesn't continue soon then stop it and use Dr Web instead. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
I checked it this morning and there was a question of whether or not I wanted to 'move' something. I said YES to all. After it completed its run, I saved a copy of the log to the desktop. Then I rebooted my computer. That was about 3 hours ago. I just went downstairs to check my computer (I'm on my husband's computer right now) and it is still showing the blue Windows screen that says WINDOWS IS SHUTTING DOWN. About an hour ago I tried to help it shut down all the way by pressing CTRL+ALT+DEL but nothing happened. I don't know what to do at this point. Should I hold the on/off button until it shuts down? Or will that undo everything that DrWeb has done in its scan? Please advise. Thanks!Hold the on/off button until it shuts down. The log should still be on the desktop.Here is the DrWeb log: NULL;C:\;Trojan.DownLoader.324;Deleted.; install.htm;C:\;Exploit.DialogArg;Deleted.; uinst_cp.exe;C:\WINDOWS\SYSTEM32;Adware.CasProg;; RxUser.exe;C:\Program Files\Dell\Resolution Assistant\Common\bin;Trojan.Spambot.origin;Incurable.Moved.; Uninstall.exe\SkillJamLoader.dll;C:\Program Files\SkillJam Technologies\Secure Player\Uninstall.exe;Program.PopcapLoader.4;; Uninstall.exe;C:\Program Files\SkillJam Technologies\Secure Player;Archive contains infected objects;Moved.; 01129984.FIL.OLD;C:\$VAULT$.AVG;Adware.Bho;; 08137240.FIL.OLD;C:\$VAULT$.AVG;Trojan.Inject.351;Cured.; 08982035.FIL.OLD;C:\$VAULT$.AVG;Trojan.Inject.351;Cured.; 33135219.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.; 33136160.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.; 19503571.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.; 57809879.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.489;Deleted.; 28995633.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.489;Deleted.; 45116527.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.; 45117208.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.; 11073900.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.; 11074991.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.; SkillJamLoader.dll;C:\Documents and Settings\All Users\Application Data\SkillJam\SecurePlayer;Program.PopcapLoader.4;; A0065913.exe;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Spambot.origin;Incurable.Moved.; A0065921.exe\SkillJamLoader.dll;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129\A0065921.exe;Program.PopcapLoader.4;; A0065921.exe;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Archive contains infected objects;Moved.; A0065922.OLD;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Inject.351;Cured.; A0065923.OLD;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Inject.351;Cured.; |
|