Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

4401.

Solve : Is E-excelleration or Stopsign good??

Answer»

My parents are paying for stopsign and she was wondering if this was a good program? I was telling her how you helped me. What are the best ones out there to catch everything for those of us who don't know that much about computers. We are just wondering if you could point us in a direction.

Thanks,

ChristalThey are both ROGUES, and are not recommended.

They are listed in some HOSTS files as well:

http://hosts-file.net/?s=stop-sign.com
http://hosts-file.net/?s=eacceleration.com

with classification: EMD.

EMD=Engaged in malware distribution.Thank you for the information.

They have been paying a yearly fee for this "security". What do you suggest they do? What TYPE of program should they be using... It is a Vista OS.Attempt to get refund.

Go with something much more trusted, which would be:

Avira Free, or Premium: http://www.avira.com (Premium is a low cost, and powerful SOLUTION.)
Kaspersky Antivirus: http://www.kaspersky.com
ESET Nod32 Antivirus: http://www.eset.com
Avast Free antivirus: http://www.avast.comThank you again. They chose Avast. They are on dial up and evidently it takes 13 hours to download...they started the download then stopped it now it appears they can't go back to it now.... I am 18 hours away. LOL

4402.

Solve : hard drive filling up?

Answer»

was told to post here since i might have virus or something.

couple weeks after i upgraded from windows vista to windows 7 my hard drive been saying its full when i have like NOTHING. it makes my INTERNET use show up all weird and says not enough memory.. when i try to clean up the hard drive which theres nothing to clean up besides temporary internet files and thumnails. after doing that im ABLE to use net to the fullest for about 1-2 days sometimes less and then i have to repeat the process. i dont know wats making the hard drive full. any help??

Only (C) drive is filling up nothing happens to (D) drive. Please go to this link and follow the directions and post the required logs. well guess WAT i went to the link u posted and since my antivirus isnt working properly any more and as stated on one of the steps i had to download a new working anti virus i uninstalled my current antivirus which was kasperky antivirus and it solved the problem!!!! i am suprised that a simple antivirus program would be filling up my hard drive!! i am still wondering why it would be filling up my hard drive?? but EVERYTHING is back to normal i guess i just need a new anti virus now.I doubt that your problem is completely solved. You should follow the link in SuperDave's post and follow all instructions therein.

4403.

Solve : Trojan,Adware,Malware?

Answer»

Thank you for your time in advance. I just got this computer from another person, and I followed the Malware Removal Guide on this website to a T. I have fully updated versions of AVG, Online Armor, SUPER Anti-Spyware, Malwarebytes anti-malware. Again I've followed that guide to a T. Since I am not an expert at this, how do I know if my computer is 100% clean and safe to use? I have sensitive data that I need this computer for, but I'm not going to start until I know it is 100% clean. I also have the logs for anti-spyware, MBAM, and hijackthis ready and waiting on my desktop. Thank you for your time and help.If you don't know the history of the computer, the only way to know that it is absolutely clean is to do a re-format and re-install the Operating System. The computer may have had some serious infections that may have compromised the security of the machine. I've included the warning below that we give to those whose computers have been affected. This is very important especially if you're going to use this computer for financial transactions. We can run scans and check the logs but we can't guarantee it's security.

A backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

I would counsel you to disconnect this PC from the Internet immediately.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very LIKELY compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall?

We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next postI don't have any personally or financially identifiable information on this computer. And I won't start either. This is a home PC with Windows XP service pack 2 running. I use this computer for surfing the internet/watching movies/video games/ and music. Nothing else. I would like to go ahead and try to secure/clean this computer as much as possible. Unfortunately this is my father's PC who passed away a few months ago, and all of the XP re-install discs are missing. So re-installing isn't much of an option. Any help would be great, thank you.First of all, my sincere condolences. Let's run some scans to see what we have. Could you please copy and paste the logs that you have from the different scans that you've run already

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

If I'm reading this correctly then this is uglier than I thought.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/03/2010 at 07:28 AM

Application Version : 4.38.1004

Core Rules Database Version : 5024
Trace Rules Database Version: 2836

Scan type : Complete Scan
Total Scan Time : 03:37:45

Memory items scanned : 489
Memory threats detected : 0
Registry items scanned : 6314
Registry threats detected : 0
File items scanned : 158689
File threats detected : 220

Adware.HotBar/SpamBlockerUtility (Low Risk)
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\3_Shot Gun.wav
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\ASAPCom.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\Redemption.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBClientSinkPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBInst.exe
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBOLExp.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBOLExt.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBSrvPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBTrayAppPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBUIRes.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBUISkin.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SpamBlocker.exe
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0
C:\Program Files\SpamBlockerUtility\Bin\SbUninst.exe
C:\Program Files\SpamBlockerUtility\Bin
C:\Program Files\SpamBlockerUtility\SBTV\sbtvau.dat
C:\Program Files\SpamBlockerUtility\SBTV\sbtv_hpk.dat
C:\Program Files\SpamBlockerUtility\SBTV\sbtv_kyf.dat
C:\Program Files\SpamBlockerUtility\SBTV
C:\Program Files\SpamBlockerUtility

Trojan.Media-Codec
C:\Program Files\Perfect Codec

Adware.Tracking Cookie
.2o7.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.aprilteens.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigfreesex.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bs.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.discount-cigarettes-store.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.e-2dj6wfmyaiajagp.stats.esomniture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.edge.ru4.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.elitematureporn.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.estat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.fortunecity.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.fortunecity.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.freefind.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.funwebproducts.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hairypornpics.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hairypornpics.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.icc.intellisrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.internet-*adult URL* [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.kanoodle.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.locator.metadata.windowsmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.metareward.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.paycounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.perf.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.*censored*-paradise.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qnsr.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.revenue.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.roiservice.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sav.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sex-superstore.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sex-superstore.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.smileycentral.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.uk.sitestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.uk.sitestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valueclick.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.webpower.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.webpower.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wetrack.it [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.3dstats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.bigtitpornstars.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dapornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dialysisfinder.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dialysisfinder.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.girlsfuckinghard.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.internet-*adult URL* [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.jimmyspornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.jimmyspornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.porninspector.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.*censored*-galleries.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.sexsweety.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.toyboxxx.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www1.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www3.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www4.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www5.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xiti.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xxxcreatures.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xxxcreatures.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected].bridgetrack[2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt

Trojan.Agent/Gen-Tmp[27]
C:\DOCUMENTS AND SETTINGS\HP_OWNER\LOCAL SETTINGS\TEMP\1E.TMP

Rootkit.TDSServ/Fake
C:\DOCUMENTS AND SETTINGS\HP_OWNER\LOCAL SETTINGS\TEMP\TDSS6B19.TMP

Unclassified.Unknown Origin
C:\PYTHON22\NMSKSSRVC.EXE

MBAM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4168

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

6/3/2010 4:14:36 PM
mbam-log-2010-06-03 (16-14-36).txt

Scan type: Quick scan
Objects scanned: 164981
Time elapsed: 33 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry VALUES Infected: 0
Registry Data Items Infected: 0
Folders Infected: 42
Files Infected: 1165

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\HP_Owner\Application Data\SpamBlocker (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\eskin (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\IESkins (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0 (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\344stat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML (Adware.Hotbar) -> Files: 1569 -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ustat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility_Icons (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0 (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\repair-bar (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\scan-bar-100 (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\scan-bar-pulse (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\VVSN (Adware.WhenU) -> Quarantined and deleted successfully.
C:\Program Files\VVSN\URL2 (Adware.WhenU) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\HP_Owner\Local Settings\Temp\TDSS6bf3.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1184993395.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185048657.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185206559.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185223343.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185241841.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185399928.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185426751.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185723951.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1186768111.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1187659084.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1188678814.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1189729597.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1190862601.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1191729391.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1193332121.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1194987890.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1196740502.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1199730375.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1202187586.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1204482847.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1205864239.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1208402346.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1210353729.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1212436305.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1215273810.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1217300433.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1218306053.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1219938068.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1222282807.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1224267785.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1226642864.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1227767493.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1229060932.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1230267080.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1232946843.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1240201362.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1246971787.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1251334694.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1252165073.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1252853416.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1254280043.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte10_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte11_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte12_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte13_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte14_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte19_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte20_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte21_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte9_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030203lib_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102angel_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102bigluf_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102bigsmile_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102birthday_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102cheers_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102flo_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102good_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102jump_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102king_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102lough_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102luf_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102smiled_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102smile_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102sor_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102thanx_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102uhu_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040103ahh_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040103wow_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040104_emi2_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\042102_1134_112_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103big_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103gig_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103hm_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103nomail_emoti_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103norm_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema15_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema16_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema17_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema18_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema19_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema20_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema21_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema24_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema25_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema26_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema30_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema33_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema34_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\062802hippi_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\062802jumpie_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402argh_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402oops_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402ouch_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\082502no_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\082502yes_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_boring1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_confused_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_crying_ugly_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_fantastic_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_feel_better_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_gimme_break_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_heehee_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_hlopaet_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_ign_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_lol_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_no_comment_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_peace_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_smashing_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_talk2thehand_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\blocked.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\blocked2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_sm.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_sm2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_smli.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_smli2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_add-but.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_back-but.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_cut_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_middle_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_middle_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_cut_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\business_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\buttondir.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\components.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_main.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_pagingmodule.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_topbuttons.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css_cattree.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css_flashpreview.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\delete.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_clear_sound.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_fs.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_select.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-511724-549108.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-511724-9595.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-backgrounds.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-bcards.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-ecards.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-emoticons.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-estationery.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-funny.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-help.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-images.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-info.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-more.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-my.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-new.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-new2.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-options.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-people.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-photo.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-SpamBlocked.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-tell.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-temp.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-text.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-voice.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-premium-email-premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-t7-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-temp-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\estatationery.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\flashpatch.js (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\flashpreview.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\fs3.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\hotbar_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_checked_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_close_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_close_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_edit_preview.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_edit_send.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_flash_preview.gif (Adware.Hotbar) -> QuarantinDo you have a HJT log and the Security Check log?Sorry I completely spaced it .

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:02:30 PM, on 6/3/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Napster\napster.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra BUTTON: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\OAcat.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10098 BYTES



Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG 9.0
Norton Personal Firewall
Online Armor 4.0
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 20
Adobe Flash Player 10.0.45.2
Adobe Reader 6.0.1
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.3)
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
Tall Emu Online Armor OAcat.exe
````````````````````````````````
DNS Vulnerability Check:

REQUEST Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)

``````````End of Log````````````
Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

==============================

Open HijackThis and select Open the Misc Tools section. Select open process manager. select
C:\WINDOWS\ALCXMNTR.EXE

and click on kill process. Exit HJT.
----------------------------------------------

Click Start, Search, select All Files and Folders. Copy and paste
Code: [Select]C:\WINDOWS\ALCXMNTR.EXE and click search. Delete this file.

=================================

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==================================

The Security Check shows that you are running more than one Firewall which is a no-no. Windows Firewall Enabled
Norton Personal Firewall Online Armor 4.0 . Two of them should be disabled and removed. The Windows Firewall is not very good because it only protects against incoming traffic and not against out-going traffic which can be most harmful. Windows Firewall can't be uninstall. It's intergrated with XP. It can only be disabled.

==============================

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

=================================

Download ComboFix by sUBs from one of the below links.

Important! You MUST save ComboFix to your desktop

link # 1
Link # 2

Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click on ComboFix.exe & follow the prompts.

Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

When the scan completes it will open a text window.

Post the contents of that log in your next reply.

Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.

ComboFix 10-06-05.01 - HP_Owner 06/05/2010 23:58:45.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.172 [GMT -7:00]
Running from: c:\documents and settings\HP_Owner.RACER\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Application Data\alot
c:\program files\alot
c:\program files\alot\alotUninst.exe
c:\program files\alot\bin\alot.dll
c:\program files\Mozilla Firefox\plugins\NPMorpBr.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\Fonts\acrsec.fon
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\pthreadVC.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-05-06 to 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Malwarebytes
2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\SUPERAntiSpyware.com
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-02 19:56 . 2010-06-02 19:56--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\AVG9
2010-06-01 03:44 . 2010-06-01 03:49--------d-----w-c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-31 10:37 . 2010-05-31 11:27--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor
2010-05-31 10:37 . 2010-05-31 10:37--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\OnlineArmor
2010-05-31 05:56 . 2010-05-31 05:56--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2010-05-30 06:25 . 2010-05-30 06:25--------d-----w-c:\documents and settings\All Users\Application Data\Qwest
2010-05-27 05:12 . 2010-05-27 05:12--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Intuit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 06:27 . 2005-06-17 13:26--------d-----w-c:\program files\Common Files\Adobe
2010-06-06 06:11 . 2007-05-08 05:27--------d--h--r-c:\documents and settings\All Users\Application Data\yahoo!
2010-06-06 06:11 . 2005-08-15 05:00--------d-----w-c:\program files\Yahoo!
2010-06-06 06:11 . 2010-01-15 01:41--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Yahoo!
2010-06-04 08:52 . 2008-12-09 06:03--------d-----w-c:\program files\Google
2010-06-04 07:11 . 2010-06-04 07:11--------d-----w-c:\program files\EA Games
2010-06-04 07:11 . 2004-12-02 05:41--------d--h--w-c:\program files\InstallShield Installation Information
2010-06-03 23:58 . 2010-06-03 23:58--------d-----w-c:\program files\Trend Micro
2010-06-03 23:53 . 2004-12-02 05:15--------d-----w-c:\program files\Java
2010-06-03 23:43 . 2004-12-02 05:15--------d-----w-c:\program files\Common Files\Java
2010-06-03 23:41 . 2010-06-03 23:42411368----a-w-c:\windows\system32\deployJava1.dll
2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\program files\SUPERAntiSpyware
2010-06-03 10:31 . 2010-06-03 10:31--------d-----w-c:\program files\CCleaner
2010-06-02 00:36 . 2010-01-15 00:43--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Apple Computer
2010-06-01 21:10 . 2010-05-31 06:00242896----a-w-c:\windows\system32\drivers\avgtdix.sys
2010-06-01 21:10 . 2010-05-31 06:0029584----a-w-c:\windows\system32\drivers\avgmfx86.sys
2010-06-01 05:08 . 2009-06-08 18:15--------d-----w-c:\program files\Bonjour
2010-06-01 03:49 . 2004-12-02 05:46--------d-----w-c:\program files\iTunes
2010-06-01 03:12 . 2006-11-01 02:47--------d-----w-c:\program files\Napster
2010-06-01 02:37 . 2010-05-31 23:54--------d-----w-c:\program files\RadarSync
2010-06-01 02:36 . 2010-01-15 02:20--------d-----w-c:\program files\Shockwave.com
2010-06-01 02:28 . 2010-01-17 03:31--------d-----w-c:\program files\WildTangent
2010-05-31 23:56 . 2010-01-17 22:5842472----a-w-c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-31 23:17 . 2010-05-31 23:17--------d-----w-c:\program files\iXi Tools
2010-05-31 21:45 . 2010-05-31 21:45--------d-----w-c:\program files\sisagp
2010-05-31 20:46 . 2004-12-02 05:54--------d-----w-c:\program files\PC-Doctor for Windows
2010-05-31 20:26 . 2004-12-02 06:07--------d-----w-c:\program files\Common Files\Symantec Shared
2010-05-31 19:58 . 2004-12-02 06:07--------d-----w-c:\program files\Symantec
2010-05-31 19:58 . 2004-12-02 06:07--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
2010-05-31 19:51 . 2004-12-02 05:41--------d-----w-c:\program files\IntelliMover Data Transfer Demo
2010-05-31 19:49 . 2004-12-02 05:55--------d-----w-c:\program files\Easy Internet signup
2010-05-31 11:07 . 2004-12-02 06:08--------d-----w-c:\program files\Norton AntiVirus
2010-05-31 10:35 . 2010-05-31 10:35--------d-----w-c:\program files\Tall Emu
2010-05-31 08:52 . 2004-12-02 05:46--------d-----w-c:\program files\QuickTime
2010-05-31 08:46 . 2006-11-06 20:04--------d-----w-c:\program files\Apple Software Update
2010-05-31 06:00 . 2010-05-31 06:0012464----a-w-c:\windows\system32\avgrsstx.dll
2010-05-31 06:00 . 2010-05-31 06:0052872----a-w-c:\windows\system32\drivers\avgrkx86.sys
2010-05-31 06:00 . 2010-05-31 06:0025096----a-w-c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-31 06:00 . 2010-05-31 06:00216200----a-w-c:\windows\system32\drivers\avgldx86.sys
2010-05-31 05:57 . 2010-05-31 05:57--------d-----w-c:\program files\AVG
2010-05-31 05:13 . 2010-05-31 01:55--------d-----w-c:\program files\Belkin
2010-05-30 06:23 . 2010-05-30 06:23--------d-----w-c:\program files\Xenocode
2010-05-29 05:17 . 2006-11-25 02:46--------d-----w-c:\program files\GameFiesta
2010-05-28 01:33 . 2010-05-28 01:33--------d-----w-c:\program files\Common Files\AnswerWorks 5.0
2010-05-28 01:32 . 2005-06-15 16:50--------d-----w-c:\program files\Quicken
2010-05-27 05:11 . 2010-01-15 00:43--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Symantec
2010-04-29 22:39 . 2010-06-03 22:2938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39 . 2010-06-03 22:2920952----a-w-c:\windows\system32\drivers\mbam.sys
2010-04-20 11:13 . 2010-05-31 10:3524440----a-w-c:\windows\system32\drivers\OAmon.sys
2010-04-20 11:13 . 2010-05-31 10:3529560----a-w-c:\windows\system32\drivers\OAnet.sys
2010-04-20 11:13 . 2010-05-31 10:35228216----a-w-c:\windows\system32\drivers\OADriver.sys
2010-04-12 09:40 . 2004-12-02 05:1819200----a-w-c:\windows\system32\drivers\srvkp.sys
2010-04-12 09:40 . 2004-12-02 05:181571001----a-w-c:\windows\system32\sisgl.dll
2010-04-12 09:22 . 2004-12-02 05:183468288----a-w-c:\windows\system32\sisgrv.dll
2010-04-12 09:17 . 2004-12-02 05:18324608----a-w-c:\windows\system32\drivers\sisgrp.sys
2010-04-12 09:08 . 2010-04-12 09:089728----a-w-c:\windows\system32\SiSPIns2.dll
2010-04-12 09:07 . 2005-06-18 03:1412288----a-w-c:\windows\InstFunc.dll
2010-04-12 09:07 . 2004-12-02 05:18172032----a-w-c:\windows\system32\SiSInst.dll
2010-04-12 09:07 . 2004-12-02 05:18258048----a-w-c:\windows\system32\SiSParse.dll
2010-04-12 09:06 . 2004-12-02 05:1849152----a-w-c:\windows\system32\SiSBase.dll
2010-04-08 20:20 . 2010-04-08 20:2091424----a-w-c:\windows\system32\dnssd.dll
2010-04-08 20:20 . 2010-04-08 20:20107808----a-w-c:\windows\system32\dns-sd.exe
2010-03-10 06:15 . 2004-08-04 11:00420352----a-w-c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-31 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-18 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"NapsterShell"="c:\program files\Napster\napster.exe" [2009-10-06 323280]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe" [2009-12-09 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2010-04-20 6678008]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-02 180269]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinCinema Manager.lnk - c:\program files\Sandisk\Common\Bin\WinCinemaMgr.exe [2010-1-29 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
SpySubtract.lnk - c:\program files\interMute\SpySubtract\SpySub.exe [2006-5-4 1187840]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-12-1 45056]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-04-20 925688]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-31 06:0012464----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dlbtcoms.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1308:UDP"= 1308:UDP:Windows Media Format SDK (napster.exe)
"1309:UDP"= 1309:UDP:Windows Media Format SDK (napster.exe)

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [5/30/2010 11:00 PM 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/30/2010 11:00 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/30/2010 11:00 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/30/2010 11:00 PM 242896]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/31/2010 3:35 AM 228216]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/31/2010 3:35 AM 24440]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/31/2010 3:35 AM 29560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/30/2010 10:58 PM 308064]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [5/30/2010 10:58 PM 5888008]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [5/30/2010 10:58 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [5/30/2010 10:58 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [5/30/2010 10:58 PM 26120]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [5/30/2010 10:08 PM 594048]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32128512----a-w-c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

2010-06-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-09 18:30]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-04 08:43]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-04 08:43]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750873676-2119400782-1055263353-1009Core.job
- c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-31 06:39]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750873676-2119400782-1055263353-1009UA.job
- c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-31 06:39]

2010-06-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-04 01:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner.RACER\Application Data\Mozilla\Firefox\Profiles\5uge2q0r.default\
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrch.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWTHost.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKLM-Run-IS CfgWiz - c:\program files\Common Files\Symantec Shared\cfgwiz.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-06 00:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(472)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2748)
c:\windows\system32\WININET.dll
c:\docume~1\HP_OWN~1.RAC\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\Tall Emu\Online Armor\OAcat.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\AGRSMMSG.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlbtcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-06-06 00:32:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-06 07:31

Pre-Run: 103,217,016,832 bytes free
Post-Run: 103,561,994,240 bytes free

- - End Of File - - 36B2B1C882C60CCE211754A93108191D
I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Here are the ESET scan results



C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfgn.class-234f3403-1f6066ff.classprobably a variant of Java/TrojanDownloader.OpenStream trojancleaned by deleting - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-746825f5-16fe8516.zipmultiple threatsdeleted - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-516dc14a-5e884b29.zipprobably a variant of Win32/Agent trojandeleted - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv645.jar-750ad2c1-6189b599.zipmultiple threatsdeleted - quarantined
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\R77SF69V\scn3[1].jsJS/TrojanDownloader.FakeAlert.NAB trojancleaned by deleting - quarantined
It looks like your computer is clean. If there's nothing else, let's do some clean-up

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

===============================

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

===============================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
4404.

Solve : fake windows security page?

Answer»

Could you please delete ComboFix from your desktop. It's supposed to work with Vista. Let's try downloading it again.

  • Download combofix from here, use the top links - combofix.exe
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.[/b]

  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.


  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may CAUSE it to stall.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:00 AM, on 6/6/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files (x86)\SGPSA\SearchAssistant.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Calorie Count Plus Toolbar - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\PROGRA~2\ccptb\ccptb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Calorie Count Plus Toolbar - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\PROGRA~2\ccptb\ccptb.dll
O4 - HKLM\..\Run: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed LAUNCHER] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe /Minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [iLike] C:\Program Files (x86)\iLike\1.2.16\ilikesidebar.exe /checkforupdate
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: lxdfCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxdfserv.exe
O23 - Service: lxdf_device - - C:\Windows\system32\lxdfcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SAS Core Service (SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\system32\STacSV64.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 12415 bytes
Please go to VirSCAN.org FREE on-line scan service
(If more than one file needs scanned they must be done separately and logs posted for each one)

1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page.

Code: [Select]C:\Program Files\SGPSA\ie3sh.exe
2. At the upload site, click once inside the window next to Browse.
3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
4. Click on the Upload button.
This will perform a scan across multiple different virus scanning engines.
Your file will possibly be entered into a queue which normally takes less than a minute to clear.
Important: Wait for all of the scanning engines to complete.
5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard.
6. Paste the contents of the Clipboard in your next reply.

===========================

Did you try running ComboFix again?

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

Combofix takes me to a page for geek police asking me to register for forum use... and as before vira scan will not let me paste using control +V nor the old fashioned way of just right clicking to paste... BOTH instances are greyed out. I will do the hyjack thing again.Ok. Forget about ComboFix and try this:

Download OTL to your desktop.

* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* When the window appears, underneath Output at the top change it to Minimal Output.
* Check the boxes beside LOP Check and Purity Check.
* Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy and pate the contents of these files, one at a time, into your next reply.

Note: You may need two or more posts to fit them all in.TL logfile created on: 6/6/2010 7:43:06 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\christal\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.34 Gb Total Space | 175.17 Gb Free Space | 61.82% Space Free | Partition Type: NTFS
Drive D: | 14.75 Gb Total Space | 7.97 Gb Free Space | 54.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRISTAL-PC
Current User Name: christal
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (BthServ) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (lxdf_device) -- C:\Windows\SysNative\lxdfcoms.exe ( )
SRV:64bit: - (lxdfCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdfserv.exe ()
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (npggsvc) -- C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (lxdf_device) -- C:\Windows\SysWow64\lxdfcoms.exe ( )
SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | ---D | M]
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) -- C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek )
DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (BTHPORT) -- C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) -- C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:64bit: - (BthEnum) -- C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:64bit: - (BTHUSB) -- C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:64bit: - (RTSTOR) -- C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (SiFilter) -- C:\Windows\SysNative\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV:64bit: - (SiRemFil) -- C:\Windows\SysNative\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV:64bit: - (Si3531) -- C:\Windows\SysNative\DRIVERS\Si3531.sys (Silicon Image, Inc)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (NETw5v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (UMPass) -- C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) -- C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) -- C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (NETw4v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (UVCFTR) -- C:\Windows\SysNative\Drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (BCM43XV) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 81 51 63 B3 05 27 CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{018F2688-3B85-4961-9B20-8D80113AA792}" = lport=445 | protocol=6 | dir=in | app=system |
"{02004DB0-A953-485D-9CB2-0CB6D9FB486E}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{08643C05-553D-4F93-A8C3-BB5CE32F659F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{16D45D6E-1930-4950-B1A9-A84C82FC4377}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{199ED1AC-A398-4C60-B3F9-E84BC042F614}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1A93C711-5374-4108-B058-93E09BCB0148}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{1FB44374-74FF-4C52-AC1A-A84F0EA35DFB}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{2216986F-8490-4ACA-A930-D984947498EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2370027C-B2D9-4EEF-89E3-943FDF773FB0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{23DA0C2C-8687-4DF2-940C-72CE6378A66C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2607EC0B-F5CD-4791-BC93-574476980CF4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2D202A91-807E-4856-BFC1-F6CD9BFAD113}" = lport=10244 | protocol=6 | dir=in | app=system |
"{327C8253-C22F-47F5-AD0A-EB90F4F099C8}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{359A734F-2BEB-4696-A1FE-23CE3F8E1890}" = lport=137 | protocol=17 | dir=in | app=system |
"{36038A39-E85A-4C0F-9679-EFD21FF37123}" = lport=138 | protocol=17 | dir=in | app=system |
"{36C87270-6BA9-49C4-851C-C7F2F77A1BD2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{401E6089-4DCD-4770-AB24-3B021BF416A3}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4130BBF7-D67B-4F3E-B548-DE529EF971C5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4BED0BE5-68BF-44C9-8853-4C59E90EEA1E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{51C77E64-4F38-489F-9495-6DE7B81BE094}" = lport=10244 | protocol=6 | dir=in | app=system |
"{6B06D71A-BB1B-4284-B09E-1B7AC703F775}" = lport=139 | protocol=6 | dir=in | app=system |
"{6DCC3E73-71C7-428A-A697-1F67CEE05533}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6F75A199-9237-4F63-9096-6635DCD56261}" = rport=10244 | protocol=6 | dir=out | app=system |
"{7030D9DD-7810-4477-8B53-5F1DFD1B26F9}" = rport=138 | protocol=17 | dir=out | app=system |
"{72E93761-5963-4D8C-9632-A333445FC9DA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{78C988E2-F1E4-4214-8C1D-2ACF0146D1D9}" = rport=445 | protocol=6 | dir=out | app=system |
"{7F9DC1B5-DD32-48B5-A46E-87DC5433BDA4}" = rport=10244 | protocol=6 | dir=out | app=system |
"{83907F7F-08E5-457F-9559-FE7569FDD4B2}" = lport=3390 | protocol=6 | dir=in | app=system |
"{870D5452-50DA-4908-A7D2-62D7B4D69998}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8C768901-0669-424E-AB5D-23091AF2B13A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [emailprotected],-28539 |
"{8D28730A-5BE9-4826-BB5F-F44EDA4EDF9F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{93A24FDB-447A-4661-8F2F-CAEEDDEF50F1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{98A4744D-114B-4DFD-88F5-47DAEE05F8CD}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A6E1F317-9D42-4948-A361-7018F985D5B3}" = rport=139 | protocol=6 | dir=out | app=system |
"{AEB723E4-8BBE-48D5-AF7A-5A45D75428CA}" = lport=9420 | protocol=6 | dir=in | name=akamai network manager |
"{B5A34DC5-A21E-402B-84B3-FFDF8E22D692}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D24330F8-9CA9-474F-B6AC-EF3C14882657}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D453BBDA-0A6D-4C92-81D1-D465B4D2B0A4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D51CBD42-4267-435B-9614-3BBF17699780}" = rport=137 | protocol=17 | dir=out | app=system |
"{DB128F4E-9443-4C5C-B537-EAAC24384C8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DFA6066D-C9C7-4C24-A410-C9F9F43B72B8}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{E0A13B46-3B08-407E-A342-285EFAE082DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED1508CC-D2F5-46B0-AC49-9DB9DBB3D874}" = lport=5000 | protocol=17 | dir=in | name=akamai network manager |
"{F5EBE828-ED52-4AEE-B5E1-6976476C9C9D}" = lport=3390 | protocol=6 | dir=in | app=system |
"{F70D102C-A3FC-4025-ABF8-EBD94639DD74}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FA19479-159E-4F8B-A181-3AF1C7714F0B}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxdfcoms.exe |
"{176928C1-0872-4E95-992D-009F1FDC81E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1D4698D0-D73D-4A06-868B-8505C3F7F1FC}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{1E23F6D9-0ACE-4B63-A4F6-C321FF6F07B7}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfamon.exe |
"{20951D0C-45A2-406D-B069-970321D3C850}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{3549372B-02EB-447B-A536-55D93C8A6516}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfjswx.exe |
"{36F18110-25B7-4C25-9583-D017EBC7FD43}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{42458B3B-3F8F-4CF1-B6A2-E7C5D1E2C4A0}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{4AF88C93-E78C-4791-A5C9-4FD1E08B10C3}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{4DA7F2FC-D919-4994-8614-4452F8D188CF}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |
"{5141C9EC-D5A2-4F48-AF4E-BDEF1FB6724D}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe |
"{57007F84-B333-4DAD-AF54-C289EFEC758E}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{5CD7D776-3C94-4E86-8656-0E12877C0AF3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{606031B5-2FA7-451E-AE12-693A14DE70A4}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{63C3240C-9C66-4B61-87B3-DED6DBFBCE50}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{749B947B-A023-473A-9640-E787C646A73E}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdftime.exe |
"{74A17DE9-C954-464F-90A7-FC12161C3C22}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{79B9B7A3-E7CF-4812-800B-FFDCE078453D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{7AD06813-D418-4B9A-AE16-4FA3B38975C2}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfmon.exe |
"{7C987659-0F92-4528-869F-915689FB8601}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{7F512E54-86F5-4CEE-AD1A-14B15C38AAF8}" = protocol=17 | dir=in | app=c:\windows\system32\lxdfcoms.exe |
"{7F5987A1-410A-4CB1-BE98-2BB6FB449B55}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark 6500 series\frun.exe |
"{8137BF57-1B23-4372-9913-26605C1E4CAE}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{8287E80D-C9E5-4C3D-B135-8C5D24BEC809}" = protocol=17 | dir=in | app=c:\windows\system32\lxdfcfg.exe |
"{8519AB2F-31B6-48E4-B247-A83BA37FEF35}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{8A822B07-A07C-4BF0-A94F-8A2FAF23C2C1}" = protocol=58 | dir=out | [emailprotected],-28546 |
"{8AAC1F04-53E2-4D11-A608-A0DF321703CF}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{9C9884C0-BFD3-4F1D-91A8-506AC94AAA6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{A5319875-9864-4290-B399-FB316B1AA4C3}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{A74F24AE-78EC-4972-A724-547207FFD681}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{AD8020EA-4AC7-4942-9317-533595AA5F2A}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{AF635B43-6720-4FF8-BA8E-8A5E13346B20}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{B1E5B761-56FA-46A7-B15C-35CD71876993}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |
"{B86DA11C-0BD0-4323-BE9C-9D9902DDCB37}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfmon.exe |
"{BBD8111B-3EF9-4D95-8EEC-66D491D6E385}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxdfcoms.exe |
"{CE1EECA4-7EC3-4CC5-B12E-65266294C182}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfjswx.exe |
"{D040D1B1-4BF4-4693-83B8-E72690DEFFDF}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe |
"{D3857ACA-9849-4D84-8702-4FD9A7004AE2}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\lxdfamon.exe |
"{D4F85714-3825-48BE-9CC4-32D4D9E9375B}" = protocol=6 | dir=in | app=c:\windows\system32\lxdfcoms.exe |
"{D86AB65E-3B3D-43B4-8039-89DF2886580B}" = protocol=1 | dir=in | [emailprotected],-28543 |
"{D8F73BD4-F78E-403D-BD99-C6EAA2175EF7}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |
"{D8FBFD1B-27D8-4BF0-BA8D-F2FF8CDFB4CF}" = protocol=1 | dir=out | [emailprotected],-28544 |
"{D93871D1-0EE4-4B57-A1BC-EC38C6AEBA74}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{E7D77EFB-1EE0-4BCF-B927-C00F98733934}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{EC8AF866-5C8F-49CE-9AFF-33CEB3947787}" = protocol=6 | dir=in | app=c:\windows\system32\lxdfcfg.exe |
"{ECD049FA-CADF-4750-916A-131074685E95}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{EE63EBC9-96CB-4F91-AADA-0C1CD4D2AD16}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{F0F66782-BC17-4B79-947C-031F429D7EFF}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark 6500 series\frun.exe |
"{F7521E49-EE30-4886-A455-334F5B2DD901}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdftime.exe |
"{FBAFC9D9-6E09-4F04-A269-683B4AAA4C19}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |
"{FC426CB0-5E4F-43F8-B2CF-05796EB02FD8}" = protocol=58 | dir=in | [emailprotected],-28545 |
"{FD76F04C-B588-40AB-A4CA-98CA87909301}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"TCP Query User{0295F370-36ED-41F5-A59C-5DA507EA08FB}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe |
"TCP Query User{04A80907-7DFD-4E5B-9CAD-7C1F6376524A}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe" = protocol=6 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe |
"TCP Query User{2034B9D4-08A7-4DC6-BBF1-AEBEE7BE9A64}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{2B6F2197-F16D-46BA-807A-FB97F3F2438F}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{3C7A2B0E-D0FF-4277-90B5-5B8CF2E760DC}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe |
"TCP Query User{6ABBB54B-96DF-429B-AEA8-7DD09A5CE241}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe" = protocol=6 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe |
"TCP Query User{AF813B86-CD0F-4D8B-9A13-B5742FE69A80}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{CB945C38-56AF-4EB8-9829-8F6EA6C17D80}C:\users\christal\desktop\ddi_cb.exe" = protocol=6 | dir=in | app=c:\users\christal\desktop\ddi_cb.exe |
"TCP Query User{CC680EE5-990C-4DCF-A5C4-0E67DDC49D64}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{CF07B12E-8288-4794-9B39-6F1CF5F3AEE4}C:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe |
"TCP Query User{D10AC1D1-415E-41E6-A9AE-408BDD859129}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{18E23A06-4688-4C10-8594-3E7A12ADBA3E}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe" = protocol=17 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 127956f0\launcher.exe |
"UDP Query User{2B62C20B-5D11-4F29-AE51-6BD59BD09CA0}C:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe" = protocol=17 | dir=in | app=c:\users\christal\appdata\local\temp\blizzard launcher temporary - 070345d8\launcher.exe |
"UDP Query User{32DC9B8C-CC6D-41D2-B6C5-89F6009A0E1C}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe |
"UDP Query User{51D54237-BACB-43F0-AB6E-06BD22EC48A3}C:\users\christal\desktop\ddi_cb.exe" = protocol=17 | dir=in | app=c:\users\christal\desktop\ddi_cb.exe |
"UDP Query User{525A2B4C-B5E5-43C9-9404-82C07725ADA0}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{896BCD68-F38C-425D-BA51-36AF8326DBF2}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{9058C6A4-0FAF-4B28-A59A-A1B0C5C2CC15}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{97AD2B18-0520-4D47-9D6C-5364F954404C}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{C30C57AB-079E-4108-A0A8-BFF8DF2A8666}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{EE3A05DC-D794-4C40-8FA7-9B94815EFDDE}C:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firesky\stargate worlds\working\binaries\sgw.exe |
"UDP Query User{F5D6CC3E-01FE-4CA9-B512-E94F07DFFA73}C:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\lxdfpswx.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5400
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Lexmark 6500 Series" = Lexmark 6500 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup PACKAGE (x64)
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{626C034B-50B8-47BD-AF93-EEFD0FA78FF4}" = Character Builder
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}" = AGEIA PhysX v7.11.13
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BookSmart® 2.6.0 2.6.0" = BookSmart® 2.6.0 2.6.0
"ccptb" = Calorie Count Plus Toolbar
"Digital Editions" = Adobe Digital Editions
"FMOD Designer" = FMOD Designer
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (2.0.0.3)" = Mozilla Firefox (2.0.0.3)
"SystemRequirementsLab" = System Requirements Lab
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Mail Advisor" = Yahoo! Mail Advisor
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"NCsoft-Aion" = Aion

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/6/2010 5:38:52 PM | Computer Name = christal-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1010
Description =

Error - 6/6/2010 6:41:45 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

Error - 6/6/2010 6:41:46 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

Error - 6/6/2010 6:41:47 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

Error - 6/6/2010 6:41:48 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

Error - 6/6/2010 6:41:49 PM | Computer Name = christal-PC | Source = Perflib | ID = 1005
Description =

Error - 6/6/2010 6:41:49 PM | Computer Name = christal-PC | Source = Perflib | ID = 1018
Description =

Error - 6/6/2010 6:41:50 PM | Computer Name = christal-PC | Source = Perflib | ID = 1008
Description =

[ Media Center Events ]
Error - 3/19/2010 11:18:21 PM | Computer Name = christal-PC | Source = McrMgr | ID = 107
Description =

[ System Events ]
Error - 6/6/2010 7:18:59 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:22:02 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:25:05 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:28:07 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:31:10 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:34:14 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:37:16 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:40:19 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:43:21 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =

Error - 6/6/2010 7:46:23 PM | Computer Name = christal-PC | Source = WMPNetworkSvc | ID = 866333
Description =


< End of report >
OTL logfile created on: 6/6/2010 7:43:06 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\christal\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.34 Gb Total Space | 175.17 Gb Free Space | 61.82% Space Free | Partition Type: NTFS
Drive D: | 14.75 Gb Total Space | 7.97 Gb Free Space | 54.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRISTAL-PC
Current User Name: christal
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\christal\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (BthServ) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (lxdf_device) -- C:\Windows\SysNative\lxdfcoms.exe ( )
SRV:64bit: - (lxdfCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdfserv.exe ()
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (npggsvc) -- C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (lxdf_device) -- C:\Windows\SysWow64\lxdfcoms.exe ( )
SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | ---D | M]
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) -- C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek )
DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (BTHPORT) -- C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) -- C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:64bit: - (BthEnum) -- C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:64bit: - (BTHUSB) -- C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:64bit: - (RTSTOR) -- C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (SiFilter) -- C:\Windows\SysNative\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV:64bit: - (SiRemFil) -- C:\Windows\SysNative\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV:64bit: - (Si3531) -- C:\Windows\SysNative\DRIVERS\Si3531.sys (Silicon Image, Inc)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (NETw5v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (UMPass) -- C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) -- C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) -- C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (NETw4v64) Intel(R) -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (UVCFTR) -- C:\Windows\SysNative\Drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (BCM43XV) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=BB&Br=GTW&Loc=ENG_US&Sys=PTB&M=P-6860FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginen ame: "Fast Browser Search"
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..browser.search.defaultEngine: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaultenginen ame: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&type=&p="


FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/10/24 11:32:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/02 22:55:42 | 000,000,000 | ---D | M]

[2009/12/13 11:45:31 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions
[2009/10/24 11:33:39 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/08/18 06:53:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\christal\AppData\Roaming\Mozilla\Firefox\Profiles\hdkuc1vc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/31 09:50:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/31 09:50:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009/10/24 11:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected]
[2009/10/24 11:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected]
[2009/10/24 11:32:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected]
[2009/08/18 17:26:26 | 002,619,266 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\components\1249345.dll
[2007/03/12 05:01:33 | 000,066,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\jar50.dll
[2007/03/12 05:01:34 | 000,054,376 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\jsd3250.dll
[2007/03/12 05:01:36 | 000,034,952 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\myspell.dll
[2007/03/12 05:01:38 | 000,046,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\spellchk.dll
[2007/03/12 05:01:40 | 000,172,144 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\xpinstal.dll
[2010/05/31 09:50:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/10/24 11:32:41 | 000,003,700 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fast.png
[2009/10/24 11:32:40 | 000,001,963 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fast.xml

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,736 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files (x86)\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( )
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( )
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Calorie Count Plus Toolbar) - {A057A204-BACC-4D26-DFC4-6BAE8BAD3DC9} - C:\Program Files (x86)\ccptb\ccptb.dll ( )
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [iLike] C:\Program Files (x86)\iLike\1.2.16\ilikesidebar.exe File not found
O4 - HKCU..\Run: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O4 - Startup: C:\Users\christal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab (Image Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: CabBuilder http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 68.237.161.12
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\christal\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\christal\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 04:01:00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/06 19:41:38 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Users\christal\Desktop\OTL.exe
[2010/06/06 18:27:45 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/06/05 17:45:24 | 000,069,152 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/02 22:33:00 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS
[2010/06/02 17:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2010/06/02 17:41:04 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Users\christal\Desktop\HijackThisInstaller.exe
[2010/06/02 06:35:45 | 000,000,000 | ---D | C] -- C:\Users\christal\AppData\Roaming\SUPERAntiSpyware.com
[2010/06/02 06:35:45 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/06/02 06:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\SASCORE
[2010/06/02 06:35:37 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/06/02 06:34:37 | 008,924,856 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\christal\Desktop\SUPERAntiSpyware.exe
[2010/05/31 09:53:43 | 000,157,696 | ---- | C] (The RaProducts Team: Paul McLain and Fred de Vries) -- C:\Users\christal\Desktop\JavaRa.exe
[2010/05/31 09:50:44 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2010/05/31 09:50:44 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010/05/31 09:50:44 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010/05/31 09:50:44 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2010/05/30 20:19:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Antimalware
[2010/05/30 20:18:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/05/28 18:44:29 | 000,000,000 | -HSD | C] -- C:\found.000
[2010/05/18 18:21:46 | 000,000,000 | ---D | C] -- C:\Users\christal\Documents\My Digital Editions
[2010/05/09 20:04:12 | 000,000,000 | ---D | C] -- C:\Users\christal\Documents\BookSmartData
[2010/05/09 20:04:00 | 000,000,000 | ---D | C] -- C:\Users\christal\.blurb
[2010/05/09 20:02:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BookSmart
[2008/06/15 11:43:17 | 001,200,128 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfserv.dll
[2008/06/15 11:43:17 | 000,950,272 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfusb1.dll
[2008/06/15 11:43:17 | 000,647,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfpmui.dll
[2008/06/15 11:43:17 | 000,565,248 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdflmpm.dll
[2008/06/15 11:43:17 | 000,356,352 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfinpa.dll
[2008/06/15 11:43:17 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfiesc.dll
[2008/06/15 11:43:17 | 000,053,248 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfprox.dll
[2008/06/15 11:43:15 | 000,663,552 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfhbn3.dll
[2008/06/15 11:43:14 | 000,860,160 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfcomc.dll
[2008/06/15 11:43:14 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdfcomm.dll
[135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/06 19:43:13 | 002,359,296 | -HS- | M] () -- C:\Users\christal\ntuser.dat
[2010/06/06 19:42:53 | 000,000,440 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6C0934CF-0A85-42F1-A2BE-C48A6A068357}.job
[2010/06/06 19:41:46 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\christal\Desktop\OTL.exe
[2010/06/06 19:38:20 | 000,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/06 19:38:20 | 000,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/06 18:30:52 | 000,000,828 | ---- | M] () -- C:\Users\christal\Desktop\World of Warcraft.lnk
[2010/06/06 17:40:23 | 000,028,124 | ---- | M] () -- C:\Users\christal\AppData\Roaming\nvModes.001
[2010/06/06 17:38:39 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/06 17:38:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/05 22:03:34 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/06/05 22:03:29 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000001.regtrans-ms
[2010/06/05 22:03:29 | 000,065,536 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TM.blf
[2010/06/05 22:03:20 | 003,340,508 | -H-- | M] () -- C:\Users\christal\AppData\Local\IconCache.db
[2010/06/05 17:41:42 | 000,069,152 | ---- | M] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/05 17:21:02 | 000,028,124 | ---- | M] () -- C:\Users\christal\AppData\Roaming\nvModes.dat
[2010/06/04 23:00:15 | 001,208,320 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mbb
[2010/06/04 23:00:15 | 000,686,080 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mb
[2010/06/02 22:38:54 | 000,001,888 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/02 18:40:29 | 000,000,104 | ---- | M] () -- C:\Users\christal\Desktop\Recycle Bin - Shortcut.lnk
[2010/06/02 18:03:24 | 000,867,892 | ---- | M] () -- C:\Users\christal\Desktop\SecurityCheck.exe
[2010/06/02 17:41:23 | 000,001,939 | ---- | M] () -- C:\Users\christal\Desktop\HijackThis.lnk
[2010/06/02 17:41:06 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Users\christal\Desktop\HijackThisInstaller.exe
[2010/06/02 06:35:40 | 000,001,767 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/02 06:34:46 | 008,924,856 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\christal\Desktop\SUPERAntiSpyware.exe
[2010/05/31 09:50:32 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2010/05/31 09:50:32 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010/05/31 09:50:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010/05/31 09:50:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2010/05/30 21:36:04 | 000,000,736 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/05/30 21:35:48 | 000,000,736 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/05/30 20:18:57 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/28 21:58:45 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\EasyShare Registration Task.job
[2010/05/28 18:31:50 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000002.regtrans-ms
[2010/05/28 17:00:38 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TMContainer00000000000000000001.regtrans-ms
[2010/05/28 17:00:38 | 000,065,536 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TM.blf
[2010/05/18 18:24:07 | 000,001,334 | ---- | M] () -- C:\Users\christal\Desktop\vegS 4 DUMB.acsm
[2010/05/18 18:21:34 | 000,002,024 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Digital Editions.lnk
[2010/05/17 17:47:30 | 000,000,168 | ---- | M] () -- C:\Users\christal\AppData\Roaming\wklnhst.dat
[2010/05/09 20:03:52 | 000,001,763 | ---- | M] () -- C:\Users\Public\Desktop\BookSmart.lnk
[2010/05/07 23:02:19 | 000,524,288 | -HS- | M] () -- C:\Users\christal\ntuser.dat{8e8fd9bf-59fa-11df-b248-001dd9fcfe43}.TMContainer00000000000000000002.regtrans-ms
[135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[135 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/02 22:38:54 | 000,001,888 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/02 18:40:29 | 000,000,104 | ---- | C] () -- C:\Users\christal\Desktop\Recycle Bin - Shortcut.lnk
[2010/06/02 18:03:21 | 000,867,892 | ---- | C] () -- C:\Users\christal\Desktop\SecurityCheck.exe
[2010/06/02 17:41:23 | 000,001,939 | ---- | C] () -- C:\Users\christal\Desktop\HijackThis.lnk
[2010/06/02 06:35:40 | 000,001,767 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/05/31 09:53:43 | 000,245,103 | ---- | C] () -- C:\Users\christal\Desktop\JavaRa.def
[2010/05/30 20:18:57 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/28 17:05:23 | 000,524,288 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000002.regtrans-ms
[2010/05/28 17:05:23 | 000,524,288 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TMContainer00000000000000000001.regtrans-ms
[2010/05/28 17:05:23 | 000,065,536 | -HS- | C] () -- C:\Users\christal\ntuser.dat{0169a828-6a9b-11df-b100-c6f226c58229}.TM.blf
[2010/05/18 18:22:56 | 000,001,334 | ---- | C] () -- C:\Users\christal\Desktop\vegS 4 DUMB.acsm
[2010/05/18 18:21:34 | 000,002,024 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Digital Editions.lnk
[2010/05/09 20:03:52 | 000,001,763 | ---- | C] () -- C:\Users\Public\Desktop\BookSmart.lnk
[2009/08/27 06:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/08/27 06:22:21 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2008/12/24 09:36:14 | 000,339,968 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll
[2008/12/24 09:36:14 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll
[2008/06/15 11:43:17 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxdfcomx.dll
[2008/06/15 11:43:17 | 000,348,160 | ---- | C] () -- C:\Windows\SysWow64\lxdfinst.dll
[2008/01/20 22:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll

========== LOP Check ==========

[2008/06/09 19:58:32 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Acreon
[2010/04/13 06:58:17 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\ccptb
[2009/08/26 07:08:21 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\GetRightToGo
[2010/03/18 05:52:28 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\iLike
[2008/06/30 06:49:31 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Lexmark Productivity Studio
[2008/10/05 20:04:35 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\SampleView
[2009/04/25 12:59:49 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Skinux
[2008/06/30 06:48:01 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Template
[2009/05/21 23:03:16 | 000,000,000 | ---D | M] -- C:\Users\christal\AppData\Roaming\Windows Live Writer
[2010/05/28 21:58:45 | 000,000,406 | ---- | M] () -- C:\Windows\Tasks\EasyShare Registration Task.job
[2010/06/05 22:03:37 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/06 19:42:53 | 000,000,440 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6C0934CF-0A85-42F1-A2BE-C48A6A068357}.job

========== Purity Check ==========


< End of report > Add or Remove Programs

1. Click on the Windows Start button and click on the Control Panel
2. In the Control Panel window, double-click Add or Remove Programs icon. In Vista, Programs and Features
3. When the Add or Remove Programs window has fully populated, check for
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Java(TM) 6 Update 7
SGPSA

and uninstall them.

==================================

I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. If you want to help, please go here. Superdave.No threats were found using EST so they only left me with the option of pushing finish.That looks good. If there are no other issues, let's do some clean-up.

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

================================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

===============================

Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
OK, I have downloaded all you have suggested. What remains on my desktop? I have super antispyware
Hyjack this
TFC
Eset is still installed
malwarebytes
microsoft security essentials
spyware doctor
pc tools firewall
Wot
security check
spyware blaster
Of the above which ones do I need to uninstall?Uninstall HJT, ESET, TFC, Security Check. You may keep SAS and MBAM, if you wish. Update them and run it on a regular basis. SpywareBlaster needs to be updated every so often. I usually do mine about once a month. All the rest are need and can stay.
4405.

Solve : Antivirus for WIn 7?

Answer»

Which antivirus is best for WIndows 7?
I am using KAspersky Internet SEcurity for the protection of my computer. Which according to you is best for Win 7 and why?This question is asked over and over again. Please do a search of this BOARD and you'll see LOTS of similar threads.

Personally, I am a huge fan of Kaspersky.anti-virus programs are unneeded! Whenever you have a problem, it can always be fixed by checking your power supply and connections! And checking for zebra droppings inside the system You're too busy to spend a lot of time worrying about protecting your PC. With Microsoft Security Essentials, you get high-quality protection against viruses and spyware, including Trojans, worms and other malicious software. And best of all, there are no costs or annoying subscriptions to keep track of.

It's very easy to install Security Essentials using it is even easier than one might expect. Updates and upgrades are automatic, so there's no need to worry about having the latest protection. It's easy to tell if you're protected – when the Security Essentials icon is green, your status is good. It's as simple as that.

When you're busy using your PC, you don't want to be bothered by NEEDLESS alerts. Security Essentials runs quietly in the BACKGROUND, only alerting you if there's something you need to do. And it doesn't USE a lot of system resources, so it won't get in the way of your work or fun.

Microsoft Security Essentials provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software.

Microsoft Security Essentials is a free download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. It’s easy to tell if your PC is secure — when you’re green, you’re good. It’s that simple.

Microsoft Security Essentials runs quietly and efficiently in the background so that you are free to use your Windows-based PC the way you want—without interruptions or long computer wait times.
Get it here.

4406.

Solve : Operating system problems?

Answer»

i tried and got the same error...i tried to update then delete and got the same message to please wait while it deletes all Mcafee......I am gonna leave my system on THRU out the nite to see what happens with the message, maybe it needs some time to delete all programs.
Now am having new problems occur while turning my system on it takes a long them to boot up (5 or more minutes), it FREEZES after the window logo shows up. And while surfing my connection seems to have a sudder to it? any suggestions?Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. If you want to help, please go here. Superdave.You could try this.

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
===========================

Quote

my connection seems to have a sudder to it?
What does this mean?

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a FOLDER named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.Ok.....SuperdaveResults of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Norton 360
McAfee SecurityCenter
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java(TM) 6 Update 20
Adobe Flash Player 10.0.45.2
Adobe Reader 9.3.2q
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log```````````` sudder= my internet seems to be skipping..The Security Check shows these two programs: Norton 360
McAfee SecurityCenter. Are these both Anti-Virus programs? If yes, one of them will have to be disabled because running two or more AV programs at once is a no-no. Is your computer still taking a long while to boot?
4407.

Solve : MalwareBytes paid version?

Answer»

Does anyone have the paid version of MalwareBytes and if so, how is the updating? The reason I ask is apparently I've been spoiled with the virus programs, etc. automatically updating. I had been using the free version of SuperAntiSpyware and got tired of having to update it manually. I checked the settings, etc. and saw that with the paid version it would update at startup and every 8 hours. It had such good reviews so I trusted it and made the mistake of purchasing it. But, AFTER I had purchased it, I found out that if you're not online when it tries to update, you're out of LUCK. If you get an update, you have to do it manually. I had assumed it would try again if I wasn't online when it tried but I was wrong. How does the purchased version of MalwareBytes update work? Do I have to be online at the right time with it or if I'm not, will it try again later? I was no better off with the paid version of SuperAntiSpyware and I don't want to make that mistake again. THANKS for your time.I don't understand. When you do go online SAS will ALWAYS notify there is an update if there is one more current than what you are running. All you have to do is click on update. Why PURCHASE another product?Quote from: Allan on June 07, 2010, 09:35:21 AM

I don't understand. When you do go online SAS will always notify there is an update if there is one more current than what you are running. All you have to do is click on update. Why purchase another product?
If I wanted an update of the definitions or the program, I had to do it manually or it wouldn't get done. Mine has never notified me of any updates being available. If I get it, I have to do it myself and that was why I wanted it. I thought it would update automatically or at least that's what it claimed to do. I went to their forum and asked about it and there were several others having the same PROBLEM. They told me to get a support ticket which is what I did and they couldn't help me either. I had found where Malwarebytes has a scheduler for their updates. I was hoping someone could tell me if it does what it claims to do. I can't tell by the free version and I don't want to purchase another one and then find out it doesn't do what they say it will.I've never had a problem with SAS notifying me of updates.Quote from: Allan on June 07, 2010, 11:50:34 AM
I've never had a problem with SAS notifying me of updates.
My problem is that it will not update and they were advertising it to "automatically update" but it will not do it. Also, there are others that are having the same problem. It has notified me once or twice about the program updates but I still had to manually update it myself. But, it has never notified me of spyware definition updates and if I get them, I have to do it manually so why bother purchasing when you're not any better off than using the free version. And that was the reason I purchased it so it would automatically update it instead of me having to do it each time.If you go to their websites you will see there is more functionality in the paid versions, not just the automatic updates. My OS is scheduled for automatic updates but if my computer is not on at that time, I will get a message that there are updates waiting the next time I turn on my computer. The way around this it to leave your computer on 24/7 which is a bad practice, green planet wise. Quote from: SuperDave on June 07, 2010, 05:13:53 PM
If you go to their websites you will see there is more functionality in the paid versions, not just the automatic updates. My OS is scheduled for automatic updates but if my computer is not on at that time, I will get a message that there are updates waiting the next time I turn on my computer. The way around this it to leave your computer on 24/7 which is a bad practice, green planet wise.
If I had left my computer on AND connected to the internet 24/7, SuperAntispyware Pro would have updated but I don't do that and I'm not going to start it now. It didn't even notify me that there were updates waiting. I was just hoping someone could tell me that Malwarebytes Pro worked better than this. I didn't want to purchase it and THEN find out it wasn't any better. Thanks for your time.I was using MalwareBytes home version for the last 3 months or so and I thought it was doing a good job of keeping my computer clean. Then I noticed my computer was behaving really slowly whenever I was online so I decided to scan it with Emsisoft Anti-malware software. I was shocked at how much crap it found on my computer and on my external drive. I have to say I would really recommend that anyone that thinks they have a problem try the Emsisoft software because it seems to be very good. As long as they can keep up with creating new definitions then I think the app is a keeper.

4408.

Solve : Computer freezes when a new window is opened?

Answer»

Hi... I posted this in the hardware section and was told to poast here instead:

okay, let me start by saying that my computer expertise is EXTREMELY limited, (we're talking turn on turn off). A few weeks ago I tried to trun on my desktop and when I logged on it would start to do so and then log me back off. I had someone look at it and we were able to get it logged on. Now whenever I click on a link that opens a new window the computer freezes up. The only thing I can do is open the task manager and end task. The I start over. The same thing happens when I enter anything into the address bar. I dont have money to have someone look at it and charge me an ARM and a leg but I need this fixed. Any advice would be incredibly helpful.

I have a HP Pavillion a1102n. Any other INFO you need you will have to walk me along to find it, cause as I said, I am NOT a compter person.

Thank you

KariHello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. If you want to help, please go here. Superdave.Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this ISSUE on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose. Please let me know how you manage with this?Hi, sorry but I cannot get onto my computer at all now. I just say your post and have not been able to do anything. When I turn the power on the computer starts to boot up and then the screen goes blank and the monitor says "monitor going to sleep" and it starts over. It just continues to cycle through and never actually starts. I borrowed a friends laptop but i have tons of things that I need on my compter. Help please!

KariQuote

Hi, sorry but I cannot get onto my computer at all now. I just say your post and have not been able to do anything. When I turn the power on the computer starts to boot up and then the screen goes blank and the monitor says "monitor going to sleep" and it starts over. It just continues to cycle through and never actually starts. I borrowed a friends laptop but i have tons of things that I need on my compter. Help please!
Kari

Kari, the first thing I would suggest is that you slave your harddrive to another functioning computer and copy the files that you need to a DVD. If you can't do this yourself, I'm sure you could find a friend that knows enough about computers to help you. Be sure to scan the files before you use them on another computer. Then, you will probably have to take the computer to a repair shop because it looks like this is a hardware problem. Have you checked all the cables to ensure that nothing has become DISCONNECTED? Did you try booting with the Rescue CD in place?
4409.

Solve : Anyone want some AV software or a firewall tested??

Answer»

Quote from: tgp1994 on June 10, 2010, 09:45:17 AM

Well, ya, of course I ran them Some of the installers I tried just popped up a meaningless error message, while others ran, taking about 90%+ of the CPU, but still ended up doing nothing.

What did you expect them to "do"?
Well, I was mainly looking for a trojan that would download other viruses, expanding the POSSIBLITIES for me to get screwed over I mean, what kind of a virus would just run at 90% CPU, or just pop up an error message and be done with?Quote from: tgp1994 on June 10, 2010, 01:04:57 PM
I was mainly looking for a trojan that would download other viruses

How do you know that they didn't? Anyhow, most real-world malware apps are not WRITTEN purely and simply just to infect people's computers, for the pure joy of causing mischief. They often have some purpose such as joining your pc to a botnet, turning it into a spam relay, or a number of other THINGS, all of which they do silently and behind the scenes.

If you are doing all this in a VMWare virtual machine, I sure hope you aren't sharing any folders with the host OS...



Well, I suppose the more malware I have, the better. Mischief sounds good to me. And definetly no, I am not doing FOLDER sharing. In some cases, I'll disconnect the virtual network adapter after downloading a virus (to see if it is) just for good measure.
4410.

Solve : APPLICATION IS EXECUTED. THE FILE XXXXXX MAY BE INFECTED!?

Answer»

THIS IS THE OTL.TXT



OTL logfile created on: 6/2/2010 10:02:13 AM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = E:\COMBOFIX
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 69.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 239.18 Gb Free Space | 83.65% Space Free | PARTITION Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.87 Gb Total Space | 0.61 Gb Free Space | 32.51% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer NAME: BERNABES-PC
Current User Name: Bernabe's
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - E:\COMBOFIX\OTL.exe (OldTimer Tools)
PRC - C:\Users\Bernabe's\AppData\Roaming\GameRanger\GameRanger\Data\GameRanger.exe (GameRanger Technologies)
PRC - C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe ()
PRC - C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe ()
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\ltmoh\ltmoh.exe (LSI Corp.)


========== Modules (SafeList) ==========

MOD - E:\COMBOFIX\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) -- C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (TPCHSrv) -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) -- C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WwanSvc) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (Power) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) -- C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) -- C:\windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) -- C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:64bit: - (Thpsrv) -- C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (RSELSVC) -- C:\Program Files\TOSHIBA\rselect\RSelSvc.exe (TOSHIBA Corporation)
SRV:64bit: - (AgereModemAudio) -- C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (Akamai) -- c:\Program Files (x86)\Common Files\Akamai\rswin_3697.dll ()
SRV - (fsssvc) -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Norton Internet Security) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (TMachInfo) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (ConfigFree Gadget Service) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
SRV - (VSS) -- C:\Windows\Vss [2009/07/13 20:20:14 | 000,000,000 | ---D | M]
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2009/07/13 20:20:14 | 000,000,000 | ---D | M]
SRV - (HomeGroupProvider) -- C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (ConfigFree Service) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ccHP) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymIM) -- C:\Windows\SysNative\drivers\SymIMV.sys (Symantec Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (rtl8192se) -- C:\Windows\SysNative\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (BHDrvx64) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\BHDrvx64.sys (Symantec Corporation)
DRV:64bit: - (SYMTDI) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\symtdi.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\NISx64\1008000.029\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (tdcmdpst) -- C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (risdpcie) -- C:\Windows\SysNative\drivers\risdpe64.sys (REDC)
DRV:64bit: - (PMCF) -- C:\Windows\SysNative\drivers\PMCF.sys ()
DRV:64bit: - (tos_sps64) -- C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (TVALZ) -- C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) -- C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) -- C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) -- C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) -- C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) -- C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) -- C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) -- C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) -- C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) -- C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) -- C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwififlt) -- C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) -- C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) -- C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) -- C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) -- C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) -- C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) -- C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) -- C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (discache) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (ApfiltrService) -- C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) -- C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) -- C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) -- C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (rixdpcie) -- C:\Windows\SysNative\drivers\rixdpe64.sys (REDC)
DRV:64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimspe64.sys (REDC)
DRV:64bit: - (Thpevm) -- C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) -- C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) -- C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) -- C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) -- C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files (x86)\ToggleEN\tbTog1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

FF - HKLM\software\mozilla\Firefox\Extensions\\[emailprotected]: C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0379.0\Firefox [2010/01/05 00:08:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/01/05 00:08:21 | 000,000,000 | ---D | M]

[2010/01/04 23:56:42 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\Mozilla\Extensions

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files (x86)\ToggleEN\tbTog1.dll (Conduit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files (x86)\ToggleEN\tbTog1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files (x86)\ToggleEN\tbTog1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (LSI Corp.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe (Toshiba)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe File not found
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [Camtasia Recorder] C:\Program Files (x86)\TechSmith\Camtasia Studio 6\CamRecorder.exe (TechSmith Corporation)
O4 - HKCU..\Run: [hsfe8owijfisjhgs7ye39gjsoighsd7y3eu] C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe ()
O4 - HKCU..\Run: [M5T8QL3YW3] C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MyTOSHIBA] C:\Program Files (x86)\TOSHIBA\My Toshiba\MyToshiba.exe (TOSHIBA)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\Bernabe's\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk = C:\Users\Bernabe's\AppData\Roaming\GameRanger\GameRanger\Data\GameRanger.exe (GameRanger Technologies)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - HKLM WINLOGON: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{ecdc12ef-ed14-11de-9fab-90e6ba02d3e3}\Shell - "" = AutoRun
O33 - MountPoints2\{ecdc12ef-ed14-11de-9fab-90e6ba02d3e3}\Shell\AutoRun\command - "" = E:\start.exe -- File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/02 09:53:22 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\49253DE2FC994BE399A4DAB01A8E6088.TMP
[2010/06/01 22:23:03 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\Desktop\PRIVATE FILE
[2010/06/01 21:29:47 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Roaming\Malwarebytes
[2010/06/01 21:29:35 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/01 21:29:34 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2010/06/01 21:29:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/01 21:29:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/06/01 21:22:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2010/06/01 20:06:09 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Roaming\SUPERAntiSpyware.com
[2010/06/01 20:06:09 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/06/01 20:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\SASCORE
[2010/05/31 20:22:40 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/05/31 20:06:51 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Local\ElevatedDiagnostics
[2010/05/31 13:22:06 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Local\nltnjatoq
[2010/05/31 13:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Update
[2010/05/29 16:49:18 | 000,000,000 | ---D | C] -- C:\OtsLabs
[2010/05/29 13:32:53 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Roaming\WinRAR
[2010/05/29 13:32:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2010/05/29 00:39:19 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\Tracing
[2010/05/29 00:38:32 | 000,061,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\fssfltr.sys
[2010/05/29 00:38:32 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010/05/29 00:38:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2010/05/24 23:19:15 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\Documents\Camtasia Studio
[2010/05/24 23:19:09 | 000,107,864 | ---- | C] (TechSmith Corporation) -- C:\windows\SysWow64\tsccvid.dll
[2010/05/24 23:19:07 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\QuickTime
[2010/05/24 23:18:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared
[2010/05/24 23:18:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TechSmith
[2010/05/24 20:34:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iMedix Gamebox
[2010/05/24 20:34:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameBox
[2010/05/24 18:02:11 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Roaming\Apple Computer
[2010/05/24 18:02:11 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Local\Apple Computer
[2010/05/24 18:02:00 | 000,126,312 | ---- | C] (GEAR Software Inc.) -- C:\windows\SysNative\GEARAspi64.dll
[2010/05/24 18:02:00 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\windows\SysWow64\GEARAspi.dll
[2010/05/24 18:02:00 | 000,034,152 | ---- | C] (GEAR Software Inc.) -- C:\windows\SysNative\drivers\GEARAspiWDM.sys
[2010/05/24 18:02:00 | 000,000,000 | ---D | C] -- C:\windows\SysNative\DRVSTORE
[2010/05/24 18:01:42 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/24 18:01:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2010/05/24 18:01:42 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/24 18:01:42 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/05/24 18:00:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010/05/24 18:00:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010/05/24 18:00:43 | 000,000,000 | ---D | C] -- C:\Users\Bernabe's\AppData\Local\Apple
[2010/05/24 18:00:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2010/05/24 18:00:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/05/24 18:00:15 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/05/24 18:00:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2010/05/24 18:00:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010/05/24 18:00:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2010/05/23 22:19:41 | 000,000,000 | ---D | C] -- C:\Fraps
[2010/05/22 18:43:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Redbana
[2010/05/22 18:41:19 | 1418,355,454 | ---- | C] (Macrovision Corporation) -- C:\Users\Bernabe's\Desktop\Setup_America.exe
[2010/05/18 10:26:13 | 002,942,976 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Bernabe's\Desktop\SUPERAntiSpyware.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\Bernabe's\*.tmp files -> C:\Users\Bernabe's\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/02 10:03:38 | 002,097,152 | -HS- | M] () -- C:\Users\Bernabe's\ntuser.dat
[2010/06/02 09:54:39 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 09:54:39 | 000,015,568 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 09:54:31 | 000,000,104 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Control Panel - Shortcut.lnk
[2010/06/02 09:47:42 | 000,000,302 | -H-- | M] () -- C:\windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/02 09:47:38 | 000,000,894 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/02 09:47:15 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2010/06/02 09:47:13 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2010/06/02 09:47:09 | 3192,262,656 | -HS- | M] () -- C:\hiberfil.sys
[2010/06/02 09:46:26 | 001,665,669 | -H-- | M] () -- C:\Users\Bernabe's\AppData\Local\IconCache.db
[2010/06/02 00:15:38 | 000,713,888 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2010/06/02 00:15:38 | 000,615,360 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2010/06/02 00:15:38 | 000,103,702 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2010/06/01 23:36:00 | 000,000,898 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/01 22:42:57 | 000,001,454 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Internet Explorer.lnk
[2010/06/01 21:29:38 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:24:31 | 000,002,104 | ---- | M] () -- C:\Users\Bernabe's\Desktop\HijackThis.lnk
[2010/06/01 20:06:06 | 000,001,385 | ---- | M] () -- C:\Users\Bernabe's\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/05/31 18:55:41 | 000,003,224 | ---- | M] () -- C:\bootsqm.dat
[2010/05/31 14:49:04 | 000,000,355 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Computer - Shortcut.lnk
[2010/05/31 12:41:30 | 000,001,786 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Audition.lnk
[2010/05/30 13:58:23 | 000,041,530 | ---- | M] () -- C:\Users\Bernabe's\Desktop\BASTA.wlmp
[2010/05/30 03:33:28 | 000,003,584 | ---- | M] () -- C:\Users\Bernabe's\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/29 20:29:00 | 000,000,506 | -H-- | M] () -- C:\windows\tasks\Norton Security Scan for Bernabe's.job
[2010/05/29 00:54:52 | 000,001,304 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Windows Live Movie Maker.lnk
[2010/05/24 23:35:44 | 000,002,581 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Camtasia Recorder.lnk
[2010/05/24 23:18:57 | 000,002,575 | ---- | M] () -- C:\Users\Bernabe's\Desktop\Camtasia Studio.lnk
[2010/05/24 18:02:06 | 000,002,429 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/05/18 10:26:13 | 002,942,976 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Bernabe's\Desktop\SUPERAntiSpyware.exe
[2010/05/11 19:19:22 | 000,010,461 | ---- | M] () -- C:\Users\Bernabe's\Documents\THE BOOKFAIR AT SCOOL.docx
[2010/05/11 18:56:25 | 000,012,070 | ---- | M] () -- C:\Users\Bernabe's\Documents\Rules In School.docx
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\Bernabe's\*.tmp files -> C:\Users\Bernabe's\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/02 09:54:31 | 000,000,104 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Control Panel - Shortcut.lnk
[2010/06/01 22:42:57 | 000,001,454 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Internet Explorer.lnk
[2010/06/01 21:29:38 | 000,001,020 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:22:21 | 000,002,104 | ---- | C] () -- C:\Users\Bernabe's\Desktop\HijackThis.lnk
[2010/06/01 20:06:06 | 000,001,385 | ---- | C] () -- C:\Users\Bernabe's\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/05/31 18:55:41 | 000,003,224 | ---- | C] () -- C:\bootsqm.dat
[2010/05/31 14:49:04 | 000,000,355 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Computer - Shortcut.lnk
[2010/05/31 13:21:00 | 000,000,302 | -H-- | C] () -- C:\windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/05/30 03:41:54 | 000,041,530 | ---- | C] () -- C:\Users\Bernabe's\Desktop\BASTA.wlmp
[2010/05/29 00:54:52 | 000,001,304 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Windows Live Movie Maker.lnk
[2010/05/24 23:35:44 | 000,002,581 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Camtasia Recorder.lnk
[2010/05/24 23:31:40 | 000,003,584 | ---- | C] () -- C:\Users\Bernabe's\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/24 23:18:57 | 000,002,575 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Camtasia Studio.lnk
[2010/05/24 18:02:06 | 000,002,429 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/05/22 18:44:10 | 000,001,786 | ---- | C] () -- C:\Users\Bernabe's\Desktop\Audition.lnk
[2010/05/11 19:19:22 | 000,010,461 | ---- | C] () -- C:\Users\Bernabe's\Documents\THE BOOKFAIR AT SCOOL.docx
[2010/05/11 00:38:45 | 000,012,070 | ---- | C] () -- C:\Users\Bernabe's\Documents\Rules In School.docx
[2010/02/22 22:59:08 | 000,000,621 | ---- | C] () -- C:\windows\SysWow64\Franklin Access Manager.ini
[2009/12/19 18:15:19 | 000,000,013 | RHS- | C] () -- C:\windows\SysWow64\drivers\fbd.sys
[2009/09/24 09:16:35 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2009/12/20 21:02:04 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\DragonicaSCB
[2010/01/30 16:13:27 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\GameRanger
[2010/04/12 20:35:14 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\TOSHIBA
[2009/12/20 00:03:31 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\Ulead Systems
[2009/12/19 18:14:59 | 000,000,000 | ---D | M] -- C:\Users\Bernabe's\AppData\Roaming\WinBatch
[2010/06/02 09:39:43 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/02 09:47:42 | 000,000,302 | -H-- | M] () -- C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========


< End of report >
THIS IS THE EXTRAS



OTL Extras logfile created on: 6/2/2010 10:02:13 AM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = E:\COMBOFIX
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 69.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 239.18 Gb Free Space | 83.65% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.87 Gb Total Space | 0.61 Gb Free Space | 32.51% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BERNABES-PC
Current User Name: Bernabe's
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [OtsMedia.Surf] -- "C:\OtsLabs\OTSPLAY.EXE" "%1" /play /surf File not found
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [OtsMedia.Surf] -- "C:\OtsLabs\OTSPLAY.EXE" "%1" /play /surf File not found
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{5AC309D7-93D6-418F-8DCA-DD710724A5B4}" = Windows Live Family Safety
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"LTMOH" = LSI V92 MOH Application
"TOSHIBA Software Modem" = TOSHIBA Software Modem

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}" = MyToshiba
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.06.03.02
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3B843B38-04B1-4CE6-8888-586273E0F289}" = Quickbooks Financial Center
"{3D281B1C-BF39-4893-B32A-EAB3B84BDE34}" = Audition
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{49253DE2-FC99-4BE3-99A4-DAB01A8E6088}" = Camtasia Studio 6
"{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = Toshiba Application Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AEAF9CC-390B-49C0-8F7F-14092BF163B6}" = NetZero Launcher
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{9FE10246-A876-4979-B345-CADE6863BD8E}" = TOSHIBA Supervisor Password
"{A65F7CF8-6F76-40CE-B44D-D5A89D9881C7}" = MSN Toolbar Platform
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C12A198C-E751-4729-839A-8FA07CF941C1}_is1" = Dragonica
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Toshiba Online Backup
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D5D8637D-FA1C-4CAD-91FC-4ADB1C284A21}" = TOSHIBA Hardware Setup
"{DA84ECBF-4B79-47F2-B34C-95C38484C058}" = SKYPE Launcher
"{E487EE7D-EAAA-4E2A-9116-E3B477D8A74F}" = TOSHIBA USB Sleep and Charge Utility
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = Toshiba Quality Application
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice GUARD
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"{F3529665-D75E-4D6D-98F0-745C78C68E9B}" = TOSHIBA ConfigFree
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NIS" = Norton Internet Security
"NSS" = Norton Security Scan
"ToggleEN Toolbar" = ToggleEN Toolbar
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/30/2010 9:40:39 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 9:40:39 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 9:43:27 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 9:43:27 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 10:27:46 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 10:27:46 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 10:28:56 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/30/2010 10:28:56 PM | Computer Name = Bernabes-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 5/31/2010 2:59:50 AM | Computer Name = Bernabes-PC | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.107:49152 4 Bernabes-PC.local.
Addr 192.168.0.107

Error - 5/31/2010 2:59:50 AM | Computer Name = Bernabes-PC | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will rename 4 Bernabes-PC.local.
Addr 192.168.0.101

[ System Events ]
Error - 5/31/2010 10:26:44 PM | Computer Name = Bernabes-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 11:08:03 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:09 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:15 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:21 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:29 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:35 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:41 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:08:47 PM | Computer Name = Bernabes-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/31/2010 11:10:50 PM | Computer Name = Bernabes-PC | Source = NetBT | ID = 4321
Description = The name "BERNABES-PC :0" could not be registered on the interface
with IP address 192.168.0.101. The computer with the IP address 192.168.0.107 did
not allow the name to be claimed by this computer.


< End of report >Please read here for more information about WildTangent. Your choice if you want to remove it or not.

If you choose to follow my advice, please follow these instructions.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

WildTangent Web Driver, WildTangent Games or anything else related to WildTangent.

==================================

Add or Remove Programs

1. Click on the Windows Start button and click on the Control Panel
2. In the Control Panel window, double-click Programs and Features icon.
3. When the Programs and Features window has fully populated, check for GameBox and uninstall it. It is a malicious program.

=======================================

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :OTL
    O4 - HKCU..\Run: [hsfe8owijfisjhgs7ye39gjsoighsd7y3eu] C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe ()
    O4 - HKCU..\Run: [M5T8QL3YW3] C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe ()

    :files
    C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe ()
    C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe ()
    C:\Users\Bernabe's\49253DE2FC994BE399A4DAB01A8E6088.TMP

    :commands
    [resethosts]
    [purity]
    [clearrestorepoints]
    [emptytemp]
    [start explorer]


  • Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

==============================================

I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

IM DYING WAITING FOR THE ESET TO FINISH BUT AS SOON AS I FINISH IT ILL POST THE LOG!

FYI INTERNET IS WORKING NOW AND NO MORE IRRITATING POP OUTS!

THANK U VERY MUCH! XDAll processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hsfe8owijfisjhgs7ye39gjsoighsd7y3eu deleted successfully.
File not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\M5T8QL3YW3 deleted successfully.
File not found.
========== FILES ==========
File\Folder C:\Users\Bernabe's\AppData\Local\Temp\cem6l.exe () not found.
File\Folder C:\Users\Bernabe's\AppData\Local\Temp\Xcl.exe () not found.
File\Folder C:\Users\Bernabe's\49253DE2FC99A4DABO1A8E6088.TMP not found.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Error: Unable to interpret <[clearrestorepoints]> in the current context!

[EMPTYTEMP]

User: All Users

User: AppData

User: Bernabe's
->Temp folder emptied: 1492001980 bytes
->Temporary Internet Files folder emptied: 92372857 bytes
->Java cache emptied: 4616576 bytes
->Google Chrome cache emptied: 348239320 bytes
->Flash cache emptied: 85369 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8729698 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,856.00 mb


OTL by OldTimer - Version 3.2.5.3 log created on 06022010_202449

Files\Folders moved on Reboot...
C:\Users\Bernabe's\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\windows\temp\JET7AAB.tmp not found!

Registry entries deleted on Reboot...
Im sorry, I cant find the log for the ESET. After it scanned i didnt found the "list of found threats" beacause i think it scanned no threats at all. And i tried to find it on my computer but i cant find the log file. Is it ok if I dont give you the log?

And for the files that you made me download pls tell me what to do with them?Quote
And for the files that you made me download pls tell me what to do with them?
If it is the programs that we used, we'll get to cleaning those up later. Let's just try another scan.

Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:

•Double-click on drweb-cureit.exe and then click Start

•An information notice will appear, click OK.

•This starts a short scan that will scan the files currently running in memory.
•If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version

•If or when something is found, click the Yes button when it asks you if you want to cure it.
•Once the short scan has finished, Click Settings > Change Settings

•Under the Scanning tab UNcheck Heuristic analysis and click OK

•Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.

•Click Yes to all if it asks if you want to cure/move any file(s).

•When the scan is done.
•In the Dr.Web CureIt menu on top left, click File and choose Save report list.

•Save the DrWeb.csv report to your Desktop.

•Exit Dr.Web Cureit.
Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
* After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
* Copy and paste that log in the next reply.

the dr. web is taking so long... XDAfter it scanned i clicked "file" and tried to click "save report list" but it wont let me. It scanned 376326 files in all. And it says at the bottom "Done-no viruses found." Ok. That sound good. If there are no other issues, it's time for some clean-up

To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.

==========================================

To remove all of the tools we used and the files and folders they created, please do the following:

Double click OTC.exe.
Click the CleanUp! button.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes.

Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

===========================================
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

===================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Can i just delete them manually cause i cant find OTC.exe and for the control pannel I cant find "System Maintenance".THANK U ^^Quote
Can i just delete them manually cause i cant find OTC.exe and for the control panel I cant find "System Maintenance".

Sorry. That should read double-click OTL.exe. That's the tool we used to get that long report. As for System Maintenance, I know very little about Windows 7 so I just did that part about resetting your Restore Point from what I found on the net. Please check your computer on how to turn off and then turn back on your System Restore.I have the same problem as stated here however I can not even get rkill to run on my computer. I have tried downloading all 4 version listed in the first step and non of them run.

Any suggestions?

Thanks.
4411.

Solve : Cannot Install HijackThis?

Answer»

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the CONTENT of the following codebox into the main textfield:
Code: [Select]:filefind
smb.sys
atapi.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the RESULTS of the scan. Please POST this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txtSystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 18:59 on 22/06/2010 by Dawn (ADMINISTRATOR - Elevation successful)

========== filefind ==========

SEARCHING for "smb.sys"
C:\Windows\System32\drivers\smb.sys--a--- 66560 bytes[18:02 17/09/2009][04:45 11/04/2009] 031E6BCD53C9B2B9ACE111EAFEC347B6
C:\Windows\winsxs\x86_microsoft-windows-nbsmb_31bf3856ad364e35_6.0.6001.18000_none_5f6a9133f7f64138\smb.sys--a--- 66560 bytes[02:25 21/01/2008][02:25 21/01/2008] 40E0C1EA4D5CEB087E04F34560980418

Searching for "atapi.sys"
C:\Windows\ERDNT\cache\atapi.sys--a--- 21560 bytes[22:55 14/06/2010][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys--a--- 19944 bytes[18:03 17/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys--a--- 19048 bytes[10:25 02/11/2006][09:49 02/11/2006] 4F4FCB8B6EA06784FB6D475B7EC7300F
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys--a--- 21560 bytes[02:23 21/01/2008][02:23 21/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\System32\drivers\atapi.sys------ 21560 bytes[02:23 21/01/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys--a--- 21560 bytes[02:23 21/01/2008][02:23 21/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 0D83C87A801A3DFCD1BF73893FE7518C
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys--a--- 21560 bytes[21:50 25/11/2008][21:50 25/11/2008] 96DC4E1A9F90CCD489950A8935425C59
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys--a--- 19944 bytes[18:03 17/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4

-=End Of File=-Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the codebox below into it:
Code: [Select]killall::

FCopy::
C:\Windows\System32\drivers\smb.sys | C:\Windows\winsxs\x86_microsoft-windows-nbsmb_31bf3856ad364e35_6.0.6001.18000_none_5f6a9133f7f64138\smb.sys

Reboot::
  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
ComboFix 10-06-23.02 - Dawn 06/23/2010 20:16:28.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.836 [GMT -4:00]
Running from: c:\users\Dawn\Downloads\ComboFix.exe
Command switches used :: c:\users\Dawn\Desktop\CFScript.txt.lnk
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2010-05-24 to 2010-06-24 )))))))))))))))))))))))))))))))
.

2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Public\AppData\Local\temp
2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Default\AppData\Local\temp
2010-06-24 00:27 . 2010-06-24 00:27--------d-----w-c:\users\Bewn\AppData\Local\temp
2010-06-24 00:10 . 2010-06-24 00:11--------d-----w-C:\32788R22FWJFW
2010-06-23 20:41 . 2009-11-08 14:5599176----a-w-c:\windows\system32\PresentationHostProxy.dll
2010-06-23 20:41 . 2009-11-08 14:5549472----a-w-c:\windows\system32\netfxperf.dll
2010-06-23 20:41 . 2009-11-08 14:55297808----a-w-c:\windows\system32\mscoree.dll
2010-06-23 20:41 . 2009-11-08 14:55295264----a-w-c:\windows\system32\PresentationHost.exe
2010-06-23 20:41 . 2009-11-08 14:551130824----a-w-c:\windows\system32\dfshim.dll
2010-06-21 01:44 . 2010-06-21 01:44--------d-----w-c:\program files\ESET
2010-06-15 23:05 . 2010-06-15 23:05--------d-----w-c:\program files\Windows Portable Devices
2010-06-15 20:19 . 2009-09-10 02:0092672----a-w-c:\windows\system32\UIAnimation.dll
2010-06-15 20:19 . 2009-09-10 02:013023360----a-w-c:\windows\system32\UIRibbon.dll
2010-06-15 20:19 . 2009-09-10 02:001164800----a-w-c:\windows\system32\UIRibbonRes.dll
2010-06-15 20:18 . 2009-09-25 01:33369664----a-w-c:\windows\system32\WMPhoto.dll
2010-06-15 20:18 . 2009-09-24 22:54258048----a-w-c:\windows\system32\winspool.drv
2010-06-15 20:18 . 2009-09-25 01:27634880----a-w-c:\windows\system32\drivers\dxgkrnl.sys
2010-06-15 20:18 . 2009-09-25 01:2737888----a-w-c:\windows\system32\cdd.dll
2010-06-15 20:16 . 2009-10-01 01:0230208----a-w-c:\windows\system32\WPDShextAutoplay.exe
2010-06-15 20:16 . 2009-10-01 01:0231232----a-w-c:\windows\system32\BthMtpContextHandler.dll
2010-06-15 20:16 . 2009-10-01 01:0181920----a-w-c:\windows\system32\wpdbusenum.dll
2010-06-15 20:16 . 2009-10-01 01:0160928----a-w-c:\windows\system32\PortableDeviceConnectApi.dll
2010-06-15 20:16 . 2009-10-01 01:022537472----a-w-c:\windows\system32\wpdshext.dll
2010-06-15 20:16 . 2009-10-01 01:02334848----a-w-c:\windows\system32\PortableDeviceApi.dll
2010-06-15 20:16 . 2009-10-01 01:0287552----a-w-c:\windows\system32\WPDShServiceObj.dll
2010-06-15 20:16 . 2009-10-01 01:01546816----a-w-c:\windows\system32\wpd_ci.dll
2010-06-15 20:16 . 2009-10-01 01:01160256----a-w-c:\windows\system32\PortableDeviceTypes.dll
2010-06-15 20:16 . 2009-10-01 01:01350208----a-w-c:\windows\system32\WPDSp.dll
2010-06-15 20:16 . 2009-10-01 01:01196608----a-w-c:\windows\system32\PortableDeviceWMDRM.dll
2010-06-15 20:16 . 2009-10-01 01:01100864----a-w-c:\windows\system32\PortableDeviceClassExtension.dll
2010-06-15 20:14 . 2009-10-08 21:074096----a-w-c:\windows\system32\oleaccrc.dll
2010-06-15 20:14 . 2009-10-08 21:08555520----a-w-c:\windows\system32\UIAutomationCore.dll
2010-06-15 20:14 . 2009-10-08 21:08234496----a-w-c:\windows\system32\oleacc.dll
2010-06-15 01:40 . 2010-05-04 05:5571680----a-w-c:\windows\system32\iesetup.dll
2010-06-15 01:40 . 2010-05-04 05:55109056----a-w-c:\windows\system32\iesysprep.dll
2010-06-15 01:40 . 2010-05-04 04:31133632----a-w-c:\windows\system32\ieUnatt.exe
2010-06-15 01:40 . 2010-01-06 15:391696256----a-w-c:\windows\system32\gameux.dll
2010-06-15 01:40 . 2010-01-06 15:3828672----a-w-c:\windows\system32\Apphlpdm.dll
2010-06-15 01:40 . 2010-01-06 13:304240384----a-w-c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-15 01:40 . 2010-05-01 14:132037248----a-w-c:\windows\system32\win32k.sys
2010-06-15 01:10 . 2010-06-15 01:46--------d-----w-c:\users\Dawn\AppData\Local\Microsoft Games
2010-06-14 22:57 . 2010-06-24 00:28--------d-----w-c:\users\Dawn\AppData\Local\temp
2010-06-14 22:57 . 2010-06-24 00:27--------d-----w-c:\users\Ben\AppData\Local\temp
2010-06-13 18:49 . 2010-06-13 18:49388096----a-r-c:\users\Dawn\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-13 18:13 . 2010-06-13 18:37--------d-----w-c:\program files\Trend Micro
2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\users\Dawn\AppData\Roaming\Malwarebytes
2010-06-13 04:01 . 2010-04-29 19:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\programdata\Malwarebytes
2010-06-13 04:01 . 2010-06-13 04:01--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-06-13 04:01 . 2010-04-29 19:3920952----a-w-c:\windows\system32\drivers\mbam.sys
2010-06-12 23:55 . 2010-06-12 23:5563488----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-06-12 23:55 . 2010-06-12 23:5552224----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-06-12 23:55 . 2010-06-12 23:55117760----a-w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\users\Dawn\AppData\Roaming\SUPERAntiSpyware.com
2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\programdata\SUPERAntiSpyware.com
2010-06-12 23:54 . 2010-06-12 23:54--------d-----w-c:\program files\SUPERAntiSpyware
2010-06-12 23:32 . 2010-06-12 23:32--------d-----w-c:\program files\CCleaner
2010-06-07 02:47 . 2010-06-07 02:47411368----a-w-c:\windows\system32\deployJava1.dll
2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\ca-ES
2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\eu-ES
2010-05-31 02:21 . 2010-05-31 02:23--------d-----w-c:\windows\system32\vi-VN
2010-05-31 01:49 . 2010-05-31 01:49--------d-----w-c:\windows\system32\EventProviders
2010-05-28 18:18 . 2010-05-28 18:18--------d-----w-c:\windows\Sun
2010-05-28 03:39 . 2010-05-28 03:39--------d-----w-c:\users\Dawn\AppData\Roaming\vlc
2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\users\Dawn\AppData\Local\Graboid_Inc
2010-05-28 03:35 . 2010-05-28 03:40--------d-----w-c:\users\Dawn\AppData\Local\Graboid
2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\users\Dawn\AppData\Roaming\MozillaControl
2010-05-28 03:35 . 2010-05-28 03:35--------d-----w-c:\program files\Mozilla ActiveX Control v1.7.12
2010-05-28 03:34 . 2010-05-28 03:34--------d-----w-c:\program files\VideoLAN
2010-05-28 03:33 . 2010-05-28 03:44--------d-----w-c:\program files\Graboid
2010-05-25 20:06 . 2010-04-23 14:132048----a-w-c:\windows\system32\tzres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-15 23:04 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
2010-06-15 23:04 . 2006-11-02 10:25665600----a-w-c:\windows\inf\drvindex.dat
2010-06-15 23:03 . 2010-06-15 23:030---ha-w-c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-06-15 23:02 . 2008-12-27 05:07--------d-----w-c:\program files\Microsoft Silverlight
2010-06-07 02:48 . 2008-11-25 20:22--------d-----w-c:\program files\Common Files\Java
2010-06-07 02:47 . 2008-11-25 20:22--------d-----w-c:\program files\Java
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Calendar
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Sidebar
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Journal
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Collaboration
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Photo Gallery
2010-05-31 02:23 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Defender
2010-05-31 01:46 . 2008-12-08 01:44--------d-----w-c:\programdata\Viewpoint
2010-05-29 03:12 . 2009-03-17 02:445972----a-w-c:\users\Ben\AppData\Local\d3d9caps.dat
2010-05-28 03:46 . 2009-03-03 02:13--------d-----w-c:\users\Dawn\AppData\Roaming\Apple Computer
2010-05-26 17:06 . 2010-06-15 01:4134304----a-w-c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-15 01:41289792----a-w-c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-03 14:42221568------w-c:\windows\system32\MpSigStub.exe
2010-05-20 20:32 . 2010-05-20 20:32666112----a-w-c:\users\Ben\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv306hw-1004220-0-main.dll
2010-05-04 23:46 . 2010-05-04 23:44--------d-----w-c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-04 23:46 . 2010-05-04 23:44--------d-----w-c:\program files\iTunes
2010-05-04 23:44 . 2010-05-04 23:44--------d-----w-c:\program files\iPod
2010-05-04 23:44 . 2009-03-03 02:08--------d-----w-c:\program files\Common Files\Apple
2010-05-04 23:42 . 2010-05-04 23:42--------d-----w-c:\program files\Apple Software Update
2010-05-04 22:58 . 2010-05-04 22:58--------d-----w-c:\users\Dawn\AppData\Roaming\Roxio
2010-05-04 22:45 . 2010-05-04 22:44--------d-----w-c:\program files\QuickTime
2010-05-04 05:59 . 2010-06-15 01:41916480----a-w-c:\windows\system32\wininet.dll
2010-04-28 19:45 . 2010-04-28 19:4573000----a-w-c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-15 00:30 . 2009-05-19 01:05143976----a-w-c:\users\Dawn\AppData\Roaming\Move Networks\uninstall.exe
2010-04-15 00:30 . 2009-10-15 00:505642688----a-w-c:\users\Dawn\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
2010-04-05 17:01 . 2010-06-15 01:4167072----a-w-c:\windows\system32\asycfilt.dll
2009-11-02 20:15 . 2009-11-02 20:15119808----a-w-c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-11-25 20:42 . 2008-11-25 20:4276--sh--r-c:\windows\CT4CET.bin
2008-11-25 21:51 . 2008-11-25 21:508192--sha-w-c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( [emailprotected]_22.53.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-23 20:41 . 2009-11-08 14:5599176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.1.6001.18242_none_f290a8a118b9134c\PresentationHostProxy.dll
+ 2010-06-22 20:02 . 2010-03-30 11:5999176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.0.6002.22377_none_2cb6816f90457914\PresentationHostProxy.dll
+ 2010-06-22 20:02 . 2010-04-05 12:1999176 c:\windows\winsxs\x86_wpf-presentationhostproxy_31bf3856ad364e35_6.0.6002.18236_none_2c57240a7708502f\PresentationHostProxy.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0140448 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdusb.sys
+ 2010-06-15 20:16 . 2009-10-01 01:0161952 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpus.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0168608 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpip.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0178336 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpbt.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0133280 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdconns.dll
+ 2010-06-15 01:40 . 2010-04-12 12:2217256 c:\windows\winsxs\x86_wcf-m_svc_mon_sup_dll_31bf3856ad364e35_6.0.6002.22380_none_a7f79e1e62233116\ServiceMonikerSupport.dll
+ 2010-06-15 01:40 . 2010-04-12 12:2117256 c:\windows\winsxs\x86_wcf-m_svc_mon_sup_dll_31bf3856ad364e35_6.0.6002.18239_none_a7ad138948d4e9a6\ServiceMonikerSupport.dll
+ 2010-06-23 20:41 . 2009-11-08 14:5511600 c:\windows\winsxs\x86_netfx-mscorees_dll_31bf3856ad364e35_6.1.6001.18242_none_e15f1c362a176592\mscorees.dll
+ 2010-06-23 20:41 . 2009-11-08 14:5549472 c:\windows\winsxs\x86_netfx-fw_netfxperf_dll_31bf3856ad364e35_6.1.6001.18242_none_5c993a771a2304b1\netfxperf.dll
+ 2010-06-15 01:39 . 2010-03-25 11:5430544 c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6002.22372_none_adfdfb72a63b9516\aspnet_wp.exe
+ 2010-06-15 01:39 . 2010-03-25 11:5330544 c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6002.18232_none_c4c7a10a8c97cfb4\aspnet_wp.exe
+ 2010-06-15 20:16 . 2009-10-01 01:0287552 c:\windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.0.6002.18112_none_130696d2c3f64ac4\WPDShServiceObj.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0230208 c:\windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.0.6002.18112_none_130696d2c3f64ac4\WPDShextAutoplay.exe
+ 2010-06-15 20:16 . 2009-10-01 01:0160928 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceConnectApi.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0181920 c:\windows\winsxs\x86_microsoft-windows-wpd-busenumservice_31bf3856ad364e35_6.0.6002.18112_none_79dbda7dc92efc79\wpdbusenum.dll
+ 2010-06-15 20:19 . 2009-09-10 02:0092672 c:\windows\winsxs\x86_microsoft-windows-uianimation_31bf3856ad364e35_7.0.6002.18108_none_7edc01bff7a1cb45\UIAnimation.dll
+ 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.22164_none_2de0cf8ef1d7d6cc\printfilterpipelineprxy.dll
+ 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.18060_none_2d53319bd8bdd1a6\printfilterpipelineprxy.dll
+ 2010-06-15 01:41 . 2010-04-05 17:1467072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6002.22377_none_78f4d4e8cf978645\asycfilt.dll
+ 2010-06-15 01:41 . 2010-04-05 17:0167072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6002.18236_none_78957783b65a5d60\asycfilt.dll
+ 2010-06-15 01:41 . 2010-04-05 16:2867072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6001.22665_none_77173258d26ae282\asycfilt.dll
+ 2010-06-15 01:41 . 2010-04-05 16:0767072 c:\windows\winsxs\x86_microsoft-windows-o..mation-asyncfilters_31bf3856ad364e35_6.0.6001.18454_none_76976349b9461049\asycfilt.dll
+ 2010-06-15 20:18 . 2009-09-25 01:2737888 c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_7.0.6002.18107_none_9f26906a6b93696c\cdd.dll
+ 2010-06-15 01:40 . 2010-05-04 06:3071680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\iesetup.dll
+ 2010-06-15 01:40 . 2010-05-04 06:3055808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\iernonce.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5571680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\iesetup.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5555808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\iernonce.dll
+ 2010-06-15 01:40 . 2010-05-04 04:5813312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23019_none_dfbeba5109ad11a7\msfeedssync.exe
+ 2010-06-15 01:40 . 2010-05-04 06:3055296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23019_none_dfbeba5109ad11a7\msfeedsbs.dll
+ 2010-06-15 01:40 . 2010-05-04 04:3013312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18928_none_df297713f0983e5c\msfeedssync.exe
+ 2010-06-15 01:40 . 2010-05-04 05:5655296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18928_none_df297713f0983e5c\msfeedsbs.dll
+ 2010-06-15 01:40 . 2010-05-04 06:3164512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\WininetPlugin.dll
+ 2010-06-15 01:40 . 2010-05-04 06:3025600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\jsproxy.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5964512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\WininetPlugin.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5525600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\jsproxy.dll
+ 2010-06-15 01:41 . 2010-05-26 17:1023552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\lpk.dll
+ 2010-06-15 01:41 . 2010-05-26 17:0972704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\fontsub.dll
+ 2010-06-15 01:41 . 2010-05-26 17:0810240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\dciman32.dll
+ 2010-06-15 01:41 . 2010-05-26 17:0834304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\atmlib.dll
+ 2009-07-15 14:05 . 2009-06-15 14:5223552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\lpk.dll
+ 2010-01-13 12:56 . 2009-10-19 13:3572704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\fontsub.dll
+ 2009-07-15 14:05 . 2009-06-15 14:5110240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\dciman32.dll
+ 2010-06-15 01:41 . 2010-05-26 17:0634304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\atmlib.dll
+ 2010-06-15 01:41 . 2010-05-26 16:2023552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\lpk.dll
+ 2010-06-15 01:41 . 2010-05-26 16:1972704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\fontsub.dll
+ 2010-06-15 01:41 . 2010-05-26 16:1810240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\dciman32.dll
+ 2010-06-15 01:41 . 2010-05-26 16:1734304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\atmlib.dll
+ 2010-01-13 12:56 . 2009-10-19 14:2472704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\fontsub.dll
+ 2009-07-15 14:05 . 2009-06-15 15:2010240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\dciman32.dll
+ 2010-06-15 01:41 . 2010-05-26 16:1634304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\atmlib.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0231232 c:\windows\winsxs\x86_microsoft-windows-d..thmtpcontexthandler_31bf3856ad364e35_7.0.6002.18112_none_302fc434dcfbe04c\BthMtpContextHandler.dll
+ 2010-06-15 01:40 . 2010-01-06 16:0128672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.22303_none_8474f2d5770488ce\Apphlpdm.dll
+ 2010-06-15 01:40 . 2010-01-06 15:3828672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.18179_none_83a5a66c5e1a477e\Apphlpdm.dll
+ 2010-06-22 20:03 . 2010-04-16 16:0828672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.22672_none_8241d12f7a17ddea\Apphlpdm.dll
+ 2010-06-22 20:03 . 2010-04-16 16:0528672 c:\windows\winsxs\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.18461_none_81c2022060f30bb1\Apphlpdm.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0150688 c:\windows\winsxs\x86_bthmtpenum.inf_31bf3856ad364e35_6.0.6002.18112_none_01d56cf0911e704e\bthmtpenum.sys
+ 2010-06-15 01:40 . 2010-04-12 12:2332768 c:\windows\winsxs\msil_system.servicemodel.washosting_b77a5c561934e089_6.0.6002.22380_none_a725653cfb4fe6ae\System.ServiceModel.WasHosting.dll
+ 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\winsxs\msil_system.servicemodel.washosting_b77a5c561934e089_6.0.6002.18239_none_bded3d82e1adee9e\System.ServiceModel.WasHosting.dll
+ 2010-06-15 20:17 . 2009-09-24 22:5426112 c:\windows\System32\printfilterpipelineprxy.dll
- 2009-09-17 18:02 . 2009-04-11 06:2826112 c:\windows\System32\printfilterpipelineprxy.dll
+ 2010-06-23 20:41 . 2009-11-08 14:5511600 c:\windows\System32\MUI\0409\mscorees.dll
- 2010-04-02 18:38 . 2010-02-23 04:5413312 c:\windows\System32\msfeedssync.exe
+ 2010-06-15 01:40 . 2010-05-04 04:3013312 c:\windows\System32\msfeedssync.exe
- 2010-04-02 18:38 . 2010-02-23 06:3455296 c:\windows\System32\msfeedsbs.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5655296 c:\windows\System32\msfeedsbs.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5964512 c:\windows\System32\migration\WininetPlugin.dll
- 2010-04-02 18:38 . 2010-02-23 06:3964512 c:\windows\System32\migration\WininetPlugin.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5525600 c:\windows\System32\jsproxy.dll
- 2010-04-02 18:38 . 2010-02-23 06:3425600 c:\windows\System32\jsproxy.dll
- 2010-04-02 18:38 . 2010-02-23 06:3355808 c:\windows\System32\iernonce.dll
+ 2010-06-15 01:40 . 2010-05-04 05:5555808 c:\windows\System32\iernonce.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0140448 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdUsb.sys
+ 2010-06-15 20:16 . 2009-10-01 01:0161952 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpUS.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0168608 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpIP.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0178336 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdMtpbt.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0133280 c:\windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdConns.dll
+ 2010-06-15 20:16 . 2009-10-01 01:0150688 c:\windows\System32\DriverStore\FileRepository\bthmtpenum.inf_201caa7f\BthMtpEnum.sys
+ 2009-11-28 02:58 . 2010-06-17 23:5316384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-28 02:58 . 2010-06-01 22:4816384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-28 02:58 . 2010-06-17 23:5332768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-28 02:58 . 2010-06-01 22:4832768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-28 02:58 . 2010-06-01 22:4816384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-28 02:58 . 2010-06-17 23:5316384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
- 2009-09-17 18:02 . 2009-02-18 18:3832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2010-06-15 01:40 . 2010-04-12 12:2117256 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2010-06-15 01:39 . 2010-03-25 11:5330544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2010-06-15 20:14 . 2010-06-15 20:1449936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
- 2010-04-16 13:04 . 2010-04-16 13:0449936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
- 2010-04-16 13:04 . 2010-04-16 13:0435600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2010-06-15 20:14 . 2010-06-15 20:1435600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2010-06-15 20:11 . 2010-06-15 20:1149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-06-23 23:44 . 2010-06-23 23:4460928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\81ab082be2597d562533493d955b20fa\UIAutomationProvider.ni.dll
+ 2010-06-16 00:54 . 2010-06-16 00:5460928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\71446066f8f87652fa7303395df566cc\UIAutomationProvider.ni.dll
+ 2010-06-23 23:46 . 2010-06-23 23:4637888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\8f17237b1a97a723837bede4c5b10085\System.Windows.Presentation.ni.dll
+ 2010-06-23 23:46 . 2010-06-23 23:4636864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\6b60acb027ae9b015ffc61dcba421bd3\System.Web.DynamicData.Design.ni.dll
+ 2010-06-16 00:58 . 2010-06-16 00:5894208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\e3da89cc15807bd5c9747b4ba394cd41\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-06-16 00:58 . 2010-06-16 00:5882944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\ef965cf9c5c75294aef56d47f4b0eb26\System.AddIn.Contract.ni.dll
+ 2010-06-16 00:56 . 2010-06-16 00:5644032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\6fb97ad4786df4e2a5c0edaa3a284de8\stdole.ni.dll
+ 2010-06-16 00:58 . 2010-06-16 00:5847104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\f56c075fa1f45464ede198e36e79d617\PresentationFontCache.ni.exe
+ 2010-06-23 23:45 . 2010-06-23 23:4547104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\c57f58acdfc796bc888fcb6603715537\PresentationFontCache.ni.exe
+ 2010-06-16 00:54 . 2010-06-16 00:5439424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\76a79903753244ecd4bedb4b607da4b8\PresentationCFFRasterizer.ni.dll
+ 2010-06-23 23:44 . 2010-06-23 23:4439424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\44ecfa244cf6aa4212e23ba22349a240\PresentationCFFRasterizer.ni.dll
+ 2010-06-16 00:58 . 2010-06-16 00:5879872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\ec37fe0ddb66e6ed277cc9c83c39e134\napcrypt.ni.dll
+ 2010-06-16 00:54 . 2010-06-16 00:5455296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\3aa49e133664e428e319de2e6a008335\Microsoft.Vsa.ni.dll
+ 2010-06-16 00:53 . 2010-06-16 00:5315872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\84dda64a3e7cec7239ede8d5e48b5847\Microsoft.VisualC.ni.dll
+ 2010-06-16 00:55 . 2010-06-16 00:5574752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\f156806d82a796faf4968b2cb872141d\Microsoft.Build.Framework.ni.dll
+ 2010-06-16 00:57 . 2010-06-16 00:5765024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2990c6a100dc31f3a36bd8c2afafa92b\Microsoft.Build.Framework.ni.dll
+ 2010-06-16 00:57 . 2010-06-16 00:5768608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\f4e3668f28222716aef5866686aec3cc\loadmxf.ni.exe
+ 2010-06-23 23:44 . 2010-06-23 23:4468608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\6d929408f21f2b81b51dff132a83c60e\loadmxf.ni.exe
+ 2010-06-16 00:56 . 2010-06-16 00:5657856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\9e40e4d9ddeac7b337afb0ab2a45b7c7\ehiUserXp.ni.dll
+ 2010-06-16 00:56 . 2010-06-16 00:5655296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiReplay\53c8ef024a64e5e6c4a1a4e23db7c753\ehiReplay.ni.dll
+ 2010-06-16 00:56 . 2010-06-16 00:5623552 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtCOM\3c3b9f210946ad30b80aef7c2c61bec1\ehiExtCOM.ni.dll
+ 2010-06-23 23:45 . 2010-06-23 23:4539424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\8289c53c4bb2b134feb8e6da972fd492\ehExtCOM.ni.dll
+ 2010-06-16 00:56 . 2010-06-16 00:5639424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\49b927a353d3c2aa8cc6e5e27836adf7\ehExtCOM.ni.dll
+ 2010-06-16 00:56 . 2010-06-16 00:5614336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\8b295851a21fc513dcb5dbcd9b5385e6\dfsvc.ni.exe
+ 2010-06-16 00:53 . 2010-06-16 00:5325600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1bcbcac5237f54c73628936552c55b69\Accessibility.ni.dll
- 2009-09-17 18:02 . 2009-02-18 18:3832768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-06-15 01:40 . 2010-04-12 12:2132768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-06-15 20:14 . 2009-10-08 21:074096 c:\windows\winsxs\x86_microsoft-windows-oleaccrc_31bf3856ad364e35_6.0.6002.18156_none_7ae05aee84ac8b45\oleaccrc.dll
+ 2010-06-23 20:43 . 2010-04-14 17:536656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.dll
+ 2010-06-15 01:40 . 2010-01-06 13:312560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.22303_none_0e955139088d9e83\AcRes.dll
+ 2010-06-22 20:03 . 2010-04-16 14:162560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.22672_none_0c622f930ba0f39f\AcRes.dll
+ 2009-03-06 01:30 . 2010-06-21 12:212632 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2010-06-23 02:26 . 2010-06-23 20:512048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-06-14 22:32 . 2010-06-14 22:322048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-06-14 22:32 . 2010-06-14 22:322048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-06-23 02:26 . 2010-06-23 20:512048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-06-23 20:41 . 2009-11-08 14:55295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.1.6001.18242_none_37f9c545bf07d41a\PresentationHost.exe
+ 2010-06-22 20:02 . 2010-03-30 11:59295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.0.6002.22377_none_721f9e14369439e2\PresentationHost.exe
+ 2010-06-22 20:02 . 2010-04-05 12:19295264 c:\windows\winsxs\x86_wpf-presentationhostexe_31bf3856ad364e35_6.0.6002.18236_none_71c040af1d5710fd\PresentationHost.exe
+ 2010-06-22 20:02 . 2010-03-30 11:59130408 c:\windows\winsxs\x86_wpf-presentationhostdll_31bf3856ad364e35_6.0.6002.22377_none_7236d7fc36759770\PresentationHostDLL.dll
+ 2010-06-22 20:02 . 2010-04-05 12:19129896 c:\windows\winsxs\x86_wpf-presentationhostdll_31bf3856ad364e35_6.0.6002.18236_none_71d77a971d386e8b\PresentationHostDLL.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01839168 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtpdr.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01226816 c:\windows\winsxs\x86_wpdmtp.inf_31bf3856ad364e35_6.0.6002.18112_none_2177efcb83dd35a0\wpdmtp.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01227840 c:\windows\winsxs\x86_wpdfs.inf_31bf3856ad364e35_6.0.6002.18112_none_27ca7fa9cfc85a60\wpdfs.dll
+ 2010-06-15 01:40 . 2010-04-12 12:22970752 c:\windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783\System.Runtime.Serialization.dll
+ 2010-06-15 01:40 . 2010-04-12 12:21970752 c:\windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73\System.Runtime.Serialization.dll
+ 2010-06-15 01:40 . 2010-04-12 12:22442368 c:\windows\winsxs\x86_wcf-system.identitymodel_b03f5f7f11d50a3a_6.0.6002.22380_none_0ebeb2ba5a6f811c\System.IdentityModel.dll
+ 2010-06-15 01:40 . 2010-04-12 12:20438272 c:\windows\winsxs\x86_wcf-system.identitymodel_b03f5f7f11d50a3a_6.0.6002.18239_none_25868b0040cd890c\System.IdentityModel.dll
+ 2010-06-15 01:39 . 2010-03-25 11:54436048 c:\windows\winsxs\x86_netfx-web_engine_dll_b03f5f7f11d50a3a_6.0.6002.22372_none_1fb465ed51de1b9c\webengine.dll
+ 2010-06-15 01:39 . 2010-03-25 11:53435024 c:\windows\winsxs\x86_netfx-web_engine_dll_b03f5f7f11d50a3a_6.0.6002.18232_none_367e0b85383a563a\webengine.dll
+ 2010-06-15 20:11 . 2009-09-04 06:59388920 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.22219_none_fcfe427e14d1391e\SOS.dll
+ 2010-06-15 20:11 . 2009-09-04 06:59388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.18107_none_13cb1683fb2a8c7f\SOS.dll
+ 2010-06-23 20:41 . 2009-11-08 14:55297808 c:\windows\winsxs\x86_netfx-mscoree_dll_31bf3856ad364e35_6.1.6001.18242_none_7d658e19f5139de5\mscoree.dll
+ 2010-06-15 20:11 . 2009-09-04 06:58989528 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.22219_none_142ffabd20dc5d09\mscordacwks.dll
+ 2010-06-15 20:11 . 2009-09-04 06:58989000 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.18107_none_2afccec30735b06a\mscordacwks.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01546816 c:\windows\winsxs\x86_microsoft.windows.h..ler.wpd-driverclass_31bf3856ad364e35_6.0.6002.18112_none_6a8bd86c653628e0\wpd_ci.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01134144 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledevicesqm_31bf3856ad364e35_7.0.6002.18112_none_46439f2b6f000426\sqmapi.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01160256 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceTypes.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01100864 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceClassExtension.dll
+ 2010-06-15 20:16 . 2009-10-01 01:02334848 c:\windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6002.18112_none_4cde706de936888c\PortableDeviceApi.dll
+ 2010-06-15 20:17 . 2009-09-25 02:07189440 c:\windows\winsxs\x86_microsoft-windows-windowscodecext_31bf3856ad364e35_7.0.6002.18107_none_86efc43840ac1e52\WindowsCodecsExt.dll
+ 2010-06-15 20:17 . 2009-09-25 02:10974848 c:\windows\winsxs\x86_microsoft-windows-windowscodec_31bf3856ad364e35_7.0.6002.18107_none_89dfaf462924c1eb\WindowsCodecs.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01196608 c:\windows\winsxs\x86_microsoft-windows-w..ewmdrmcompatibility_31bf3856ad364e35_6.0.6002.18112_none_aeefe03423bfee4f\PortableDeviceWMDRM.dll
+ 2010-06-15 20:16 . 2009-10-01 01:01350208 c:\windows\winsxs\x86_microsoft-windows-w..cationcompatibility_31bf3856ad364e35_6.0.6002.18112_none_7007d7d4dbaec336\WPDSp.dll
+ 2010-06-23 20:43 . 2010-04-14 17:54293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22670_none_dc3b2eff7065f9a1\psisdecd.dll
+ 2010-06-23 20:43 . 2010-04-14 17:47293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18459_none_dbd032c0573008dd\psisdecd.dll
+ 2010-06-15 20:14 . 2009-10-08 21:08555520 c:\windows\winsxs\x86_microsoft-windows-uiautomationcore_31bf3856ad364e35_6.0.6002.18156_none_b1ceff3f3f65520f\UIAutomationCore.dll
+ 2010-06-23 20:43 . 2010-04-14 17:54428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22670_none_e0b60d45a7bcf5f6\EncDec.dll
+ 2010-06-23 20:43 . 2010-04-14 17:46428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18459_none_e04b11068e870532\EncDec.dll
+ 2010-06-15 20:17 . 2009-09-25 01:48351232 c:\windows\winsxs\x86_microsoft-windows-printing-xpsprint_31bf3856ad364e35_7.0.6002.18107_none_9f011af59951f340\XpsPrint.dll
+ 2010-06-15 20:17 . 2009-09-25 02:04321024 c:\windows\winsxs\x86_microsoft-windows-photometadatahandler_31bf3856ad364e35_7.0.6002.18107_none_bdcd592c6d8ad7f7\PhotoMetadataHandler.dll
+ 2010-06-15 20:18 . 2009-09-25 01:33369664 c:\windows\winsxs\x86_microsoft-windows-photo-image-codec_31bf3856ad364e35_7.0.6002.18107_none_9297a600cdc57a69\WMPhoto.dll
+ 2010-06-15 20:18 . 2009-09-24 22:55258048 c:\windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6002.22197_none_9543bd3e2f3469c3\winspool.drv
+ 2010-06-15 20:18 . 2009-09-24 22:54258048 c:\windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6002.18088_none_94c5f0a9160dc75f\winspool.drv
+ 2010-06-15 20:17 . 2009-09-24 22:55667648 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.22164_none_2de0cf8ef1d7d6cc\printfilterpipelinesvc.exe
+ 2010-06-15 20:17 . 2009-09-24 22:54667648 c:\windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6002.18060_none_2d53319bd8bdd1a6\printfilterpipelinesvc.exe
+ 2010-06-15 20:14 . 2009-10-08 21:08234496 c:\windows\winsxs\x86_microsoft-windows-oleacc_31bf3856ad364e35_6.0.6002.18156_none_6c3b296e1fad2902\oleacc.dll
+ 2010-06-15 20:18 . 2009-09-25 01:27634880 c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_7.0.6002.18107_none_9f26906a6b93696c\dxgkrnl.sys
+ 2010-06-15 01:41 . 2010-05-04 06:30164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.23019_none_481337e6dd0a172b\ieui.dll
+ 2010-06-15 01:41 . 2010-05-04 05:55164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18928_none_477df4a9c3f543e0\ieui.dll
+ 2010-06-15 01:40 . 2010-05-04 06:30109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.23019_none_ff02e517e8e79415\iesysprep.dll
+ 2010-06-15 01:40 . 2010-05-04 05:55109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.18928_none_fe6da1dacfd2c0ca\iesysprep.dll
+ 2010-06-15 01:40 . 2010-05-04 04:59173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23019_none_a941806b8d645750\ie4uinit.exe
+ 2010-06-15 01:40 . 2010-05-04 04:30173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18928_none_a8ac3d2e744f8405\ie4uinit.exe
+ 2010-06-15 01:41 . 2010-05-04 06:31129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.23019_none_2b1475a0bb6f3e25\sqmapi.dll
+ 2010-06-15 01:41 . 2010-05-04 05:58129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18928_none_2a7f3263a25a6ada\sqmapi.dll
+ 2010-06-15 01:41 . 2010-05-04 06:31206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.23019_none_1a973373430e2393\occache.dll
+ 2010-06-15 01:41 . 2010-05-04 05:58206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.18928_none_1a01f03629f95048\occache.dll
+ 2010-06-15 01:41 . 2010-05-04 06:32638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
+ 2010-06-15 01:40 . 2010-05-04 04:59133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\ieUnatt.exe
+ 2010-06-15 01:41 . 2010-05-04 06:00638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
+ 2010-06-15 01:40 . 2010-05-04 04:31133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\ieUnatt.exe
+ 2010-06-15 01:41 . 2010-05-04 06:30197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.23019_none_2afdfb3cc92410b5\IEShims.dll
+ 2010-06-15 01:41 . 2010-05-04 05:55197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18928_none_2a68b7ffb00f3d6a\IEShims.dll
+ 2010-06-15 01:41 . 2010-05-04 06:30247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.23019_none_739fafa6797baa47\ieproxy.dll
+ 2010-06-15 01:41 . 2010-05-04 05:55247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18928_none_730a6c696066d6fc\ieproxy.dll
+ 2010-06-15 01:41 . 2010-05-04 06:30599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.23019_none_4357559369617280\msfeeds.dll
+ 2010-06-15 01:41 . 2010-05-04 05:56599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.18928_none_42c21256504c9f35\msfeeds.dll
+ 2010-06-15 01:41 . 2010-05-04 06:30743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.23019_none_1f15d8176ec16c09\iedvtool.dll
+ 2010-06-15 01:41 . 2010-05-04 05:55743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.18928_none_1e8094da55ac98be\iedvtool.dll
+ 2010-06-15 01:40 . 2010-05-04 06:30184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.23019_none_20344ff620f8e82a\iepeers.dll
+ 2010-06-15 01:40 . 2010-05-04 05:55184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.18928_none_1f9f0cb907e414df\iepeers.dll
+ 2010-06-15 01:41 . 2010-05-04 06:30387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.23019_none_57c137c08668408f\iedkcs32.dll
+ 2010-06-15 01:41 . 2010-05-04 05:55387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18928_none_572bf4836d536d44\iedkcs32.dll
+ 2010-06-15 01:41 . 2010-05-04 06:31919040 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23019_none_e559bec4d0be1fc8\wininet.dll
+ 2010-06-15 01:41 . 2010-05-04 05:59916480 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18928_none_e4c47b87b7a94c7d\wininet.dll
+ 2010-06-15 01:41 . 2010-05-04 06:30611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.23019_none_c43671ebab5db8a4\mstime.dll
+ 2010-06-15 01:41 . 2010-05-04 05:56611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.18928_none_c3a12eae9248e559\mstime.dll
+ 2010-06-15 01:41 . 2010-05-26 14:54289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22412_none_ac3a633770d08fc3\atmfd.dll
+ 2010-06-15 01:41 . 2010-05-26 14:47289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\atmfd.dll
+ 2010-06-15 01:41 . 2010-05-26 14:35289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22700_none_aa5cc0a773a3ec00\atmfd.dll
+ 2010-06-15 01:41 . 2010-05-26 14:25289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\atmfd.dll
+ 2010-06-23 20:43 . 2010-04-14 16:27253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22670_none_4ba6b5206e120937\ehvid.exe
+ 2010-06-23 20:43 . 2010-04-14 16:15253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18459_none_4b3bb8e154dc1873\ehvid.exe
+ 2010-06-23 20:43 . 2010-04-14 17:52522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22670_none_cf021320e2be175a\ehui.dll
+ 2010-06-23 20:43 . 2010-04-14 17:45522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18459_none_ce9716e1c9882696\ehui.dll
+ 2010-06-23 20:43 . 2010-04-14 17:52105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22670_none_27068e6d7b50798e\ehPresenter.dll
+ 2010-06-23 20:43 . 2010-04-14 17:45105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18459_none_269b922e621a88ca\ehPresenter.dll
+ 2010-06-23 20:43 . 2010-04-14 19:00278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22382_none_2fd4fb80cf8bbccc\ehPlayer.dll
+ 2010-06-23 20:43 . 2010-04-14 18:23278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18242_none_2f769e65b64dad3e\ehPlayer.dll
+ 2010-06-23 20:43 . 2010-04-14 17:52278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22670_none_2df758f0d25f1909\ehPlayer.dll
+ 2010-06-23 20:43 . 2010-04-14 17:45278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18459_none_2d8c5cb1b9292845\ehPlayer.dll
+ 2010-06-23 20:43 . 2010-04-14 17:52373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22670_none_2f79d14e8378639a\ehglid.dll
+ 2010-06-23 20:43 . 2010-04-14 17:45373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18459_none_2f0ed50f6a4272d6\ehglid.dll
+ 2010-06-23 20:43 . 2010-04-14 17:20173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.exe
+ 2010-06-23 20:43 . 2010-04-14 17:11173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18459_none_33fce2ffda1a968b\McrMgr.exe
+ 2010-06-23 20:43 . 2010-04-14 17:52254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22670_none_14f56ee8b90922f1\ehReplay.dll
+ 2010-06-23 20:43 . 2010-04-14 17:45254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18459_none_148a72a99fd3322d\ehReplay.dll
+ 2010-06-23 20:43 . 2010-04-14 19:03180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6002.22382_none_d03f3d66e04a56b8\cbva.dll
+ 2010-06-23 20:43 . 2010-04-14 18:25180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6002.18242_none_cfe0e04bc70c472a\cbva.dll
+ 2010-06-23 20:43 . 2010-04-14 17:54180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22670_none_ce619ad6e31db2f5\cbva.dll
+ 2010-06-23 20:43 . 2010-04-14 17:46180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18459_none_cdf69e97c9e7c231\cbva.dll
+ 2010-06-15 20:17 . 2009-09-25 01:33829440 c:\windows\winsxs\x86_microsoft-windows-directx-warp10_31bf3856ad364e35_7.0.6002.18107_none_ddc19bafdeb30271\d3d10warp.dll
+ 2010-06-15 20:17 . 2009-09-25 01:30481792 c:\windows\winsxs\x86_microsoft-windows-directx-dxgi_31bf3856ad364e35_7.0.6002.18107_none_2ddc701ea6935db8\dxgi.dll
+ 2010-06-15 20:17 . 2009-09-25 01:31519680 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d11_31bf3856ad364e35_7.0.6002.18107_none_e31646a255b2bb52\d3d11.dll
+ 2010-06-15 20:17 . 2009-09-25 01:30190464 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10_31bf3856ad364e35_7.0.6002.18107_none_e3165d6a55b2a1b1\d3d10core.dll
+ 2010-06-15 20:17 . 2009-09-25 01:31218112 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10.1_31bf3856ad364e35_7.0.6002.18107_none_438775313198baea\d3d10_1core.dll
+ 2010-06-15 20:17 . 2009-09-25 01:31161280 c:\windows\winsxs\x86_microsoft-windows-directx-direct3d10.1_31bf3856ad364e35_7.0.6002.18107_none_438775313198baea\d3d10_1.dll
+ 2010-06-15 20:17 . 2009-09-25 01:31486912 c:\windows\winsxs\x86_microsoft-windows-directx-d3d10level9_31bf3856ad364e35_7.0.6002.18107_none_d6bc647e27993a91\d3d10level9.dll
+ 2010-06-15 20:17 . 2009-09-25 01:27793088 c:\windows\winsxs\x86_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_7.0.6002.18107_none_f80806179955d90c\FntCache.dll
+ 2010-06-15 20:17 . 2009-09-25 01:31828928 c:\windows\winsxs\x86_microsoft-windows-d2d_31bf3856ad364e35_7.0.6002.18107_none_9afade8fe3f79d22\d2d1.dll
+ 2010-06-15 20:17 . 2009-09-25 01:33195584 c:\windows\winsxs\x86_microsoft-windows-d..x-directxdiagnostic_31bf3856ad364e35_7.0.6002.18107_none_17218ffde5ca9cc0\dxdiagn.dll
+ 2010-06-15 20:17 . 2009-09-25 01:32252928 c:\windows\winsxs\x86_microsoft-windows-d..x-directxdiagnostic_31bf3856ad364e35_7.0.6002.18107_none_17218ffde5ca9cc0\dxdiag.exe
+ 2010-06-15 20:17 . 2009-09-25 01:38847360 c:\windows\winsxs\x86_microsoft-windows-component-opcom_31bf3856ad364e35_7.0.6002.18107_none_9694f99f3a97a698\OpcServices.dll
+ 2010-06-15 20:17 . 2009-09-25 01:35135680 c:\windows\winsxs\x86_microsoft-windows-c..nt-xpsrasterservice_31bf3856ad364e35_7.0.6002.18107_none_0dfb54ccb407a2d9\XpsRasterService.dll
+ 2010-06-15 20:17 . 2009-09-25 01:36280064 c:\windows\winsxs\x86_microsoft-windows-c..ent-xpsgdiconverter_31bf3856ad364e35_7.0.6002.18107_none_064a6d5573576b79\XpsGdiConverter.dll
+ 2010-06-15 01:40 . 2010-01-06 16:01173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22303_none_0e995261088a03df\AcXtrnal.dll
+ 2010-06-15 01:40 . 2010-01-06 16:01542720 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22303_none_0e995261088a03df\AcLayers.dll
+ 2010-06-15 01:40 . 2010-01-06 15:38173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18179_none_0dca05f7ef9fc28f\AcXtrnal.dll
+ 2010-06-15 01:40 . 2010-01-06 15:38542720 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18179_none_0dca05f7ef9fc28f\AcLayers.dll
+ 2010-06-22 20:03 . 2010-04-16 16:08173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22672_none_0c6630bb0b9d58fb\AcXtrnal.dll
+ 2010-06-22 20:03 . 2010-04-16 16:08541696 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22672_none_0c6630bb0b9d58fb\AcLayers.dll
+ 2010-06-22 20:03 . 2010-04-16 16:05173056 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18461_none_0be661abf27886c2\AcXtrnal.dll
+ 2010-06-22 20:03 . 2010-04-16 16:05541696 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18461_none_0be661abf27886c2\AcLayers.dll
+ 2010-06-15 01:40 . 2010-01-06 16:01458752 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.22303_none_0e985217088aea88\AcSpecfc.dll
+ 2010-06-15 01:40 . 2010-01-06 15:38458752 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.18179_none_0dc905adefa0a938\AcSpecfc.dll
+ 2010-06-22 20:03 . 2010-04-16 16:08459776 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.22672_none_0c6530710b9e3fa4\AcSpecfc.dll
+ 2010-06-22 20:03 . 2010-04-16 16:05459776 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.18461_none_0be56161f2796d6b\AcSpecfc.dll
+ 2010-06-15 01:41 . 2010-03-04 12:53258048 c:\windows\winsxs\msil_system.security_b03f5f7f11d50a3a_6.0.6002.22354_none_851a050be8358bb4\System.Security.dll
+ 2010-06-15 01:41 . 2010-03-04 12:53258048 c:\windows\winsxs\msil_system.security_b03f5f7f11d50a3a_6.0.6002.18222_none_9be4d87dce90ac67\System.Security.dll
+ 2010-06-15 01:40 . 2010-04-12 12:22970752 c:\windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41\System.Runtime.Serialization.dll
+ 2010-06-15 01:40 . 2010-04-12 12:21970752 c:\windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531\System.Runtime.Serialization.dll
+ 2010-06-15 01:40 . 2010-04-12 12:22970752 &nbsPlease try again.

The CFScript was spelled like this: c:\users\Dawn\Desktop\CFScript.txt.lnk\

Go to My Documents folder, click Tools > Folder Options.

Click the View tab.

Find "Hide extensions for known file types" and uncheck that.

Click Apply, then OK.

Then, for CFScript.txt

rename it to only say CFScript.txt


Then drag it in to ComboFix like I instructed earlier.
4412.

Solve : Some sort of malware happened, and now my computer can't connect to the internet?

Answer»

About a week and a half ago, I was downloading a toolbar and some malware[at least I'm farily certain it's a malware.] infected my desktop; which now cannot connect to the INTERNET. I'm writing this on my laptop.
Back to when the malware infected- I ran Malware-Bytes Anti Malware, then I ran Spybot S&D after to make sure. Even after running them my computer was still funky, and so I did a system restore. Right after that, my computer stopped being able to connect to the internet and the taskbar is that gray taskbar old computers used to have, and I cannot CHANGE it.

Just today I was trying to scan something with my scanner, I told my printer to scan from my computer, and it gave me a weird message saying "The specified type cannot be found in the image FILE." I'm not sure if that is related at all, but thought it might be. Oh, and my computer also won't hibernate. I'll click on the hibernate option, and it'll go to the bluish screen that says "Preparing to hibernate", but then it'll go back to the desktop like normal and won't hibernate. Please go to this link and follow the directions and post the required logs. Hello, your comment has been removed. Please do not post malware ADVICE, or post here in the malware forum, unless you NEED help. If you want to help, please go here. Superdave.

4413.

Solve : Recommendations for Internet Security Software Please?

Answer»

I'd like some RECOMMENDATIONS for the BEST internet security software, either free or not. My NORTON subscription is about to run out and I've had trouble renewing it. At this point, I'm ready to TRY a new supplier.

ThanksClose this post, PLEASE. I found the information I needed. Thanks

4414.

Solve : Rootkit, Winsock Error, Redirected Searches, Task Bar color change?

Answer»

Here is the RootRepeal Log.

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:2010/06/08 20:16
Program Version:Version 1.3.5.0
Windows Version:Windows XP SP3
==================================================

Drivers
-------------------
Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xF75A8000Size: 187776File Visible: -Signed: Yes
Status: -

Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000Size: 2260992File Visible: -Signed: Yes
Status: -

Name: afd.sys
Image Path: C:\WINDOWS\System32\drivers\afd.sys
Address: 0xB6A40000Size: 138496File Visible: -Signed: Yes
Status: -

Name: ASACPI.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ASACPI.sys
Address: 0xF79C5000Size: 5152File Visible: -Signed: Yes
Status: -

Name: atapi.sys
Image Path: atapi.sys
Address: 0xF749A000Size: 96512File Visible: -Signed: Yes
Status: -

Name: ati2cqag.dll
Image Path: C:\WINDOWS\System32\ati2cqag.dll
Address: 0xBF065000Size: 626688File Visible: -Signed: Yes
Status: -

Name: ati2dvag.dll
Image Path: C:\WINDOWS\System32\ati2dvag.dll
Address: 0xBF012000Size: 339968File Visible: -Signed: Yes
Status: -

Name: ati2mtag.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Address: 0xB8F4B000Size: 3891200File Visible: -Signed: Yes
Status: -

Name: ati3duag.dll
Image Path: C:\WINDOWS\System32\ati3duag.dll
Address: 0xBF1CD000Size: 3821568File Visible: -Signed: Yes
Status: -

Name: atikvmag.dll
Image Path: C:\WINDOWS\System32\atikvmag.dll
Address: 0xBF0FE000Size: 540672File Visible: -Signed: Yes
Status: -

Name: atiok3x2.dll
Image Path: C:\WINDOWS\System32\atiok3x2.dll
Address: 0xBF182000Size: 307200File Visible: -Signed: Yes
Status: -

Name: ativvaxx.dll
Image Path: C:\WINDOWS\System32\ativvaxx.dll
Address: 0xBF572000Size: 2670592File Visible: -Signed: Yes
Status: -

Name: ATMFD.DLL
Image Path: C:\WINDOWS\System32\ATMFD.DLL
Address: 0xBFFA0000Size: 286720File Visible: -Signed: Yes
Status: -

Name: audstub.sys
Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys
Address: 0xF7A68000Size: 3072File Visible: -Signed: Yes
Status: -

Name: Beep.SYS
Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xF79D7000Size: 4224File Visible: -Signed: Yes
Status: -

Name: BOOTVID.dll
Image Path: C:\WINDOWS\system32\BOOTVID.dll
Address: 0xF7897000Size: 12288File Visible: -Signed: Yes
Status: -

Name: Cdfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xF7517000Size: 63744File Visible: -Signed: Yes
Status: -

Name: cdrom.sys
Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Address: 0xF76A7000Size: 62976File Visible: -Signed: Yes
Status: -

Name: CLASSPNP.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Address: 0xF7637000Size: 53248File Visible: -Signed: Yes
Status: -

Name: cmdguard.sys
Image Path: C:\WINDOWS\System32\DRIVERS\cmdguard.sys
Address: 0xB6B64000Size: 222208File Visible: -Signed: Yes
Status: -

Name: cmdhlp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\cmdhlp.sys
Address: 0xF777F000Size: 18304File Visible: -Signed: Yes
Status: -

Name: disk.sys
Image Path: disk.sys
Address: 0xF7627000Size: 36352File Visible: -Signed: Yes
Status: -

Name: dmio.sys
Image Path: dmio.sys
Address: 0xF74B2000Size: 153344File Visible: -Signed: Yes
Status: -

Name: dmload.sys
Image Path: dmload.sys
Address: 0xF798D000Size: 5888File Visible: -Signed: Yes
Status: -

Name: drmk.sys
Image Path: C:\WINDOWS\system32\drivers\drmk.sys
Address: 0xF7507000Size: 61440File Visible: -Signed: Yes
Status: -

Name: Dxapi.sys
Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xB6BAF000Size: 12288File Visible: -Signed: Yes
Status: -

Name: dxg.sys
Image Path: C:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000Size: 73728File Visible: -Signed: Yes
Status: -

Name: dxgthk.sys
Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xB651D000Size: 4096File Visible: -Signed: Yes
Status: -

Name: fdc.sys
Image Path: C:\WINDOWS\system32\DRIVERS\fdc.sys
Address: 0xF77F7000Size: 27392File Visible: -Signed: Yes
Status: -

Name: Fips.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xBA750000Size: 44544File Visible: -Signed: Yes
Status: -

Name: flpydisk.sys
Image Path: C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Address: 0xF7757000Size: 20480File Visible: -Signed: Yes
Status: -

Name: fltmgr.sys
Image Path: fltmgr.sys
Address: 0xF747A000Size: 129792File Visible: -Signed: Yes
Status: -

Name: Fs_Rec.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF79D5000Size: 7936File Visible: -Signed: Yes
Status: -

Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xF74D8000Size: 125056File Visible: -Signed: Yes
Status: -

Name: hal.dll
Image Path: C:\WINDOWS\system32\hal.dll
Address: 0x806FF000Size: 134400File Visible: -Signed: Yes
Status: -

Name: HDAudBus.sys
Image Path: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Address: 0xB8F0F000Size: 163840File Visible: -Signed: Yes
Status: -

Name: HdAudio.sys
Image Path: C:\WINDOWS\system32\drivers\HdAudio.sys
Address: 0xB6CE2000Size: 131072File Visible: -Signed: Yes
Status: -

Name: HIDCLASS.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Address: 0xBA710000Size: 36864File Visible: -Signed: Yes
Status: -

Name: HIDPARSE.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Address: 0xB9341000Size: 28672File Visible: -Signed: Yes
Status: -

Name: hidusb.sys
Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Address: 0xB8E0D000Size: 10368File Visible: -Signed: Yes
Status: -

Name: HTTP.sys
Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xB2D37000Size: 265728File Visible: -Signed: Yes
Status: -

Name: i8042prt.sys
Image Path: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Address: 0xB9D73000Size: 52480File Visible: -Signed: Yes
Status: -

Name: imapi.sys
Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys
Address: 0xF7697000Size: 42112File Visible: -Signed: Yes
Status: -

Name: inspect.sys
Image Path: inspect.sys
Address: 0xF743D000Size: 80512File Visible: -Signed: Yes
Status: -

Name: intelide.sys
Image Path: intelide.sys
Address: 0xF798B000Size: 5504File Visible: -Signed: Yes
Status: -

Name: intelppm.sys
Image Path: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Address: 0xB9D83000Size: 36352File Visible: -Signed: Yes
Status: -

Name: ipnat.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Address: 0xB6AB2000Size: 152832File Visible: -Signed: Yes
Status: -

Name: ipsec.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Address: 0xB6B31000Size: 75264File Visible: -Signed: Yes
Status: -

Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xF75F7000Size: 37248File Visible: -Signed: Yes
Status: -

Name: kbdclass.sys
Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Address: 0xF77FF000Size: 24576File Visible: -Signed: Yes
Status: -

Name: KDCOM.DLL
Image Path: C:\WINDOWS\system32\KDCOM.DLL
Address: 0xF7987000Size: 8192File Visible: -Signed: Yes
Status: -

Name: kmixer.sys
Image Path: C:\WINDOWS\system32\drivers\kmixer.sys
Address: 0xB280B000Size: 172416File Visible: -Signed: Yes
Status: -

Name: ks.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys
Address: 0xB8E7D000Size: 143360File Visible: -Signed: Yes
Status: -

Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xF7451000Size: 92928File Visible: -Signed: Yes
Status: -

Name: lknuhst.sys
Image Path: C:\WINDOWS\system32\DRIVERS\lknuhst.sys
Address: 0xBA6F6000Size: 12032File Visible: -Signed: No
Status: -

Name: lknuhub.sys
Image Path: C:\WINDOWS\system32\DRIVERS\lknuhub.sys
Address: 0xF7547000Size: 39424File Visible: -Signed: No
Status: -

Name: mfehidk.sys
Image Path: C:\WINDOWS\system32\drivers\mfehidk.sys
Address: 0xB2EF1000Size: 164672File Visible: -Signed: Yes
Status: -

Name: mferkdk.sys
Image Path: C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys
Address: 0xF7787000Size: 25088File Visible: -Signed: Yes
Status: -

Name: mfetdik.sys
Image Path: C:\WINDOWS\system32\drivers\mfetdik.sys
Address: 0xBA780000Size: 45376File Visible: -Signed: Yes
Status: -

Name: mnmdd.SYS
Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xF79D9000Size: 4224File Visible: -Signed: Yes
Status: -

Name: mouclass.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Address: 0xF7817000Size: 23040File Visible: -Signed: Yes
Status: -

Name: mouhid.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Address: 0xB8E09000Size: 12160File Visible: -Signed: Yes
Status: -

Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xF7607000Size: 42368File Visible: -Signed: Yes
Status: -

Name: mrxsmb.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Address: 0xB69A5000Size: 455680File Visible: -Signed: Yes
Status: -

Name: Msfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xF776F000Size: 19072File Visible: -Signed: Yes
Status: -

Name: msgpc.sys
Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Address: 0xF76F7000Size: 35072File Visible: -Signed: Yes
Status: -

Name: mssmbios.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Address: 0xBA6FA000Size: 15488File Visible: -Signed: Yes
Status: -

Name: Mup.sys
Image Path: Mup.sys
Address: 0xF787D000Size: 105344File Visible: -Signed: Yes
Status: -

Name: NDIS.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\NDIS.SYS
Address: 0xF7410000Size: 182656File Visible: -Signed: Yes
Status: -

Name: ndistapi.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Address: 0xBA7C0000Size: 10112File Visible: -Signed: Yes
Status: -

Name: ndisuio.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Address: 0xB40DC000Size: 14592File Visible: -Signed: Yes
Status: -

Name: ndiswan.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Address: 0xB8E66000Size: 91520File Visible: -Signed: Yes
Status: -

Name: NDProxy.SYS
Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xF7557000Size: 40576File Visible: -Signed: Yes
Status: -

Name: netbios.sys
Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys
Address: 0xBA760000Size: 34688File Visible: -Signed: Yes
Status: -

Name: netbt.sys
Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys
Address: 0xB6A62000Size: 162816File Visible: -Signed: Yes
Status: -

Name: Npfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xF7777000Size: 30848File Visible: -Signed: Yes
Status: -

Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xF7B52000Size: 574976File Visible: -Signed: Yes
Status: -

Name: ntoskrnl.exe
Image Path: C:\WINDOWS\system32\ntoskrnl.exe
Address: 0x804D7000Size: 2260992File Visible: -Signed: Yes
Status: -

Name: Null.SYS
Image Path: C:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xF7AAE000Size: 2944File Visible: -Signed: Yes
Status: -

Name: parport.sys
Image Path: C:\WINDOWS\system32\DRIVERS\parport.sys
Address: 0xB8EA0000Size: 80128File Visible: -Signed: Yes
Status: -

Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xF770F000Size: 19712File Visible: -Signed: Yes
Status: -

Name: ParVdm.SYS
Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xF79B9000Size: 6784File Visible: -Signed: Yes
Status: -

Name: pci.sys
Image Path: pci.sys
Address: 0xF7597000Size: 68224File Visible: -Signed: Yes
Status: -

Name: pciide.sys
Image Path: pciide.sys
Address: 0xF7A4F000Size: 3328File Visible: -Signed: Yes
Status: -

Name: PCIIDEX.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Address: 0xF7707000Size: 28672File Visible: -Signed: Yes
Status: -

Name: pnarp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\pnarp.sys
Address: 0xB66E3000Size: 18560File Visible: -Signed: Yes
Status: -

Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000Size: 2260992File Visible: -Signed: Yes
Status: -

Name: portcls.sys
Image Path: C:\WINDOWS\system32\drivers\portcls.sys
Address: 0xB6CBE000Size: 147456File Visible: -Signed: Yes
Status: -

Name: psched.sys
Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys
Address: 0xB8E55000Size: 69120File Visible: -Signed: Yes
Status: -

Name: ptilink.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Address: 0xF7807000Size: 17792File Visible: -Signed: Yes
Status: -

Name: purendis.sys
Image Path: C:\WINDOWS\system32\DRIVERS\purendis.sys
Address: 0xB66DB000Size: 19840File Visible: -Signed: Yes
Status: -

Name: rasacd.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Address: 0xBA7E4000Size: 8832File Visible: -Signed: Yes
Status: -

Name: rasl2tp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Address: 0xF76C7000Size: 51328File Visible: -Signed: Yes
Status: -

Name: raspppoe.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Address: 0xF76D7000Size: 41472File Visible: -Signed: Yes
Status: -

Name: raspptp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Address: 0xF76E7000Size: 48384File Visible: -Signed: Yes
Status: -

Name: raspti.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys
Address: 0xF780F000Size: 16512File Visible: -Signed: Yes
Status: -

Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000Size: 2260992File Visible: -Signed: Yes
Status: -

Name: rdbss.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Address: 0xB6A15000Size: 175744File Visible: -Signed: Yes
Status: -

Name: RDPCDD.sys
Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xF79DB000Size: 4224File Visible: -Signed: Yes
Status: -

Name: rdpdr.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Address: 0xB8E25000Size: 196224File Visible: -Signed: Yes
Status: -

Name: redbook.sys
Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys
Address: 0xF76B7000Size: 57600File Visible: -Signed: Yes
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB3622000Size: 49152File Visible: NoSigned: No
Status: -

Name: serenum.sys
Image Path: C:\WINDOWS\system32\DRIVERS\serenum.sys
Address: 0xBA7C8000Size: 15744File Visible: -Signed: Yes
Status: -

Name: serial.sys
Image Path: C:\WINDOWS\system32\DRIVERS\serial.sys
Address: 0xB9D63000Size: 64512File Visible: -Signed: Yes
Status: -

Name: sr.sys
Image Path: sr.sys
Address: 0xF7468000Size: 73472File Visible: -Signed: Yes
Status: -

Name: srv.sys
Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys
Address: 0xB369A000Size: 353792File Visible: -Signed: Yes
Status: -

Name: STREAM.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\STREAM.SYS
Address: 0xBA740000Size: 53248File Visible: -Signed: Yes
Status: -

Name: swenum.sys
Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys
Address: 0xF79C7000Size: 4352File Visible: -Signed: Yes
Status: -

Name: sysaudio.sys
Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xB3FD8000Size: 60800File Visible: -Signed: Yes
Status: -

Name: tcpip.sys
Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Address: 0xB6AD8000Size: 361600File Visible: -Signed: Yes
Status: -

Name: TDI.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Address: 0xF7717000Size: 20480File Visible: -Signed: Yes
Status: -

Name: termdd.sys
Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys
Address: 0xF7587000Size: 40704File Visible: -Signed: Yes
Status: -

Name: update.sys
Image Path: C:\WINDOWS\system32\DRIVERS\update.sys
Address: 0xB8D9F000Size: 384768File Visible: -Signed: Yes
Status: -

Name: usbaudio.sys
Image Path: C:\WINDOWS\system32\drivers\usbaudio.sys
Address: 0xBA730000Size: 60032File Visible: -Signed: Yes
Status: -

Name: usbccgp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Address: 0xF778F000Size: 32128File Visible: -Signed: Yes
Status: -

Name: USBD.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Address: 0xF79D1000Size: 8192File Visible: -Signed: Yes
Status: -

Name: usbehci.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Address: 0xF77EF000Size: 30208File Visible: -Signed: Yes
Status: -

Name: usbhub.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Address: 0xBA7A0000Size: 59520File Visible: -Signed: Yes
Status: -

Name: USBPORT.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Address: 0xB8EB4000Size: 147456File Visible: -Signed: Yes
Status: -

Name: usbuhci.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Address: 0xF77E7000Size: 20608File Visible: -Signed: Yes
Status: -

Name: vga.sys
Image Path: C:\WINDOWS\System32\drivers\vga.sys
Address: 0xF7767000Size: 20992File Visible: -Signed: Yes
Status: -

Name: VIDEOPRT.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Address: 0xB8F37000Size: 81920File Visible: -Signed: Yes
Status: -

Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xF7617000Size: 52352File Visible: -Signed: Yes
Status: -

Name: VX6000Xp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys
Address: 0xB6798000Size: 2068480File Visible: -Signed: Yes
Status: -

Name: VX6KCamd.sys
Image Path: C:\WINDOWS\system32\DRIVERS\VX6KCamd.sys
Address: 0xB9349000Size: 28672File Visible: -Signed: Yes
Status: -

Name: wanarp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Address: 0xBA770000Size: 34560File Visible: -Signed: Yes
Status: -

Name: watchdog.sys
Image Path: C:\WINDOWS\System32\watchdog.sys
Address: 0xF7797000Size: 20480File Visible: -Signed: Yes
Status: -

Name: wdmaud.sys
Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xB3E4B000Size: 83072File Visible: -Signed: Yes
Status: -

Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000Size: 1851392File Visible: -Signed: Yes
Status: -

Name: win32k.sys
Image Path: C:\WINDOWS\System32\win32k.sys
Address: 0xBF800000Size: 1851392File Visible: -Signed: Yes
Status: -

Name: WMILIB.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS
Address: 0xF7989000Size: 8192File Visible: -Signed: Yes
Status: -

Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000Size: 2260992File Visible: -Signed: Yes
Status: -



[recovering disk space - old attachment deleted by admin]How is your computer running now? Any more redirects?No more redirects. Everything seems to be running fine. My gf said she had some pop ups yesterday. I wasn't home but it wasn't the fake security alerts. I have been able to update XP so overall I think I am in good shape.

I wonder about IO Bit Advanced System Care and if it really helps or not and about switching McAfee for one of the anti virus products recommended here.

I really appreciate your help and input, thanks.Well, that sound good. Let's run one more scan and if that comes up clean, we'll do some clean-up. I'll have some more suggestions about how to keep your computer safe in the clean-up speech.

I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Wow, 33 items found, was this expected?

[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=a0d5c9e1b047ac48af0108484ba6a6e9
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-06-10 05:13:14
# local_time=2010-06-09 10:13:14 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 4507239 4507239 0 0
# compatibility_mode=3073 16777213 80 92 0 11094560 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=77165
# found=33
# cleaned=33
# scan_time=8895
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ubxo.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\gyqig.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\Jon\Application Data\Kuyzwe\omzun.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\Jon\Application Data\Sun\Java\Deployment\cache\6.0\46\2ef6a5ae-29c19df4a variant of Java/TrojanDownloader.Agent.NBE trojan (deleted - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\43120580-4af80629a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\30feb821-6a642e70a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\5473416c-2e86c9caa variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\63\43e0867f-1c23f9a1probably a variant of Win32/Agent trojan (deleted - quarantined)00000000000000000000000000000000C
C:\Program Files\Unlocker\eBay_shortcuts_1016.exea variant of Win32/Adware.ADON application (deleted - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mirepcmw.dll.vira variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\imapi.sys.virWin32/Olmarik.ZC trojan (cleaned - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP36\A0018169.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022896.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022906.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026253.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026255.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026256.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029852.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029853.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029883.dlla variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030305.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030306.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032444.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032446.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032447.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035015.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035016.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036642.sysWin32/Olmarik.ZC trojan (cleaned - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036698.dlla variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039289.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039290.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039291.exea variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039292.exea variant of Win32/Adware.ADON application (deleted - quarantined)00000000000000000000000000000000C


[recovering disk space - old attachment deleted by admin]The most of these are duplicates and most were in System RESTORE.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above PROCEDURE will:
* Delete the following:
* ComboFix and its associated files and folders.
* RESET the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

==============================

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

If there are any tools/programs left, install them or delete them.
==============================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

=================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - SEARCH & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!I have been away for a couple days. Just finished your LAST suggestions. Thank you so much. The computer is running really well and I am very happy with the results. You turned a source of frustration and anger into a workable and enjoyable experience. I learned as I went and really appreciate your help.
4415.

Solve : topic locked?

Answer»

what/s it mean when a "topic is locked" i asked aquestion about au.exe but got a reply that it/s been locked by "super dave " who/s super daveYou should post a question once only. Second or third threads ASKING the same question will get locked.
i did ask the question only once still has/nt been answered may-be no one knowsmaybe the topic was agains the forum RULES ? The post is clearly marked as double posted.i asked in spyware &VIRUS forum what is "au.exe" can/t see any probs with that questionYou should not post the same question more than once.o.k. i/m sorry it/ll never happen again i asked it months AGO & FORGOT, thought it might have got lost in the internet universeNo harm done. If you post a question that isn't answered after a period of time, you can always "bump" it. o.k. how do i bump my question about au.exe might get answer if i bump it!Just make a new reply with the word "bump" in the reply.

4416.

Solve : Can't remove rogue malware?

Answer»

Please delete this one: ALCMTR.EXE C\WINDOWS It is spyware installed with Realtek AC97 Audio.OK..IHOPE I removed everything properly from HIJACK THIS step. Not all of them were on the scan all but I think I deleted all of he ones tht matches your list. Here is the new log, just in case:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:00 AM, on 6/3/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Protector Suite QL\menusw.exe
D:\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [Biomenu] "C:\Program Files\Protector Suite QL\menusw.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {E2739AFF-FA40-4527-9A19-DE81795C2C03} (MSN Money Ticker) - http://moneycentral.msn.com/cabs/ticker.cab
O20 - Winlogon NOTIFY: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 10024 bytes
Results from SecurityCheck

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
SonicStage Mastering Studio Audio Filter Custom Preset
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java(TM) 6 Update 11
Out of date Java installed!
Adobe Flash Player 10.0.12.36
Adobe Reader 7.0
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Alwil Software Avast5 AvastSvc.exe
ALWILS~1 Avast5 avastUI.exe
````````````````````````````````
DNS Vulnerability Check:

Unknown. This method cannot test your vulnerability to DNS cache poisoning.

``````````End of Log````````````
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to CLOSE ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.
4. Run CCleaner.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To DISABLE the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

=============================

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

============================

After you do these, please download and run ComboFix.OK..updated my Java.

Where can I get CCleaner to run it?
Thanks again SuperDave!
Download CCleaner Slim and save it to your Desktop - Alternate download link

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

* Double-click the CCleaner shortcut on the desktop to start the program.
* Click on the Options block on the left, then choose Cookies.
* Under Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow > to move them to the Cookies to Keep window.
* Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
* Click Cleaner on the left then Run Cleaner on the right to run the program.
* Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes.[/I] Exit CCleaner after it has completed it's process.

OK...I've DONE it all!! Am I clean now? Can we declare victory?

SuperDave, you are my hero!!
I hope you wear a cape (I mean a girl REALLY likes a hero that wears a cape!)
Seriously..thank you so much.
Desperate Girl Yes, I would say that your computer is clean as all our scans can make it. I used to wear a cape but I discarded it when everyone was staring at me. Good luck.Deleted.Ignore the post from Kristain and just stay with SuperDave* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

=============================

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

==============================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

=============================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

4417.

Solve : W32.Silly FDC.. what to do? plz?

Answer»

Hi great CH members.

I am in need for your geneoristy. After a full scan of my pc, i found this virus W32.Silly FDC (Two of it). Norton states that its risk level is high and it can't be removed so it suggests a reveiw of the virus. That's all. Plz help me how to get rid of it without losing any of my files.

BTW, i ve Windows Vista which is protected by Norton and i run a regular update for the Windows and the Norton. I believed that this is all i need to do to protect my pc. I seem to be mistaken after all

I'd highly appreciate it. Thanks in advance Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner OPTIONS make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.Are procedures followed for desktop pc the same as for laptop? coz this problem is in my laptop!!Same thing.This's Superantispyware log.....

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/19/2008 at 11:58 AM

Application Version : 4.15.1000

Core Rules Database Version : 3485
Trace Rules Database Version: 1476

Scan type : Complete Scan
Total Scan Time : 00:44:07

Memory items scanned : 221
Memory threats detected : 0
Registry items scanned : 7064
Registry threats detected : 0
File items scanned : 87478
File threats detected : 18

Adware.Tracking Cookie
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt
C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected]lfusion[2].txt
.doubleclick.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
rotator.adjuggler.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
rotator.adjuggler.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.tribalfusion.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
www7.addfreestats.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.toplist.cz [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.adbrite.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.adbrite.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
*Blocked Russian URL* [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.fastclick.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.eb.adbureau.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.atdmt.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.pro-market.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.webstats4u.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
eas.apm.emediate.eu [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
eas.apm.emediate.eu [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.track.webgains.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.apmebf.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.clickaider.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.smileycentral.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.smileycentral.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.maxserving.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.ads.bridgetrack.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
.mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
Hi there,

While performing full scan by Malwarebytes' Anti-Malware, my computer has encountered an unexpected shutdown. After recovering from the shutdown, windows asked for checking solution online but I didn't coz i wanna ask you first if it's ok and what the problem is.

BTW while scanning, the internet was connected. Should I disconnect before scanning or what?

What shall I do now?

My Regards, Similar thing happened on ONE of my client's infected computer.
Try running scan one more time.
If it doesn't WORK, try Safe Mode.
If that doesn't work, post HJT log from Normal Mode.It works on the safe mode,

Here's the log...

Malwarebytes' Anti-Malware 1.17
Database version: 869

11:18:33 20/06/08 a.m
mbam-log-6-20-2008 (11-18-33).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 127199
Time elapsed: 18 minute(s), 18 second(s)

Memory PROCESSES Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 23
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Here's HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:53 a.m, on 20/06/08
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11512 bytes
Now what?

I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before. Quote

I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.
You'll have to elaborate little bit more on the above.

Meanwhile...

*** You need to update Java:
http://java.sun.com/javase/downloads/index.jsp
Java Runtime Environment (JRE) 6 Update 6
Uninstall all previous versions of Java through Add\Remove.

*** Disable Windows Defender, as it'll interfere with cleaning process:
* Open Windows Defender
* Click Tools
* Click General Settings
* Scroll down to Real Time Protection Options
* Uncheck Turn on Real Time Protection
* After you uncheck this, click on the Save button
* Close Windows Defender

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- *O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
- *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
- *O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
- *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
- *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- *O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
- O9 - Extra button: &#1573;&#1585;&#1587;&#1575;&#1604; &#1573;&#1604;&#1609; OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra 'Tools' menuitem: &#1573;&#1585;&&#1587;&#1575;&#1604; &#1573;&#1604;&#1609; OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

4. Click on Fix checked button.

5. Restart computer.

6. Post new HijackThis log.Hi Sir,


Concerning Java, which one to download (windows offline installion or windows online installion)? and which platform to choose (Windows , windows x64)

Shall I uninstall all previous versions of java after updating java?

Thanks for being tolerant with me. Normally, I install off-line. Select Windows (not 64), and, yes, uninstall all previous versions.Hi again,

After clicking on Fix checked button, a new window of HJT suddenly appears stating that an unexpected error has occured at procedure:
- O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

Error #5 Invalid procedure call or argument


Besides, after fixing finished, a window appears telling that HJT is not running correctly.

This is the new HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:18 ص, on 26/06/08
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11254 bytes
Quote from: Broni on JUNE 20, 2008, 06:38:39 PM
Quote
I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.
You'll have to elaborate little bit more on the above.

Ok ..

When opening the C driver, I'd see empty and transparent folders like: $Recycle.Bin , shortcut of Documents and Settings, System Volume Information...
Inside Program Data Folder on C again, you'd find shortcuts of Application Data, Desktop, Document, Favouarite, Start menue, Templates. Again they are all empty.
And i'd see files like: autoexec.bat, config.sys , IO.sys .... and the like.

Once opening Username Folder, I'd find files like: ntuser.dat.log1 , ntuser.dat.log2, ntuser.dat (BLF file), ntuser.dat (Regtrans-ns file), and ntuser.ini (config setting)

Once opening any folder containg a movie, I'd see $$Jet.THM$$.cache (cache file)

I'd find similar folders and files everywhere. Mostly they are shortcuts or empty folders. Once I tried deleting them, it's said that they contain a system file like desktop.ini and i cant remove them.

This is what makes me post here. My laptop was just brand clean but out of the blue these bugging folders are everywhere.


My Best Regards,
4418.

Solve : I have a worm?

Answer»

have to upload ONE more updateResults of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
AVG Free 9.0
ESET Online Scanner v3
Sunbelt Kerio Personal Firewall
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
HDCleaner
Java(TM) 6 Update 20
Java(TM) SE Runtime Environment 6 Update 1
Adobe Flash Player 10.0.45.2
Adobe READER 9.3
Mozilla Firefox (3.6.3)
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
Sunbelt Software Personal Firewall 4 kpf4ss.exe
Sunbelt Software Personal Firewall 4 kpf4gui.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````
That looks good. If there are no other issues, it's time for some clean-up.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type commy /uninstall in the runbox
* Make sure there's a space between commy and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

==============================

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

============================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run UNINTERRUPTED until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

============================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. GUIDE: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

4419.

Solve : Uninstalling AVG?

Answer»

Hi all, I really want to uninstall AVG 8.0.437 (FREE edition), but it wouldn't: everytime I lunch the program's uninstaller (or using the Windows Add/Remove PROGRAMS) it always tells me Uninstall failed, 1 error occured, and that is...
Local machine: installation failed
Installation:
Error: Action failed for file avgemc.exe: creating backup....
Error 0x80070002 %DESTINATION% = "C:\Program Files\AVG\AVG8\avgemc.exe.install_backup_1", %SOURCE% = "C:\Program Files\AVG\AVG8\avgemc.exe"
Please TELL me what to do! I use Windows XP Home Edition SP2, and I don't wanna start hating AVG: it's great, but let me have the choice. Thanks.Try Revo Uninstallerthanks Allan, that was fast! Revo lunches the program's built-in uninstaller then removes the UNNECESSARY values, so TECHNICALLY the problem is the same. Sorry, no use for Revo here.
http://forums.avg.com/us-en/avg-free-forum?sec=thread&act=show&id=89479

http://forums.avg.com/us-en/avg-free-forum?sec=thread&act=show&id=8043

Oh thanks again, Allan, it's http://forums.avg.com/ww-en/avg-free-forum?sec=thread&act=show&id=44013#post_44013
and now I can tell the truth: I'll never install it again!I'm not an advocate of free anti virus software, but if that's what you are going to use I'd suggest either Avast or Avira.

4420.

Solve : MP3, VIDEOS, MUSIC?

Answer»

Hi everyone, i really need your help, how can i get rid of this kind of virus: MP3, VIDEOS, MUSIC.
it just appear suddenly on my desktop. and every time i open a folder their will always, MP3, VIDEOS, MUSIC that will be created.

I have an Anvira Antivir Personal (Free) antivirus. When i RUN through using my antivirus, the virus is still there. Can I have another way on deleting this kind of virus?

Furthermore, I would like also to ask if this virus will also infect windows vista, and windows 7 platforms.

By the way, my OS is windows XP.

I would really appreciate your help! Thanks! Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the APPLICATION.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is COMPLETED, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.
4421.

Solve : Sas log, missing taskbar, start menu, no sound, can't copy, etc.. error 372, vba?

Answer» THANKS SUPERDAVE, i WENT AHEAD and reinstalled windows xp SP3. thanks
4422.

Solve : how do I find out what programs are trying to acces the internet through my comp?

Answer»

Quote

and can't WAIT to make it my default browser again, but do you think it is unsafe? I
I really can't say anything about Google Chrome. You should post this question on the software forum. I'm sure you will get MANY opinions there.

Quote
Also, just out of curiosity, what browser do you use?
I use IE 8 as my default but occasionally I use FireFox.

Quote
I would appreciate having an alternative (other than firefox and internet EXPLORER).
You could always try Opera.
4423.

Solve : VMWare image maybe infected?

Answer»

hello
is VIRUS over VMWare image can infect my PC ?
if you have exposed writable network shares a Trojan could spread through this. how can i clean virus/trojan from VMWare image? QUOTE from: k_mohsen on July 06, 2010, 01:29:16 PM

how can i clean virus/trojan from VMWare image?

Same as with ordinary installation - install and/or run antivirus program. if i install antivirus on VMWare Image, I have to UPDATE it.
what about sharing Drive,which OS installed, and scan it on my PC? from My Network Place?

Quote from: k_mohsen on July 07, 2010, 12:06:26 PM
if i install antivirus on VMWare Image, I have to update it.
Yes... and?


Quote
what about sharing Drive,which OS installed, and scan it on my PC? from My Network Place?
The moment you share the drive is the moment you expose your PC to the spread of any malware that is in the image file to the host machine. Besides, I can't think of any AV program that can scan a network path anyway.
I have Windows 7 64 bit (host OS) which has Avira Free antivirus. I run XP 32 bit (guest OS) in a VMWare virtual machine and it has its own Avira installed.
4424.

Solve : Possible Rootkit - need verification?

Answer»

A REINSTALL is the only true way to ever know everything is gone. With the changing results on each scan I would advise to go forward with it. Chalk it up to a learning experience. Nothing is truly free, a high percentage of cracks and such install EXTRA baggage unknowingly to users. Identity theft is not uncommon but they will steal anything they can INCLUDING all of your software keys.First of all I would like to thank you for all you help ! The replies were fast, accurate and easy to understand That's support.

But I have to add, that I didn't use that crack on this installed system, but on my old Windows Vista system. I'm actually proud to say I haven't used a single crack while USING this system.

Well then I'm off to make an nLite CD. Don't wanna go through all the crap of reinstalling all the software again.

Thanx again and cya next time No problem, Sorry we couldn't nail it down but I do think in this CASE a reinstall is the best advice we can give.

4425.

Solve : My computer really freaked out last night!?

Answer»

I booted up and logged on to the web, then I started getting Trojan warnings from my McAffee. I got off the web and my desk top picture went away to a default?( blue) with something wanting me to download some anti spyware stuff.
I immediately shut down, and restarted in safe mode. I ran:
AVG Antispyware
MalwareBytes anti malware.
I ran them several times in quick scan and got all kinds of stuff. (I think some of it was being reloaded after each scan)
I then ran them in full scans and went to bed. In the morning the MalwareBytes was still scanning!.
I have since ran both several more times and more stuff was found like:
Trojan FakeAlert
Trojan.Agent
Adware.Generic
Vundo
The last few scans came up clean. I ran Ccleaners Regestry tool and it found quite a few problems and it says they are fixed now. More McAffee virus scans, all good. I did a HJT scan for you to check:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:49 PM, on 6/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [StxTrayMenu] "F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Hydraquip.com
O17 - HKLM\Software\..\Telephony: DomainName = Hydraquip.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Hydraquip.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Hydraquip.com
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Seagate Sync Service - Unknown owner - F:\ceedo\Program Files\Seagate\Sync\SeaSyncServices.exe (file missing)

--
End of file - 5644 bytes

Any advise would be appreciated. I think I picked the bug up on a torrent site. Why would people act like they are sharing things, just to load this junk?
oops- I just read the underground page.
JimQuote from: jimpl on June 18, 2008, 11:40:26 AM

I think I picked the bug up on a torrent site. Why would people act like they are sharing things, just to load this junk?
Jim
Those torrent sites can be risky, thats for sure, if I use them I try to stick to Demonoid, pretty safe site....Your Hijack log looks clean from my untrained eye but you should wait for one of the Malware experts to check it out. BTW, what are you using for protection beside McAfee and AVG Antispyware?snap

well to prevent anything else from getting throught get comodo Firewall

http://www.personalfirewall.comodo.com/Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To ENTER Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* OPEN SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are CHECKED (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and REMOVAL is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Post new HijackThis log.Hello Broni,
I followed your instructions.
1. In safe mode I ran the SuperAntispyware. Full scan. It found nothing!
2. In normal mode, I ran MalwareBytes. Full scan. It found nothing!
3. In normal mode, I ran HJT. The log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:30:59 PM, on 6/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [StxTrayMenu] "F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Hydraquip.com
O17 - HKLM\Software\..\Telephony: DomainName = Hydraquip.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Hydraquip.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Hydraquip.com
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Seagate Sync Service - Unknown owner - F:\ceedo\Program Files\Seagate\Sync\SeaSyncServices.exe (file missing)

--
End of file - 6079 bytes

My uneducated guess is that the scans from yesterday did the trick.?
JimIt looks like....

Your computer is clean

1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
Run CCleaner.

2. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User ACCOUNT Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

3. Restart computer.

4. Turn System Restore on.

5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html
Hey Broni,
Thanks for all of your help. You and the other volunteers here do an outstanding service for us lay people out there and is very much appreciated.
Thanks again,
JimYou're welcome:)
Computer doing OK?
4426.

Solve : Request Assistance: Trojan and Virus deletion failure?

Answer»

You're WELCOME

4427.

Solve : AVG advice please?

Answer»

At present I have AVG Antispyware version 7.5.1.43 free edition and also AVG Anti virus version 7.5.519 free edition..

There is now a free AVG Antivirus version 8.0.1 available, and I was wondering if this is a replacement for both of the above. To properly install this version 8 would I have to remove both the versions 7.5 ? I would remove the previous one before installing the next one.

From what I've heard (and seen), both Antispyware and Antivirus are included in AVG 8.0I heard there were problems with that version. Not sure if they got fixed or not, but it will try an update it to it.squall_01 is right. You better hold on. Your versions of AVG will be supported until the year's end.or at least change to a differnt one.I have just gone from AVG 7.5 to AVG 8 Free and I have not had any problems. It includes anti-spyware.
Dias...
I'm glad, it worked for you, and it does for many people, but since serious NUMBER of people have been having problems, I just simply CAN'T recommend 8.0 to anyone.same here It's always hard, deciding whether or not to upgrade to the latest version of software.
There are always some who have major problems and others who have no issues at all.
I FALL into the latter category regarding AVG 8, you'll hear different reports from different people.
Whether or not to upgrade is a decision you'll have to make yourself I think.
However I can ANSWER PART of your question, AVG 8 includes both antivirus and antispyware protection in one program.Thanks for answers -

I was somewhat confused because the 7.5 versions of the antivirus and antispyware are separate programs. I presume from what you've told me that I should remove both of these before installing version 8 (if I do)?? I wasn't sure if version 8 somehow updated both in one go, as it were.

4428.

Solve : Can Anybody help??

Answer»

I have a toshiba laptop with windows xp home edition. I THINK I may have a virus or some malware due to SEVERAL things. When i LOAD internet explorer pages only part of the page will load(icons, text boxes, etc remain blank). When I search for something on a search engine the page comes up completely blank. Mozilla Firefox works fine. Also all basic programs run slow and freeze on a regular basis. I have windows live onecare and it can not find any viruses or spyware. Any advice on what the problem might be?What information should I add when submitting a question?The problem has been occurring for several WEEKS. It has been getting worse. First, it was just slow, then the internet pages started not loading, then search engines stopped working. I have service pack two installed but not 3 because my computer would not start with it installed. There are 64 gb on my computer with 16 used. IM using IE 7.Close IE.
Go Start>All Programs>Accessories>System Tools, click on Internet Explorer (no add-ons)
Will it work OK?nope. same thing.In IE, go Tools>Internet Options>Advanced tab, and click on Reset button. Restart computer.still nothing. thanks for the advice though. i think i might uninstall windows live onecare and use Avast. If you didn't install SP3 yet, you may uninstall IE7. It'll go back to IE6. See, if that work.
Did you try Firefox?firefox works fine. the problem w/ service pack 3 is that when i install it my computer won't turn on. i'll try ie 6.

4429.

Solve : Need advice about Anti Virus/Spyware that installed on computer?

Answer»

After lurking around in this forum, I've learned that it's best to have only 1 of anti virus and 1 of anti spyware install on the computer. But I saw all of this program being installed on my daughter PC; Nod32, Spybot-Search & Destroy, HijackThis, Ad-Aware, (SmitfraudFix, VundoFix, these two were installed recently to get rid of trojans, should I uninstalled them?) and Error Repair Professional.
I feel like it's too much but need some more advice and opinion from someone who know better. Plus, then i can use your advice to teach my daughter, too)
Have a Great Day!
NancyWell from my experience it is best to have more than one of each. They each look for DIFFERENT fingerprints of viruses and spyware, some look in every file and folder on a hard drive, some just look in the most popular places. In all honestly there's no WAY to be 100% protected from viruses or spyware unless you completely unplug your computer from the internet, but the next best thing to have more than one line of defense. To speak for myself I have Spybot Search and Destroy, AdAware, Windows Defender, and HijackThis for adware, and although I should have another anti-virus (sometimes more than one don't play well together) I'm using the free AVG Anti-Virus, there's ALSO a web-based virus scan from TrendMicro.com. Another point I feel I should make is that you need to make sure you keep them all updated. Most of them have some sort of automatic update as well. Hope this helps some. It is never suggested to use more than one antivirus. It will LEAD to problems including false positives, blue screens and system crashes. They conflict with each other.

Using more than one on DEMAND spyware scanner is advised. But only one that has real time protection as you will get the same problems.

Same for firewalls.Thank you for clearing this up.

4430.

Solve : computer needs windows reinstalled?

Answer» YEP In that CASE, we'll NEED that WINDOWS CD.
4431.

Solve : problem after running first spybot S & D?

Answer»

Took them about 6 YEARS to DECIDE it isn't. I downloaded a tool that is SUPPOSED to find the verification number; it isn't accepted
I was just allowed to download the first of 3 downloads of XP Service Pak 3, at www.microsoft.com/downloads, but have to go around my securities to download other TWO parts. I can't help you with that issue until you can show you have a legitimate copy of XP.K. I understand. You've HELPED me with a lot, and I appreciate it.

4432.

Solve : Hi There, Suggestions ? Bogus Microsoft Trojan Virus Scan / Phishing Site?

Answer» Symptons:
  • unstoppable virus scan-contunuos pop-up window from "Windows Antivirus 2008 WARNING , etc and Activate Now or Continue Unprotected
  • Originating site: http://homesecuresite.com where they ask for your credit card info to protect you!
Remidies so far:
  • run Mcafee scan: it has removed trojans: BraveSentry, Puper,GenericFakeAlert
  • put site on Restriced Sites list and rebooted but it's still there
  • running full MS mal software removal tool now(short version didnt work)
System
  • IE7 / XP updates automatically
  • McAfee complete security system
  • WPK2 password protected wifi

Thank you in advance for any ideas or suggestions!


[/list]Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any PROBLEMS while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the PROMPTS to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the LATEST version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can ALSO be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.I will do this. thank you!Attached is the complete log file.
Is it obvious how I let it in? Should I switch to SAFARI?
thank you again!

[recovering disk space -- attachment deleted by admin]All I need is HJT log.Hi Broni,

what is the HRT log? I only see the mbam log.Quote
3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.
4433.

Solve : Explorer.exe auto closing?

Answer»

Hey, heres my situation. Every time i open explorer.exe, or when the comp starts, it closes right back out. Then it tries to open back up, and then closes back out over and over until i close it out manually. I think theres a program doing it but i dont know.

This started today, before it didnt do anything. Also yesterday i got this program called advanced windowscare from download.com it had 7 million downloads so i think that was safe. And after using it it seemed fine. I cant really find a solution but since im using task manager for everything now i tried to go to desktop earlier, and a wierd message came up that said something like "windows can not find the path ;findlist-C:\documents and settings\me\desktop" which is not usual. And the message auto closed out and after i tried to see waht it was again it kind of frose my computer and i couldnt click on the task manager.

Well this is really hard for me to figure out, so any help would be really appreciated.

Here is my HJT log maybe it will help.
Quote

Logfile of HijackThis v1.99.1
Scan saved at 04:46:16 PM, on 2008-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\program files\Mozilla Firefox\firefox.exe
C:\documents and settings\me\desktop\ps\hijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,[emailprotected]
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Screenshot Utility.lnk.disabled
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Charter High-Speed Security Suite.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: ShortKeys Lite.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O15 - Trusted Zone: *.fnismls.com
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: dlcq_device - - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe" "C:\Program Files\Icecast2 Win32 (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Remote Packet Capture PROTOCOL v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Let me clarify. Shutting down happens to Windows Explorer only? Otherwise computer is working OK?
Advanced Windows Care is pretty good program, and I believe, it creates backup.
Also, your HJT version is outdated.
Download HijackThis from here:
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
Click on Download HijackThis Installer
POST HijackTHis log.Only windows explorer (explorer.exe) closes out by itself. And everything else is fine.

Thanks for the tip about that HJT thing i saw 2 things that are probably malware already Im probably gonna delete those and tell u what i get in a minute, but i might just wait for ur opinion since ur online now.

Heres the new log:

Quote
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:28 PM, on 2008-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\defrag.exe
C:\WINDOWS\system32\sndvol32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\program files\SwiftSwitch2\SwiftSwitch.exe
C:\Documents and Settings\ME\Desktop\ps\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,[emailprotected]
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Policies\Explorer\Run: [{A02B2800-0A1F-1033-1202-030512200001}] "C:\Program Files\Common Files\{A02B2800-0A1F-1033-1202-030512200001}\Update.exe" te-110-12-0000213
O4 - HKUS\S-1-5-19\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Screenshot Utility.lnk.disabled
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Charter High-Speed Security Suite.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: ShortKeys Lite.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O15 - Trusted Zone: *.fnismls.com
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: dlcq_device - - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Don't play with HJT, unless you're 100% sure what you're doing. I'll reply shortly.You have few nasties there.

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options MAKE sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Post new HijackThis log.doing now thankswell i guess theres no need to post that log, u fixed it thanks alot man have a good oneLack of symptoms does not gurantee all of the malware is gone. It is advised to continue posting any requested logs until given the all clear by a Malware Removal Specialist.As evil said....
4434.

Solve : Online Malware Removal??

Answer»

I am about to replace my old IBM Thinkpad with a new one from Lenovo. I WOULD like to copy data and some applications from the old machine to the new one. But I do not wish to import malware that may be buried in the old machine into the new one. Is there an online service to which I could upload any files to be transferred and which would subject them to a thorough, guaranteed malware removal process?

Thank you very much.

Bill Breidenbachhttp://virusscan.jotti.org/
http://www.virustotal.com/

Why not to scan a WHOLE drive?Quote from: billbreidenbach on June 23, 2008, 03:15:17 PM

I could upload any files to be transferred and which would subject them to a thorough, guaranteed malware removal process?

These clean what they find.
Dear EvilFantasy,

Thank you very much for the information provided in your reply to my POST. Most appreciated.

Bill Breidenbach
4435.

Solve : Internet Explorer - Firefox.?

Answer»

I'm using FIREFOX as my browser and like it. Can I DELETE Internet EXPLORER?

Unless you WANT to screw up your computer, do NOT delete Internet Explorer.

4436.

Solve : Rootkit?

Answer»

I'm not evil. Girls are evil!!

Just KIDDING. Let me know if anything ELSE COMES up... You will be the first to know

Thanks again! (unfortunately only one thanks allowed in an HOUR )

4437.

Solve : Missing Desktop icons and toolbar?

Answer»

everytime i START up my pc i get an error explorer.exe 0x0000006. i can only use the task manager to navigate. heres my HIJACKTHIS log btw

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:44 AM, on 3/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMAN.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [TWCU] "C:\Program Files\TP-LINK\TWCU\TWCU.exe" -nogui
O4 - HKLM\..\Run: [NVCPLDAEMON] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Diamondback] "C:\Program Files\Razer\Diamondback 3G\razerhid.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [TBPanel] "C:\Program Files\Vtune\TBPanel.exe" /A
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [RegistryMechanic] "C:\Program Files\Registry Mechanic\RegMech.exe" /H
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://edownload.grisoft.cz/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{99FAEA7A-5AFE-4639-827C-608902B789CB}: NameServer = 192.168.2.1
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper® Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
END of file - 10541 bytes



thank you

4438.

Solve : "Privacy components"?

Answer»

window entitled "privacy components" keeps popping up on PC; what is this? is it POSSIBLE to DISABLE this window?That is a ROGUE Security Program.

How to remove Privacy Components or Privacy Tools Pack (Removal Guide)

4439.

Solve : Malware/Spyware problems (logs attatched)?

Answer»

ok my computer is actually running pretty fast now! thanks!


I have a few questions though.

What antivirus would you recommend because I really don't like Comodo.


Thanks!

[attachment deleted by admin]It looks like you have AVG installed now? Is that working OK?well...i got rid of that and now i have zonealarm firewall and I have avast! home edition. Those are working pretty good but thanks for EVERYTHING!Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Use the Secunia Software INSPECTOR to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, SPAM, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    4440.

    Solve : pc is slower after installing 3 GB RAM?

    Answer»

    I recently installed 3 GB RAM and my pc which has windows vista on an acer 5100 notebook,was running great when I first put in the new RAM. It is now so slow a turtle could run faster than it. Is the problem in the websites I go to and or is it the hard drive? I think it is cluttered with junk from all these websites and adware I don't know. Where can I and how much to fix this issue? I'm about to get fed up with the darn thing. Any help would be great thanks.If you think it's a malware issue then go HERE and WORK steps 2 and 4. If step 4 doesn't turn up anything then it likely isn't a malware issue.I'm a beginner don't forget. I don't know what it is. That's what I asked for so still do the steps anyway? Thanks.It should be easy to rule in or out malware by running the MalwareBytes scan. Where do I get the Malwarebytes scan at?Go to Evilfantasy's 1st reply, click "Here" it is blue in color, then once you are at that page,
    scroll down to step 4
    You will see "Download MalwareBytes" it is ALSO blue in color this should automatically bring up a small window Click save file... and then follow the instructions for using and installing the software

    Quote from: joepinger on March 12, 2009, 06:59:58 PM

    Where do I get the Malwarebytes scan at?
    also, in addition to malwarebyte, you can go get a-squared free for a second opinion, as programs don't detect everything 100%.

    Here's the link to get a-squared free. HTTP://filehippo.com/download_asquared/


    This is just if you want a second opinion to DOUBLE check and like Malwarebyte software, they both update everyday so should be good.Please don't install a=squared. We need logs. Without them we don't know what we are dealing with or how to fix it.

    @joepinger - You have to read my replies carefully. All of the information you need will always be there.Quote from: evilfantasy on March 13, 2009, 06:13:40 AM
    Please don't install a=squared. We need logs. Without them we don't know what we are dealing with or how to fix it.

    @joepinger - You have to read my replies carefully. All of the information you need will always be there.

    I never said you needed it, i meant if you wanted A-Squared free later, as a double check afterwards when malware cleaning process is done.
    4441.

    Solve : Malware Biten.?

    Answer»

    I am getting an run time error o, and 440 when I try to start up MALWAREBYTES. Tried to uninstall but error messages POP up and cannot uninstall from add and remove. ALSO this happened after I ran a Hijackthis log and deleted a wotdll something or other. windows PROCESS log tool recommended to delete it.Update, I downloaded malwarebytes again and updated it. solved problem.

    4442.

    Solve : Please review logs. Cleaning up laptop and following your steps?

    Answer»

    i'm cleaning up my wife's lap top. i have followed all steps as instructed. she is running vista. oh, i didn't disable teatimer because i dont know if its on this system. i couldnt find the "padlock" icon on my system tray. so let me know what steps i need to take next.
    thanks in advance.

    ps this is my second computer cleanup using this forum. the first went smoothly want to thank the mods for all the help.

    [attachment deleted by admin]and now i cant get Secunia to finish its scan.. My java has been updated to version 6.12 (I think).. the java site said it was up to date.. before secunia said it needed to be updated. in which i uninstalled all old java and re downloaded the newest version. now secunia wont finish... any help WOULD be nicethe computer is still doing the same wierd things. my logs are in the original post with attachments. thanks in advanceDownload random's system information tool (RSIT) by random/random from and save it to your Desktop.

    • Double click on RSIT.exe to run.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open.
    • log.txt <will be maximized and info.txt <will be minimized
    • Please post the contents of both logs in the next reply.
    thanks for replying.. i have attached both logs

    [attachment deleted by admin]Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixhere is combo fix logs. Also i'm not used to her lap top but should i be running windows defender with superantivirus? i have them both enabled.

    [attachment deleted by admin]Download the Norton Removal Tool (SymNRT) to your Desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.
    • Go to your desktop and double click on the removal tool and then click Setup.
    • Once open Click Next
    • Accept the license agreement and click Next
    • Type in the letters/numbers that you see into the text box then click Next.
    • Then click Next and the tool will start running.
    • Once finished restart the PC and run the tool again to ensure everything has been removed.
    • Delete Nortonremoval tool from your Desktop.
    .
    ----------

    Use the ESET Online Antivirus Scanner

    This scanner REQUIRES Internet Explorer

    1. Check the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the activex control to install
    4. Click Start
    5. MAKE sure that the option Remove found threats and the option Scan unwanted applications is check marked.
    6. Click Scan
    7. Wait for the scan to finish
    8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.i used the norton removal from the desktop and it worked fine. I ran it again as requested then i removed the it from the desktop. I have tried teh ESET link but it is not working. I have intsalled the active X as it requested but it isnt doing anything. I click the start but it shows a message on the small box on the screen. It says it cannot Error: Cannot intialize OnlineScanner. Administrator rights required. I'm not sure how to get around this problem.Try this instead.

    Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
    • Double-click on drweb-cureit.exe and then click Start
    • An information notice will appear, click OK.
    • This starts a short scan that will scan the files currently running in memory.
    • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
    • If or when something is found, click the Yes button when it asks you if you want to cure it.
    • Once the short scan has finished, Click Settings > Change Settings
    • Under the Scanning tab UNcheck Heuristic analysis and click OK
    • Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
      • Click Yes to all if it asks if you want to cure/move any file(s).
    • When the scan is done.
    • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
    • Save the DrWeb.csv report to your Desktop.
    • Exit Dr.Web Cureit.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    [/COLOR]
    • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
    • Copy and paste that log in the next reply
    [/list]okay running this program. i ran it last night before bed and was planning on posting the logs. but it was taking so long i went to bed with hopes of posting logs this morning. problem is i woke up and the computer apparently rebooted and there was no logs saved on the program. So i am re doing the scan.. I have some things to do and hoping it wont do the same thing today. It won't let me click on the save report list yet (while or before scanning). According to your intructions it says to click on the save report list after it scans, so I'll assume I am doing it correctly. Will post logs later.alright i tried the dr.web again and it scanned (again and finished). I tried to save the logs as requested but the computer screen went blue with a bunch of writing and it said something like critical errors and it counted down from like sixty and before it got done counting it shut down and restarted. It DIDNT give me a chance to save or even read what was on the blue screen other than the critical error. Then it started back up and came to the black screen and asked if i wanted to start in SAFE mode, normal, or some other mode. I started back in normal mode.

    I will wait for a reply before making another scan because it takes about two to three hours to run this scan. Try running i tin Safe Mode.
    4443.

    Solve : Noob in need of some major help.?

    Answer»

    So basically EVERY day that I log onto my laptop, My Spy Sweeper virus protection pops up saying something about "A Potentially Harmful File has been QUARANTINED" or something to that extent and EVERYDAY it's EXACTLY the same thing: Virusburst Fakealert. So I go to the quarantined files and delete it but it keeps coming back.

    The one thing I don't understand is that I never have any pop ups, warnings, or a blue screen from this virus that I hear most people get. I'm just GETTING sick of seeing the warning pop up everyday and having to delete it, so can someone PLEASE help me out?

    Warning: I honestly KNOW little about computers.Read this before requesting malware removal help

    go to the top of this page ( as above ) and follow through to the end

    an expert will see them , harry

    4444.

    Solve : My Houdini computer?

    Answer»

    Yesterday, I downloaded Stopzilla (it seems to be a good utility) Now once in awhile I have a problem keeping PAGES open. I open a PAGE and it downloads and then disappears automatically. It doesn't happen with all the websites;however, it is annoying. I input the URL again, and the same thing happens. It starts to load and either it disappears during the load or shortly after the page comes up. I wanted to remove the Stopzilla file but I thought I ask first. I checked Spybot S/D & Adaware. They come clean so I just am at wits end.




    internet explorer 6
    Windows xp
    250 gb
    intel pentium 4
    2.66 g
    Cyber Power custom configured
    memory 512MB
    __________________
    lisashomeoffice I too am using Stopzilla ...... Turn off the pop UP Stopper and the websites will stay open. You should be ABLE to remove the sites from the Black List so they'll open for you.If I turn off the pop up blocker won't I get pop ups?. Do you USE a different utility to take care of the pop ups? I'll try it and let you know how it worked. Thanks for the advice.

    LisaHello,
    I disabled the pop-up blocker, and it does seem to be working better. I forgot that it doesn't take too much for the popup blocker to mess up the computer. Thanks.Ah, you are most welcome....

    4445.

    Solve : Pretty sure I might have something nasty?

    Answer»

    So, let's start from the beginning. I went to FPSbanana.com to download a map for Team Fortress 2. I usually don't need to do that, but the server that I was playing on didn't upload the map, so I had to do so manually. So I click 'Download' and then this fake online scanner 'scanned' my computer and said that I had some odd viruses. I closed out of it, knowing that it was fake, but ever since after that, I've been getting lower FPS in games and everything loads slower. I might just be paranoid, but here are my logs.


    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 03/02/2009 at 10:06 PM

    Application Version : 4.25.1014

    Core Rules Database Version : 3781
    Trace Rules Database Version: 1739

    Scan type : Complete Scan
    Total Scan Time : 02:46:03

    Memory items scanned : 370
    Memory threats detected : 0
    Registry items scanned : 6825
    Registry threats detected : 1
    File items scanned : 217191
    File threats detected : 0

    Unclassified.Unknown Origin
    HKU\S-1-5-21-1745023626-1345479032-1206160406-1000\Software\MICROSOFT\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}


    Malwarebytes' Anti-Malware 1.34
    Database version: 1814
    Windows 6.0.6001 Service Pack 1

    3/3/2009 6:11:02 AM
    mbam-log-2009-03-03 (06-11-02).txt

    Scan type: Quick Scan
    Objects scanned: 56261
    Time elapsed: 4 MINUTE(s), 34 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:25:27 AM, on 3/3/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\PLFSetI.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Program Files (x86)\JAVA\jre6\bin\jusched.exe
    C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
    C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
    C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
    C:\Program Files (x86)\Acer\Acer VCM\AcerVCMProxy.exe
    C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
    C:\Program Files (x86)\AVG\AVG8\avgtray.exe
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
    C:\Program Files (x86)\Acer\Acer VCM\acp2HID.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\sniper.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1008&m=aspire_6930g
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1008&m=aspire_6930g
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1008&m=aspire_6930g
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
    O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~2\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup
    O4 - HKLM\..\Run: [Acer Assist Launcher] "C:\Program Files (x86)\Acer\Acer Assist\launcher.exe"
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Acer VCM.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
    O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
    O23 - Service: CLHNService - Unknown owner - C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
    O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
    O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
    O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - c:\Windows\system32\ZuneWlanCfgSvc.exe (file missing)

    --
    End of file - 12030 bytes



    Oh, and after I did the Malwarebyte's scan and it asked me to reboot, it failed to do so. I had to hold down my power button to turn off my computer and then push it again to turn it back on.
    How is the computer running now?

    This scanner works with Internet Explorer only!

    Scan with the BitDefender Online Scanner
    Click I Agree to the license and then install the ActiveX control.
    Please DO NOT change the Scanning Options.
    That will make your logs huge and we don't need to see clean files.

    Select Start Scan to begin.
    This scan can take a while so please be patient and let it complete.

    Once BitDefender completes the scan:
    Click-on the Detected Problems tab.
    Then select Click here to export the scan report



    This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

    You will have to upload the file online. The forums will not accept HTML.

    Go to File Dropper

    Click Upload
    Locate the file and double click it.
    Copy the download link and post it back here.Still running pretty slow. I tried turning Team Fortress 2 to the lowest settings and I still got low FPS, which led me to believe that this is a hard drive problem. I'm defragging my computer right now and when it's done, I'll report back in.I'm not done defragging yet, but I decided to start the scanner anyways. One problem though. It's saying that it's going to take around 102 hours to complete...Don't do both at the same time it will cause the computer to crash.

    Are you on dial-up?Alright.

    And no.Just do them one at a time. BitDefender should only take around an hour.Defragging didn't really help me out much. I tried doing the BitDefender online scanner, but I had to close it out early because I had to go to my dad's house. I'll start it again tomorrow afternoon.

    Oh, and I FINALLY hunted down where I can get drivers for laptop. Though, I'm not sure which specific drivers I should get.

    http://www.acerpanam.com/synapse/forms/portal20.cfm?website=AcerPanAm.com&siteid=7117&areaid=2&formid=3394#resultsYour using Vista 64bit so there might not be a driver you need yet. What driver do you think you need?Alright, I've been out all weekend so I couldn't reply to this thread. I just finished another scan with AVG saying that I don't have a virus. I'm doing that online scanner right now. Oh, and it's not just in games. It's also in general. Everything is slowing down.Machine specs ? ?Quote from: patio on March 09, 2009, 02:00:40 PM

    Machine specs ? ?

    9600 GS
    Core 2 Duo (2.0 GHz)
    4GB of RAM
    320GB Hard DriveDo you think opening up my laptop and cleaning out my fans would help?That online virus scanner said that I didn't have a virus. I'm thinking about just formatting.Quote from: Popolop on March 12, 2009, 01:45:21 PM
    Do you think opening up my laptop and cleaning out my fans would help?

    I don't think that is very wise to open a laptop. unless you now what you are doing that is.

    Try making a post in the Windows forum. This isn't a malware issue and nobody is seeing this thread in this forum.
    4446.

    Solve : Voices in background at startup?

    Answer»

    As soon as I start-up windows, I hear a few clicks like as if I pushed enter to go to a new URL, then VOICES come on like a movie advertisement. It's not a RADIO pick-up, either. I JUST INSTALLED windows xp and then this...

    Anyway, here is my hijackthis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:32:13 AM, on 3/14/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18372)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wincpr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wpabaln.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\NOTEPAD.EXE

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel WIRELESS Tray
    O4 - HKLM\..\Run: [wincpr] C:\WINDOWS\system32\wincpr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\WLKeeper.exe

    --
    End of file - 5401 bytes




    if anyone could help, it would be greatly appreciated.Scan SUSPICIOUS File(s)

    Please go to VirusTotal.com
    (If more than one file needs scanned they must be done separately and logs posted for each one)

    1. Copy the file path in the below Code box:

    Code: [Select]C:\WINDOWS\system32\wincpr.exe
    2. At the upload site, click once inside the window next to Browse.
    3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    4. Next click Send File
    Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    This will perform a scan across multiple different virus scanning engines.
    Important: Wait for all of the scanning engines to complete.
    5. Copy and then Paste the link to the results in the next reply.Thank you for the help. I reformatted the HD and am about to scan my USB before I reinstall the drivers. If after installing the drivers I still hear the audio advertisements, I will do what you told me to and post a response.

    4447.

    Solve : autorun.inf worm removal?

    Answer»

    Hello again,
    Am I in the right place for this type of situation?

    On my Desktop PC I picked up an autorun.inf worm or virus from my flash drive. It was changing how my D: drive was running. It was making me open it like a file. I don't know if that PC is fixed yet.. I have used that flash drive on this laptop. I didn't find any files like that on it.. Instead I found a virus called HTML/Spoofing.Gen. I quarantined and removed it with Avira Antivir. I did everything on the list of things to do and here is the logs...

    Should I do all this on the Desktop PC with the flash drive attached to clean those out to or, is there a different procedure for the autorun.inf worm??
    Thanks .. Patricia

    [attachment deleted by admin]Sorry for the delay.

    Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

    • Double click on RSIT.exe to run.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open.
    • log.txt <will be maximized and info.txt <will be minimized
    • Please post the contents of both logs in the next reply.
    Quote
    Should I do all this on the Desktop PC with the flash drive attached to clean those out to or, is there a different procedure for the autorun.inf worm??

    Sorry I missed that the first time through.

    Use this for any flash drive you have used on the infected computer.

    Flash Drive Cleanup

    Download Flash Disinfector by sUBs and save it to your Desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.
    .
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

    Will be awaiting the RSIT log...quote author=PatriciaW link=topic=78698.msg518498#msg518498 date=1236883936]
    I was wondering the same thing myself. I followed everything I was suppose to do and still no reply.. I SEE they answer others with hijack logs.... If they won't answer and don't have the knowledge why make it SOUND like they do in the first place? waste of my time going through all that stuff and then no ONE will help me anyway. False advertising I might add... Free computer help for EVERYONE.. I will go else where from now on and tell others to do the same. Have you tried majorgeeks.com??? That's where I am heading.. good luck with your situation..
    [/quote]

    take your time and wait this time , not like above , help is not at hand for every-one

    on tap , harryYup, leave the attitude at the door, lady.
    Trust me you will have a much longer wait at MG's. They usually have at the least a 3 day turn around on the first reply. And their pre-steps are much more involved. Good luck!!Evil fantasy
    thank you for your help even after my attitude on the other post. Its just frustrating not being able to fix things on my own.. I haven't had any computer training I learn as i go. no one was born with this knowledge. it's taught to you. Even big companies get a virus so for Dias to act like I'm an idiot for getting a virus is uncalled for if he can't help me then don't answer posts that wasn't addressed to him. . I have never posted to a forum before and didn't understand why you skipped me and helped others that posted after me once again sry bout the attitude and thanks for the help. here are the logs you asked for...

    [attachment deleted by admin]Quote from: evilfantasy on March 12, 2009, 01:28:47 PM
    Sorry I missed that the first time through.

    Use this for any flash drive you have used on the infected computer.

    Flash Drive Cleanup

    Download Flash Disinfector by sUBs and save it to your Desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.
    .
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

    Will be awaiting the RSIT log...

    Antivir found a worm while downloading it..so i didn't open it.I found out it's a false positive.. so I am trying it again...Many of the tools I will have you use will be flagged by Avira. The way they work is similar to that of malware. Fight fire with fire...

    Don't let Dias bother you. He is somewhat likable once you figure out he has that attitude with everyone. Right Dias?

    Be right back. Looking at the logs now.Quote from: evilfantasy on March 13, 2009, 10:57:59 AM
    Don't let Dias bother you. He is somewhat likable once you figure out he has that attitude with everyone. Right Dias?

    More or less. I just can't stand people who come on here badmouthing the "service" they get (or don't get), and/or expecting to be at the head of the queue.

    I still find the title of this thread objectionable. OK back to business now. Everyone can play nicely long enough to take care of this I hope.

    Do you know what this is?

    Quote
    O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)

    If not then please scan it.

    Please go to VirusTotal.com
    (If more than one file needs scanned they must be done separately and logs posted for each one)

    1. Copy the file path in the below Code box:
    Code: [Select]C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe2. At the upload site, click once inside the window next to Browse.
    3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    4. Next click Send File
    Your file will POSSIBLY be entered into a queue which normally takes less than a minute to clear.
    This will perform a scan across multiple different virus scanning engines.
    Important: Wait for all of the scanning engines to complete.
    5. Copy and then Paste the link to the results in the next reply.I tried to scan the file and it said path don't exist. I'm pretty sure it's an old music file I transferred via the USB flash drive. The date on the file is from 2006 and I didn't have this laptop at that time.I scanned it with antivir and the malwarebytes neither of them detected anything. I was working on the desk top most of the afternoon. I have dial up so everything takes forever to download and i have to keep switching the TELEPHONE cord to whichever computer i am working on.. lol anything else i need to do?? thanks again.. Quote from: PatriciaW on March 13, 2009, 02:28:25 PM
    I have dial up so everything takes forever to download and i have to keep switching the telephone cord to whichever computer i am working on.. lol anything else i need to do?? thanks again..

    I will try to use all small tools so it doesn't take too long to download.

    Do you want to get rid of that service since you don't use it anymore or do you need it?

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    .
    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis.Ok.. here is a new log from hijackthis. which service were you asking about??? my dial up or something else?

    [attachment deleted by admin]
    4448.

    Solve : New computer horrible performance. Infected??

    Answer»

    Your welcome!!!

    Safe SURFING... Quote from: evilfantasy on February 24, 2009, 10:46:18 PM


    Let me know about CYBERDEFENDER please before we continue.

    I use Cyberdefender anti-virus all of the time. I GOT the free anti-virus scanner first off there WEBSITE which found a lot of stuff on my system and got rid of the spyware and Trojans. I also had viruses, so I bought the upgrade which got rid of everything on my system. The version that you pay for comes with 24/7 computer help, which I have used twice and they were very helpful.

    Does that help?Second forum you have posted in one of my malware removal threads about using CyberDefender hankfarkas. I'm going to start treating it as spam and removing them.

    CyberDefender has very questionable sales tactics. Very similar to that of rouge software.
    4449.

    Solve : http://liveantimalwareproscan.com WINDOWS or SCAM??

    Answer»

    So, I'm reading my emails. I never EVER open an email from an unknown sender, I just delete them. I clicked on a trusted email from a company that I do surveys for and instantly my browser closed and another opened!

    The new browser window looked EXACTLY like the window when I open 'my computer' with the same panes and words etc., except the colors seemed slightly off. I was told Windows had detected that my computer was infected with email worms.

    I have several anti-spyware, malware, and anti-virus programs running on my computer at all times and nothing else popped up with a warning except for this one. So, I was a little suspiscious and I clicked 'cancel' because it was asking me if I wanted to download and run this 'windows' anti-worm program. Immediately a small box popped up with 'Windows Security Alert' and it had a list of my supposed infections.

    Now I'm really confused. The little box looks legitimate, but I learned the hard way in the past that some scammers can make their things look like they're legitimate, so I minimized this warning window and opened up Malwarebytes and did a QUICK Scan. Nothing showed up.

    So, I went back to the warning screen and thought, well, maybe I'm being just a little paranoid and I clicked on RUN and a warning popped up asking me if I really WANT to run this software because if I don't know for sure what it is, it could damage my computer.

    There was a web address on that screen so, before I ran potentially DANGEROUS software on my computer, I went to that web address in another browser.

    It looked legitimate, but there was nothing indicating that it was from Windows or Microsoft or that Windows or Microsoft is affilliated with them in any way. So I clicked on some of the links on their home page to get more information. I clicked on FAQ, COMPANY, and others ... but they only took me to a page to order their software!

    Are they a legitimate company??? Is this software nothing more than adware???

    I'm so confused! Should I just close the browser and not worry about it?

    PLEASE ADVISE, thank you so much!I forgot to mention, it's saying it wants to add ANTIVIRUS 360 components to my computer to be sure it is clean.

    Also, you know the WINDOWS SECURITY ALERT window that I told you popped up with a list of my infections? Well, I just clicked on the down arrow of the SCROLL bar to see what the infections are and the FILE DOWNLOAD SECURITY WARNING box popped up. I thought that was strange, so I clicked on another area of the window and the same thing happened. I really don't think this is a legitimate WINDOWS SECURITY ALERT window.Yes it's a scam site. It's the Antivirus 360 Scanner, which is a rouge.

    4450.

    Solve : Please help ... unrecognized Windows files ... don't know if I can reboot?

    Answer»

    I have:

    Dell Dimension 4100
    Intel Pentium III
    Windows XP

    I run:

    Free AVG daily (update daily also)
    CCleaner
    Malwarebytes Quick Scan daily
    Super Anti-Spyware Complete Scan every few DAYS

    On the morning of the 5th, before I went online, I downloaded updates and ran MALWAREBYTES Quick Scan and it told me I had 1 infection, so I removed it.

    Then I ran the Quick Scan again, and the same infection showed up again, so I removed it.

    Then I ran the Complete Scan and 7 infections showed up, so I removed them.

    THEN a windows box popped up with the heading WINDOWS FILE PROTECTION and inside the box it said:

    Files that are required for Windows to run properly have been replaced by unrecognized versions. To maintain system stability, Windows must restore the original versions of these files. Insert your Windows XP Professional Service Pack 3 CD now.

    Well, I don't have the CD. I got this computer second-hand years ago.

    So I clicked CANCEL and it asked me if I was sure I wanted to keep the unrecognized versions and I said yes.

    So then I ran Malwarebytes Complete Scan again, and 3 infections showed up (all pertaining to 'restore'), and I deleted them.

    This time I did not get the WINDOWS FILE PROTECTION warning.

    Then I downloaded updates and ran Super ANTISPYWARE Complete Scan, and no infections were detected.

    Then I downloaded updates to AVG and ran 'scan computer' and no threats were detected.

    Even though all my scans show my computer is clear of infections, I am still very worried about that WINDOWS FILE PROTECTION warning, because now my computer has kept the unrecognized versions of files that are required for Windows to run properly.

    I am afraid to even try to reboot my computer, fearing it won't boot up again.

    Here are the Malwarebytes & HJT logs. Any help or advice will be greatly appreciated. Thanks!




    [attachment deleted by admin]avg runs it-self , ccleaner + malware + sas , would be ok to run every 5/7 days , your avg is out of date , wait for the experts to came along

    for what its worth , i can not see anything in the 2 logs , but if there is an expert will let me know , harryDownload ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is RUNNING. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixhi evil , was i right when i said there was nothing in the 2 logs , if there was could you tell me what it was , harryThere are a few things in the HJT log that need further review, Don't want to post what yet as they could be nothing so don't want anything deleted by mistake.Hi,

    Thanks so much for your help, I really REALLY appreciate it. Here is a copy of the log:



    [attachment deleted by admin]Download the OTMoveIt3 by OldTimer

    Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

    * Save it to your Desktop.
    * Double-click OTMoveIt3.exe to run it.
    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

    Code: [Select]:Processes
    explorer.exe

    :files
    c:\windows\Tasks\At1.job
    c:\windows\system32\R8uV337c.exe
    c:\windows\Tasks\At3.job
    c:\windows\Tasks\At4.job
    c:\windows\Tasks\At5.job
    c:\windows\Tasks\At6.job
    c:\windows\Tasks\At7.job
    c:\windows\Tasks\At8.job
    c:\windows\Tasks\At9.job
    c:\windows\Tasks\At10.job
    c:\windows\Tasks\At11.job
    c:\windows\Tasks\At12.job
    c:\windows\Tasks\At13.job
    c:\windows\Tasks\At14.job
    c:\windows\Tasks\At15.job
    c:\windows\Tasks\At16.job
    c:\windows\Tasks\At17.job
    c:\windows\Tasks\At18.job
    c:\windows\Tasks\At19.job
    c:\windows\Tasks\At20.job
    c:\windows\Tasks\At21.job
    c:\windows\Tasks\At22.job
    c:\windows\Tasks\At23.job
    c:\windows\Tasks\At24.job

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    * Click the red Moveit! button.
    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    Close OTMoveIt3

    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.Here are the results:

    ========== PROCESSES ==========
    Process explorer.exe killed SUCCESSFULLY.
    ========== FILES ==========
    c:\windows\Tasks\At1.job moved successfully.
    File/Folder c:\windows\system32\R8uV337c.exe not found.
    c:\windows\Tasks\At3.job moved successfully.
    c:\windows\Tasks\At4.job moved successfully.
    c:\windows\Tasks\At5.job moved successfully.
    c:\windows\Tasks\At6.job moved successfully.
    c:\windows\Tasks\At7.job moved successfully.
    c:\windows\Tasks\At8.job moved successfully.
    c:\windows\Tasks\At9.job moved successfully.
    c:\windows\Tasks\At10.job moved successfully.
    c:\windows\Tasks\At11.job moved successfully.
    c:\windows\Tasks\At12.job moved successfully.
    c:\windows\Tasks\At13.job moved successfully.
    c:\windows\Tasks\At14.job moved successfully.
    c:\windows\Tasks\At15.job moved successfully.
    c:\windows\Tasks\At16.job moved successfully.
    c:\windows\Tasks\At17.job moved successfully.
    c:\windows\Tasks\At18.job moved successfully.
    c:\windows\Tasks\At19.job moved successfully.
    c:\windows\Tasks\At20.job moved successfully.
    c:\windows\Tasks\At21.job moved successfully.
    c:\windows\Tasks\At22.job moved successfully.
    c:\windows\Tasks\At23.job moved successfully.
    c:\windows\Tasks\At24.job moved successfully.
    ========== COMMANDS ==========
    File DELETE failed. C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AF7.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AFE.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_530.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_153142
    Sorry, here is the log that popped up after I rebooted my computer:

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== FILES ==========
    c:\windows\Tasks\At1.job moved successfully.
    File/Folder c:\windows\system32\R8uV337c.exe not found.
    c:\windows\Tasks\At3.job moved successfully.
    c:\windows\Tasks\At4.job moved successfully.
    c:\windows\Tasks\At5.job moved successfully.
    c:\windows\Tasks\At6.job moved successfully.
    c:\windows\Tasks\At7.job moved successfully.
    c:\windows\Tasks\At8.job moved successfully.
    c:\windows\Tasks\At9.job moved successfully.
    c:\windows\Tasks\At10.job moved successfully.
    c:\windows\Tasks\At11.job moved successfully.
    c:\windows\Tasks\At12.job moved successfully.
    c:\windows\Tasks\At13.job moved successfully.
    c:\windows\Tasks\At14.job moved successfully.
    c:\windows\Tasks\At15.job moved successfully.
    c:\windows\Tasks\At16.job moved successfully.
    c:\windows\Tasks\At17.job moved successfully.
    c:\windows\Tasks\At18.job moved successfully.
    c:\windows\Tasks\At19.job moved successfully.
    c:\windows\Tasks\At20.job moved successfully.
    c:\windows\Tasks\At21.job moved successfully.
    c:\windows\Tasks\At22.job moved successfully.
    c:\windows\Tasks\At23.job moved successfully.
    c:\windows\Tasks\At24.job moved successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AF7.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AFE.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_530.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_153142

    Files moved on Reboot...
    File C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AF7.tmp not found!
    File C:\DOCUME~1\Default\LOCALS~1\Temp\~DF7AFE.tmp not found!
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
    File C:\WINDOWS\temp\Perflib_Perfdata_530.dat not found!

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      ----------

      Use the
    Kaspersky Lab Online Scanner

    In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

    • Click on SCAN NOW
    • Click Accept.
    • The program will then begin downloading the latest definition files.
    • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
    • The scan will take a while, so be patient and let it finish.
    When the scan is done, in the Scan is complete window, any infection is displayed.
    There is no option to clean/disinfect, however, we need to analyze the information on the report.

    To obtain the report:
    Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop.
    • In the File name area use KScan, or something similar.
    • In Save as type: click the drop arrow and select: Text file [*.txt]
    • Then, click: Save


    Copy and paste the Kaspersky Online Scanner Report in your next reply.

    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.I've been running this Kaspersky scan for a couple hours now. It was scanning slowly, but was scanning.

    For about the past 40 minutes or so its been stuck at 69% and is stuck at the same number of files scanned 43,232.

    It says there is one threat, one infected object. I believe this is the point where it stopped but I don't know for certain because I wasn't watching it constantly.

    It says ... now scanning: HALAPIC.DL_ and location: C:\cmdcons

    Do you think its stuck and no longer running? Or should I let it run overnight and see what happens?

    Thanks!
    If it doesn't continue soon then stop it and use Dr Web instead.

    Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
    • Double-click on drweb-cureit.exe and then click Start
    • An information notice will appear, click OK.
    • This starts a short scan that will scan the files currently running in memory.
    • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
    • If or when something is found, click the Yes button when it asks you if you want to cure it.
    • Once the short scan has finished, Click Settings > Change Settings
    • Under the Scanning tab UNcheck Heuristic analysis and click OK
    • Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
      • Click Yes to all if it asks if you want to cure/move any file(s).
    • When the scan is done.
    • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
    • Save the DrWeb.csv report to your Desktop.
    • Exit Dr.Web Cureit.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    [/COLOR]
    • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
    • Copy and paste that log in the next reply
    [/list]I ran DrWeb last night. It was taking a long time to run and I went to bed at about 3:00 a.m. while it still had about 1/4 of the way to go.

    I checked it this morning and there was a question of whether or not I wanted to 'move' something. I said YES to all.

    After it completed its run, I saved a copy of the log to the desktop.

    Then I rebooted my computer.

    That was about 3 hours ago. I just went downstairs to check my computer (I'm on my husband's computer right now) and it is still showing the blue Windows screen that says WINDOWS IS SHUTTING DOWN.

    About an hour ago I tried to help it shut down all the way by pressing CTRL+ALT+DEL but nothing happened.

    I don't know what to do at this point. Should I hold the on/off button until it shuts down? Or will that undo everything that DrWeb has done in its scan?

    Please advise.

    Thanks!Hold the on/off button until it shuts down. The log should still be on the desktop.Here is the DrWeb log:

    NULL;C:\;Trojan.DownLoader.324;Deleted.;
    install.htm;C:\;Exploit.DialogArg;Deleted.;
    uinst_cp.exe;C:\WINDOWS\SYSTEM32;Adware.CasProg;;
    RxUser.exe;C:\Program Files\Dell\Resolution Assistant\Common\bin;Trojan.Spambot.origin;Incurable.Moved.;
    Uninstall.exe\SkillJamLoader.dll;C:\Program Files\SkillJam Technologies\Secure Player\Uninstall.exe;Program.PopcapLoader.4;;
    Uninstall.exe;C:\Program Files\SkillJam Technologies\Secure Player;Archive contains infected objects;Moved.;
    01129984.FIL.OLD;C:\$VAULT$.AVG;Adware.Bho;;
    08137240.FIL.OLD;C:\$VAULT$.AVG;Trojan.Inject.351;Cured.;
    08982035.FIL.OLD;C:\$VAULT$.AVG;Trojan.Inject.351;Cured.;
    33135219.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.;
    33136160.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.;
    19503571.FIL;C:\$VAULT$.AVG;Trojan.Inject.380;Deleted.;
    57809879.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.489;Deleted.;
    28995633.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.489;Deleted.;
    45116527.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.;
    45117208.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.;
    11073900.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.;
    11074991.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.6098;Deleted.;
    SkillJamLoader.dll;C:\Documents and Settings\All Users\Application Data\SkillJam\SecurePlayer;Program.PopcapLoader.4;;
    A0065913.exe;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Spambot.origin;Incurable.Moved.;
    A0065921.exe\SkillJamLoader.dll;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129\A0065921.exe;Program.PopcapLoader.4;;
    A0065921.exe;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Archive contains infected objects;Moved.;
    A0065922.OLD;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Inject.351;Cured.;
    A0065923.OLD;C:\System Volume Information\_restore{D1813AB8-B0C3-49B3-96D2-D8F82859F8EF}\RP1129;Trojan.Inject.351;Cured.;