Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

4751.

Solve : Firewalls?

Answer»

Good Morning,

Can you install more than one firewall in an OS?

If so, can you give me an example of what firewalls are being used?

Just a curious question....You can, but it's generally not advisable to do so.One AV program and one firewall one a computer. More than that and you will have problems.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to USE only one firewall at the same time.HOW DOES ONE REMOVE THE WINDOWS FIREWALL?Quote from: oleger on August 13, 2010, 08:26:55 PM

HOW DOES ONE REMOVE THE WINDOWS FIREWALL?

1. don't WRITE in all capital letters.
2. you can't uninstall the windows firewall. But you can DISABLE it and get yourself another firewall if you so choose to do so.


If you're behind a router with hardware firewall, that should make software firewall unnecessary. But if not, I'd go with Online Armor, it doesn't bug you unnecessarily.


Quote from: SuperDave on August 13, 2010, 01:20:20 PM
One AV program and one firewall one a computer. More than that and you will have problems.

You can install multiple AV's, but use only one for realtime scanning.I just install a firewall.Hey thanks guys, i LIKE asking simple QUESTIONS like this.....it opens up the door for more productive replys and other forms of advice!
4752.

Solve : Trend Micro fails the 'Doomsday Test'!?

Answer»

Hello There!

All those of you who have put the safe bet on Trend Micro to shield your machines against the known & unknown threats would be disappointed to read the following story::

Check out:::

Infected link removed. How IRONIC that clicking on that link makes avast pop-up telling me a trojan was found on that page.

Quote from: Saurabhdua on August 16, 2010, 06:44:20 AM

All those of you who have put the safe bet on Trend Micro to shield your machines against the known & unknown threats would be disappointed to read the following story::

here's a "NEWS flash"- Anti-virus programs not perfect. Oh wait a second... that's not news at all...

Quote from: kpac on August 16, 2010, 02:48:34 PM
How ironic that clicking on that link makes avast pop-up telling me a trojan was found on that page.

classic! It's not coming up anymore. Must have been an ad or something. Unusually though, I get the "Additional addons are required..." message and there is some kind of Java applet on the page also. I can't find it.Quote from: kpac on August 16, 2010, 04:29:03 PM
It's not coming up anymore. Must have been an ad or something. Unusually though, I get the "Additional addons are required..." message and there is some kind of Java applet on the page also. I can't find it.

lol... it has some ridiculous toolbar on the BOTTOM, as well. I recognize it- it's the "skysa toolbar" (http://www.skysa.com/)

the toolbar itself isn't bad, it's just totally out of context on a ALLEGED news site. To make things better, it wasn't there a half hour ago when I first visited the link.When I clicked on the link, Windows MediaPlayer opened and tried to play something. Then my MicroSoft Security Essentials popped up saying there was an infection and had to clean it. I removed the link.Hey Guys!

Hold on..Iam not trying to play any 'Gimmick' over here.

Its serious.

Check it out:::

Link removed by Allan

Trend Micro disappointed Indian Ministry of Home affairs.Quote from: Saurabhdua on August 17, 2010, 06:58:10 AM
Hey Guys!


Trend Micro disappointed Indian Ministry of Home affairs.
Well, that's certainly good enough for me No-one said you were playing any "gimmick". The link was removed because something on the page alerted multiple anti-virus clients. Why post it again?
4753.

Solve : hjt log?

Answer»

hjt says i have no anti-virus but i have m s essentials


Logfile of Trend Micro HIJACKTHIS v2.0.4
Scan saved at 22:05:16, on 15/08/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
E:\Program Files\WhatPulse\WhatPulse.exe
C:\[emailprotected]\[emailprotected]\[emailprotected]
C:\[emailprotected]\[emailprotected]\FahCore_b4.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Secunia\PSI\psi.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\harry\Desktop\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SEARCH Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files (x86)\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WhatPulse] E:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: [emailprotected] - Shortcut.lnk = C:\[emailprotected]\[emailprotected]\[emailprotected]
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file MISSING)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 8603 bytes


[recovering disk space - old attachment deleted by admin]Harry. Your HJT log looks good except that it's running from the wrong place. It should be in Program Files. What problems are you having?i found hjt in downloads , i had prolems getting it to run and i found that i had to run it as administrator , so i ran a scan and seen all at the bottom

( files missing ) and thought it was a problem , so they must be ok then to leave in , will i drag it into programs , harryHijackThis will show a lot of (file missing) entries on 64 bit machines because the 64 bit OS stores files in different locations to 32 bit.Quote from: kpac on August 17, 2010, 12:29:09 PM

HijackThis will show a lot of (file missing) entries on 64 bit machines because the 64 bit OS stores files in different locations to 32 bit.

ok , so there is nothing missing then , would it have anything to do with me having my new and old hard drives installed and i moved stuff from the old one to the new one , hope i said that right No. 64 bit machines produce logs like that. ok dave , last question should i drag hjt from downloads into programsQuote from: http://www.theeldergeek.com/forum/index.php?showtopic=13415
Note for 64-bit system users: Anti-malware scanners and some specialized fix tools have problems enumerating the drivers and services on 64-bit machines so they do not always work properly. Microsoft created a new folder (C:\Windows\SysWOW64) that contains all the 32-bit .dll files required for compatibility which run on top of the 64-bit version of Windows. WOW64 is the x86 emulator that allows 32-bit Windows-based applications to run on 64-bit Windows but x86 applications are re-directed to the x86 \syswow64 when seeking the x64 \system32. For a more detailed explanation, please refer to Making the Move to x64: File System Redirection and WOW64 Implementation Details. Since this is the case, be aware that most of the tools we use for malware removal are designed for 32-bit systems and do not work or can give misleading results on 64-bit machines. For instance, running HijackThis on a 64-bit machine may show log entries which indicate indicate (file missing) when that is NOT always the case. As such, any assistance we can offer is limited at this time and there is no guarantee all types of infections can be completely removed.
thanks kpac that explains it to me , although i may not FULLY understand it so i'll leave THINGS as is , harry

and thank you to dave also , harry
4754.

Solve : I have a very different problem with Security Suite virus removal, need help?

Answer»

Hi,

I have Vista and I got the virus when I went to the MLB.com website, at least that's whenmy computer when carzy. I got the blue screen of death 2 times , once almost immediately and then a second time whe I restarted the computer, not knowing what I had yet. I got the basci security suite main screen telling me I had tons of virues, which i figured out fairly quickly it was a scam virus. I went to Bleeping computer and several other forums and site in safe mode and on my laptop, to get some answers.

Everyone says that you need to go into the Internet options and turn on the proxy settings, but with me it's the opposite. My proxy settings were checked and when checked I cannot access the Internet. when I uncheck them I can get online no problem.

Also, in Safe mode, I am still getting redirected to other sites (which I somehow got a couple of weeks ago and can't seem to get rid of), but also when I first signed on in safe mode I opened up the help for IE8. Now whenever I do anything in safe mode, like open IE, or even trying to open RKill.com, the window for that exact hlep pops up, every time. I cannot run rkill as it closes and reports after 1 second. On the bleeping computer site they say to keep clicking until it cathes, but I have clicked it over 200 times and nothing will stay open to run. I have run malware in safde mode, and hijack this, trojen removal, AVG, and DONE everything I can from every forum I can find.

My problenm doesn't seem to match up with everyone elses. I would appreciate any help I can get here.

I have a working knowledge of computers, so I can do whatever I am told to do, I just don't know what to delete unless I am told to now.

Thanks for any help
BillScratch this question......I actually had read a forum wrong and I didn't have a different problem, especially with the proxy button in the LAN settings under connection in internet options. Not a big deal, but wanted to clear that up.

I actually got rid of the Security suite virus by following the soft sailor directions and doing a few other things I saw on this forum, deleting some things from the registry like Tkbell and the proxy with 127.0.0.1=xxxx it was not the exact NUMBER most forums list in the xxxx area, but I knew it was bad. I googled every odd looking registry entry from hijack this and found good quality answers for each entry. Deleting the bad ones worked for me.

This was much easier than I expected when combining information from this site and bleeping computer and soft sailor. All these guy and gals are great for what they post to help, I thank them all

I managed to do this a strange way but it worked and my system is holding NICELY now. I think I cleaned everything on my computer, but in the end it was worth it, good luck to allok and good luck , but be careful what you delete

4755.

Solve : Verifation Words Do Not Show?

Answer»

First, I said Java was enabled. I do not know about JAVASCRIPT or how to find out.

When I pinged the address you gave me, it was very hard to read the results. After about 4 pings, I was able to make out 4 replies, I think. There was a lot of copy that followed, but it STAYED up for only a microsecond before closing.

Sorry I'm so dumb on this.
GQuote from: oleger on August 14, 2010, 01:34:34 PM

First, I said Java was enabled. I do not know about Javascript or how to find out.

Tools->Options, Content "tab". There is a checkbox, Third from the top, labelled "Enable javascript". Make sure it's checked. Thanks for the extra guidance. Javascript is and was enabled.

Are you out of ideas? Anybody?I'm wondering if you have any adblock software / plugin or addon installed?

And also you might want to SEE if booting to safe mode (Book to Safe mode with networking to get internet in safe mode) and then retrying the sites again ... don't know if that does any good? ... if it works, something is not right in normal mode.Sorry, I thanked you but forgot to reply due to an interuption, then thought I HAD replied. Senior MOMENT!

I have no adblock software added that I know of. I also have run Malwarebyte with no results.

When I get a chance, I will TRY safe mode. I am not sure how to get online using Safe Mode though.
Gplease read this link from Microsoft on how to get to safe mode.

then click the safemode with networking on the menu that comes up to enable internet in safe mode and try going on internet like normal.
4756.

Solve : Windows XP - in Costa Rica & stumped?

Answer»

Awesome - thanks again. I will post the hijack log in a couple of hours.Ok - I have been unable to get either of the scans to complete. Both just pause, the timer continues to count down, but the scanning stops.

Also - the Super Anti Spyware does not start when windows starts; it is set to, but it does not.

And - Windows in non-safe mode will not boot, it just re-boots. This seemed to start after Super Anti spyware was installed.

Any suggestions?Please uninstall SAS and see if will reboot normally. Please run MBAM either in safe mode.I was trying to run both of the scans in safe mode.

Now - when I try to boot in non-safe mode, Windows says that the OS needs to be authenticated.

Also - I can only run MBAM one time - if I try to run a second time I get two VBS errors and it stops running. I have to uninstall and then re-install in order to get it to run the scan again.

Nasty piece of work whatever this is. Please try this even though your XP CD is at home. If it finds a bad file it will ask for the CD. At least we'll narrow it down.

•Click on Start > Run and type sfc /SCANNOW then press Enter (note the space between scf and /scannow)
*Let this run undisturbed until the window with the blue PROGRESS bar goes away
SFC - Which stands for System File Checker, retrieves the CORRECT version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.Hello Dave,

In the interim I downloaded xp via the technet subscription. The file is an iso - do you happen to know off hand how I can get this to usb? Thanks.Quote

do you happen to know off hand how I can get this to usb? Thanks.
Please go to Reply #4 and follow the link. It will tell you how to burn an ISO file to CD or USB.I tried using that and it didn't work... I assumed it was because it was a linux boot?

Any additional suggestions?Also - I narrowed the COMP freezes down to pressing anything on the keyboard. I cannot run the scan.This sounds more like a problem with the laptop. Is it possible to try another USB keyboard on the laptop?

Not at the moment.

But the linux usb boot from reply number 4 worked fine - i.e., I was able to boot, scan, type, etc.

Should I be able to use the linux usb boot for a windows cd? Let's try this.

We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

Download the OTLPE Standard REATOGO Windows Recovery Environment.
  • Place a blank CD-R disc in to your CD burning drive.
  • Download OTLPEStd.exe and double-click on it to burn to a CD using ISO Burner.
  • Reboot your system using the boot CD you just created.

Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
  • Change Drivers to Non-Microsoft
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\_OTL\MovedFiles
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the OTL.txt file in your reply.
Hi Dave,

Given the laptop is a mini, I don't have a cd available.

But - on the last day of the trip here, so will be back home quick enough and I should be able to get things going from home. If not, I will let you know.

Thanks for all the help!
4757.

Solve : Malware Problem?

Answer»

my laptop has been INFECTED with malware before. All kinds of fake antivirus alerts POPUP and whenever I try to run malwarebytes the infamous "application cannot be executed" box pops up. I have been able to remove it before by running malwarebytes in safemode but I ran a full scan twice in safe mode last NIGHT and nothing came up, so I have no idea what to do. Any HELP is appreciated.anyone? give this link a read.

4758.

Solve : Malwarebytes Activates Shuriken Heuristics Module?

Answer» MALWAREBYTES ACTIVATES Shuriken HEURISTICS Module:
HTTP://forums.malwarebytes.org/index.php?showtopic=59510
4759.

Solve : Please Help.... Malware Bytes won't open and Security Suite has hijacked me.?

Answer»

Hi I have never heard of Security SUITE before but now when I try and run Malware bytes it pops up, and it ALSO says MBAM is infected and can not run.
I have never had a problem with malware bytes before please help me, I am sure I have a virus but I can't use my MBAM or Super Anti SPYWARE...

PLEASE HELP MEtry booting to safe mode and then reattempt your malwarebtes and super antispyware scans. Hopefully they get thru this time so you can post your logs for a malware specialist to look at.Well I have TRIED running Malwarebytes in safe mode and also spyware cease.... it gets to a certain point and then turns off the laptop.
Please help I am freaking out!!!P.S out of 13000 items scanned malwarebytes is saying I have 131 infected files Alright it seems to not be turning off this time.
I am still running Malwarebytes and it has detected 160 infected files... It has scanned 28000 now.
I will post the log if it finishes succesfully.
Thanks in advance everyone

4760.

Solve : Witch is the best anti virus??

Answer»

I uses internet daily for my online business.But i had faced many TIME viruses witch disturb my computer and also my business.Can any body tell me some good anti virus? If you do a search on this site you'll find dozens of threads asking the same question. I'm sure some of those will provide the answers you are looking for.
Or wait a few DAYS, this question gets asked once a week. We COULD provide a list a page long, but the answer will always come down to personal preference.

Try GOOGLING the questionQuote from: businessman1927 on August 19, 2010, 05:18:15 AM

witch disturb my computer

I always hate it when a "Witch" disturbs my computer.Latest AV Review and Certification Report 2010. Top Internet Securities are: AVG Internet Security 9.0, Norton Internet Securtiy 2010, Kaspersky Internet Security 2010, Panda Internet security 2010 and BITDEFENDER 2010.
4761.

Solve : "An Installer Wants to Run" when I press remove?

Answer»

Thanks, Dave.
I'm afraid I've got a problem with the Secunia Software Inspector. It says a software requirement is SunJava JRE 6.21 and won't run without it, but after downloading that from Java.com and trying to install it, a box came up with "Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run." I gave it a break and tried again with the same result.
After that, the computer froze for a while and when I tried to close down and disconnect, it wouldn't. I tried to turn off from Start and after several TRIES the 'Do you want to turn off... you will lose everything not SAVED' message came up. When I pressed yes, the logging off screen came up about 1/8" normal size - but at least it shut down. Quote

but at least it shut down.
I'm assuming it started correctly and is running well?

Quote
I'm afraid I've got a problem with the Secunia Software Inspector.
Don't worry about this. It must be conflicting with some other program. I would say that we have all the essential programs on your computer up-to-date. BTW, Java updated to 21 today so you probably already have that updated.Thanks for all your HELP SuperDave, it's GREAT to know I'm safe now.

You guys deserve top marks for helping us nerds out!!
4762.

Solve : Somebady used my Hotmail Account to spam??

Answer»

My wife has had some one use her email to spam her entire address book. It seems like they used her web based email to do this, but I am not sure. I have Norton Internet Security 2010 and it did not find ANYTHING during its full SYSTEM scan. I also scanned with Malware bytes, and SuperAntiSpyware free edition using the preferences mention in this FORUM. All these programs uncovered were tracking cookies. Should I be worried about my Windows Live email client or is this a web based email issue. What measures should I take to ensure this doesn't happen again.a FRIEND had the same problem i did all the scans for her and i was told all you can do is change the e-mail NAME

e.g + another to a.n.other

4763.

Solve : new uknown virus hit me.?

Answer»

here you go.

[recovering disk space - old attachment deleted by admin]As near as I can tell from the limited number of tools your computer will allow me to use your computer is clean. Are you still having problems?

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp BUTTON.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

================================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

======================================

I'm not sure if any of these tools will work on your computer but it's worth a try.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything LISTED.
.
----------

Go to Microsoft Windows Update and GET all critical updates.

----------

I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your BROWSER. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!As I told you man, ramnit a and ramnit.b viruses are still on my computer.


Whenever I access the infected file, it goes to another file and infects it. Please run another scan with HJT and post the log.
4764.

Solve : can't remove symantec antivirus?

Answer»

I just registered my avast antivirus protection, and the first thing it said to do was remove symantec antivirus from my computer because it is corrupted. after searching the internet and numerous attempts at differnt soulutions i am STILL stuck. please help.
Try this

http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN&ln=en_USI already have. when i tried to remove it with that program it said that i had to use add/remove, which i have tried also. i don't have a password and i have already tried symantec as the defalt password. this symantec antivirus program has a VIRUS in it and it keeps loading bogus antispy and malware programs onto my computer.Please try this to see if HJT can see it and remove it.

Please download: HiJackThis to your Desktop.

  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will INSTALL to: C:\Program Files\Trend Micro\HijackThis
  • Accept the license agreement.

Delete An Uninstall Entry

•Start HijackThis

•Click on the Open the Misc Tools section

•Click on the Open Uninstall Manager button.

•Highlight the entry you want to remove.
•Click Delete this entry
4765.

Solve : "Application can not be executed. The file .exe is infected"?

Answer»

Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:
•Click on Start > Run and type sfc /scannow then press ENTER (note the space between scf and /scannow)
*Let this run undisturbed until the window with the blue progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.I put in the CD, but I didn't get the option to click start. Immediately it ran the CD and went to the Windows setup.
The options are: Setup Windows XP now, repair using recovery console, or quit setup.

I'll leave this screen alone until prompted any further.Use the Recovery Console. You won't loose any data.Everything works great now! Thanks SuperDave, you were a tremendous help.What programs would you recommend I get so the same thing doesn't happen again? If your computer is booting in Normal Mode please do as instructed in Reply # 13

Quote

What programs would you recommend I get so the same thing doesn't happen again?
I will recommend some programs once I'm convinced that your computer is clean.I did the steps you mentioned, but I kept getting an error message, so I asked to ONE of the teachers in the IT department at my college what to do. He said it's best if I a clean install, so that's what I did. SuperDave I apologize for doing that after all the hard work you put towards helping me and I really thank you for that. I am just not sure which programs are best download. I've tried looking, but there's so many out there I am not sure which to get. The only thing I have downloaded so far is Avira AntiVir.I hope you didn't loose any data.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box NEXT to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to PROTECT your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!A majority of what was on my computer was music and movies. It's nothing I can't get back.
Thanks SuperDave for all the information on the software. I got all of them and they work great, but I do have one question. I don't know if you can answer it though. It deals with the Windows Update. I tried downloading the most recent Windows Update, but when I do my computer keeps restarting. In order to get my computer to startup properly I need to press F8 to go into the settings and choose "Last known good configuration." I'm not sure if I should skip it because of that, or download it anyway and try and find out what could be wrong.Perhaps you should post this question in our software forum. I'm sure someone can help you there.
4766.

Solve : File xxx.exe is infected?

Answer»

Hello,

My desktop computer was hit with a virus of some sort that blows pop ups left and right saying "the file (insertname).exe is infected would you like to activate your anti virus? "

They are blocking everything so I cannot open the web, any software or task manager. I have researched and tried to see if I can do anything but everything I have found has stated that I need to download this or that and I cannot open anything on that PC (on laptop now)

The PC is a

eMachine
model: et1161-07
os: Vista 32 bit
Processor : amd athelon dual core 4050e 2.10 ghz
Ram : 3g
Memory : 300g

What can I do?What are your current Antivirus? Antispyware? Firewall? Read this before requesting malware removal helpHello and welcome to Computer HOPE Forum. My name is Dave. Sorry for being so late. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or SCANS while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and TRANSFER any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

Please go into Safe Mode and run MBAM. Then reboot into Normal mode and run the other scans, if you can.
Here's how to get into Safe Mode.

Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be PROMPTED to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the ENTIRE report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

====================================

SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.

==============================

Please download: HiJackThis to your Desktop.
  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
  • Accept the license agreement.
  • Click the Open the Misc Tools section button.
  • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
  • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
  • Please post the log in your next reply.
4767.

Solve : Sleep Mode + Crash...HELPPP?

Answer»

Hy guys..
Sorry if I'm posting in the wrong place but I don't have much time..
My pc just goes intro sleep mode and I can't get it back on...
Or it crashes, meaning the image TURNS the color of the taskbar (the hole desktop image) and I can't do nothing, music STOPS, everything stops...
Pleaseeee help me.
My STAND by and hibernate modes are turned off...
please help meh

4768.

Solve : Infected??

Answer»

I have a windows 7 computer. Recently I downloaded a PROGRAM, shut down my computer, turned it on, and after the loading screen, a blank black screen. I couldn't even get into safe mode by pressing F8. What can I do? I'll appreciate it. Thank you.

This is meaning that I have no access to my desktop, cmd prompt, or safe mode.

The program that I downloaded was a PRINTER driver update from the HP website. I always make SURE the SITE is trusted before downloading anything.We are sorry for being so late in getting to your thread. Everyone is so busy. Do you still NEED help?

4769.

Solve : blocked from uploading my photos onto an email?

Answer»

Hi ,
I have a Toshiba laptop.
Recently Hotmail updated their layout and suddenly I can't upload photos from my pc onto an email.
If I click 'attachments' it appears to make them too big, and if I click photos-then compressed photos, up comes the familiar layout and I click each pic or 'select all' ...but then it goes ping when I click on 'Upload now' and does nothing...
Frustrating and bewildering.

There is a banner that comes up saying:
Internet explorer has blocked this site from using an Activex control in an unsafe manner. As a result, this page might not DISPLAY correctly.

I have updated my anti-virus and switched pc off... this problem has been with me for several days. (maybe even longer without me being aware of it)

Can you help please

What windows are you using? What IE version are you using?Hello, thanks for replying.

I am on windows vista home premium.
I cannot figure out how to find my IE as I am a total novice and can't understand the terms and technicalities.
Sorry to be such a duffer. hi julia,

welcome to the world of computers. i hope you'll like it here.

I hope this is not too technical for you and you can do it:

Quote

In the Browser Toolbar:
Tools -> Internet Options -> choose the Security tab
Click the Custom Level button
Enable the following settings:
Run ActiveX controls and plug-ins
Initialize and script ActiveX control not marked as safe.

Also, to find out your Internet explorer version,

Quote
To find out which version of Internet Explorer you're using, the cipher strength (SSL) it is using, the product identification number, or to see when the latest update was applied, follow these steps.

Open Internet Explorer by clicking the Start button , and then clicking Internet Explorer.

Press ALT+H, and then click About Internet Explorer.

Or you just Quote
go to the tools --> click on help --> about Internet Explorer

(I'm assuming that's what you meant when you said you can'f find your IE?)

after doing ONE of these (depends on what version IE you have), a box should appear with version number. Good to know the version number of your browser (program you use to go onto hotmail and other sites) you use so people can help you out faster with your browser problems.

Hopefully this WOULD help you with your problem If not, just holler back and we'll help you out some more



Hello,
Thank you for the info. I apologise for the time lapse... I am in France, so six hours ahead of you (if you are over the pond)... also, I have been struggling to understand what you told me to do!

I FOLLOWED the instructions (or thought I did) but got nowhere and was going to write to you for more help tonight, when a friend wandered in who is a bit more computer savvy than I.

I showed him your post and he was able to do something (I still don't know what) by following your lead.
The upshot is I can now send my photos, but a box does POP up warning me it might be dodgy... but as I know the sender (me) I took the chance, and will put up with the box.

Unfortunately I still don't know the version number of my browser... but hopefully, when the friend comes round again I can ask him.
I would like to thank you warmly for your help... and say that I will indeed 'holler back' if I get stuck again.
Best wishes from France.
Julia
4770.

Solve : Can't Use Google?

Answer»

First, I apologize if this topic is already in the Forum. Because of this PROBLEM, I cannot use the Forum Search function. Here's the problem.

Whenever I try to use Google, I watch a blank screen for minutes, then I get a "...timed out" intercept. I tried to flush the DNS (maybe not the right initials) and it will not flush. If I use the numerical address (66.102.7.104) I get the Google site, but, then, get the timed out thing when I try to search. It MAY sound like I know a lot, but all of the above was done via my ISP Customer SERVICE who went beyond what they normally would do, but had to GIVE up.

Sound familiar to anybody?
GerryJust want to add some info. I noticed today that Search.yahoo.com will not download either.

4771.

Solve : Destop icons dead / Desktop Security 2010?

Answer»

What happens when you CREATE a new icon for ex. SI.Com-Golf?They don't work.
A Firefox shortcut COPIED to the desktop will not work.
System tray internet shortcuts don't work either.
Any non internet shortcut desktop icon will work.
IE favorites don't work. An IE favorite copied to the desktop does not work.
Links in email (Outlook Express 6) do not work.It works for me. When I was on a site I went to File, Send to, shortcut to desktop. Try it and see if it will work.
I don't believe that this problem with the icons are caused by MALWARE. Perhaps, you should start a new thread in one of the software forums on this site.Well of course it works for you!

I am 99% sure this problem was caused by the Desktop Security malware.

I will look elsewhere on this site for help.

Did you try creating a new icon to one of those sites you mentioned?Yes, I tried that too. It doesn't work.Could you please run ESET scan again and this time make sure that the "Remove Found threats" box is checked.Log below. Within ESET should I delete these files?

C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{1570271F-33DC-4C63-B828-70C579138C9A}\Microsoft\Outlook Express\Emails0106to1208.dbxWin32/Sober.O wormunable to clean
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{1570271F-33DC-4C63-B828-70C579138C9A}\Microsoft\Outlook Express\inboxcopy0407.dbxWin32/Sober.O wormunable to clean
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL.vira variant of Win32/Toolbar.MyWebSearch applicationcleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Installr\1.bin\NPFUNWEB.DLL.virWin32/Toolbar.MyWebSearch applicationcleaned by deleting - quarantined
C:\WINNT\Fonts\navdb.dbxIRC/Zcrew.A trojancleaned by deleting - quarantined
C:\WINNT\Fonts\nordb.dbxIRC/Zcrew.A trojancleaned by deleting - quarantined
C:\WINNT\system32\BNC.MRCprobably a variant of Win32/Randon.G1 wormcleaned by deleting - quarantined
Quote

Within ESET should I delete these files?
Yes, please delete these emails and run ESET again.By looking at the text this appears to be a file folder of emails spanning two years. "Emails0106to1208.dbx"
What are the odds deleting this folder will cure my problem?
I think very slim, since I have not even been in that folder for months.I cut the two file folders out and put them on a thumb drive.
I ran the full scan. Results were all zeros.
No change in the icon situation.This fixed it. From Elise the Romanian at MalwareBytes

Forum DEITY
******

Group: Experts
Posts: 1,846
Joined: 13-January 10
From: Home
Member No.: 29,666




Hello, lets attempt to repair your Internet shortcuts. Please make sure to do the following steps in the given order; if you encounter a problem at any point, just stop and post back here.

Warning: this fix is for this user only. Using this fix on another computer is at your own risk and can cause damage.

BACKUP THE REGISTRY
---------------------------
Backup Your Registry with ERUNT

* Please use the following link and scroll down to ERUNT and download it.
http://aumha.org/freeware/freeware.php
* For version with the Installer:
Use the setup program to install ERUNT on your computer
* For the zipped version:
Unzip all the files into a folder of your choice.

Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe


Click Start > Run, in the box that opens type notepad and press enter.
Copy/paste the text in the codebox below in Notepad and save it as fixme.bat to your desktop.
CODE
REGEDIT4

; @echo off
; regquery "HKEY_CLASSES_ROOT\InternetShortcut" >> export.txt
; REGEDIT.EXE /S "%~f0"
; start export.txt
; del %0

[-HKEY_CLASSES_ROOT\InternetShortcut]
Exit Notepad and double-click on fixme.bat to run it.

A textfile named export.txt should open. Please posts its contents in your next reply.


Open Internet Explorer, click the Tools menu, select Internet Options, Programs
Click "Reset Web Settings". Click Apply/OK to exit the internet options and verify if the desktop shortcuts work now (to be sure everything is in place, restart your browser after changing the settings).


--------------------
Regards,
Elise
4772.

Solve : Laptops keyboard doing funny things.?

Answer» RIGHT well my mums laptop which is a DELL went funny, she was sitting on the laptop, went outside for a wee while, heading over to her friends, leaving the laptop running. When she returned it had just randomly started doing funny things but only with the keyboard the rest of the computer is working fine. It does things for example.

When she presses 'A' it appears like QAZ and when she presses 'S' it comes up as WSX then that carries on until the letter G then the rest are working fine. Then numbers 1, 2, 3, 4, 7, 8 and 9. Don't work but 5 and 6 do. Backspace wont work.

Now i had suggest about factory restoring her computer, but she doesn't want to because of all the things she has on the computer, and she can't move them onto the portable hard drive because it asks for her password and she can't type it in because different letters pop up.

I also suggest maybe the cats where playing on the keyboard and ripped/broke some things or spilt something on it but she said the cats weren't in the room, as she locked them out.

Any suggestions of what could have gone wrong?Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the GUIDANCE of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not SOLVE other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, PLEASE don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

It sounds more like a hardware problem than an infection. Please try this. Plug a USB keyboard in and see if it works. If it does, that would mean a problem with the on-board keyboard. If the computer is not too old, it could be replaced under warranty. If it still does the same thing, try doing what I've outlined below.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.


Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
Save Rkill to your desktop.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator


You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.exe
* Rkill.com
* Rkill.scr
* Rkill.pif

Once you've gotten one of them to run then try to immediately run the following.
*******************************************

SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
************************************
Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
4773.

Solve : Application cannot be executed. The file wuauclt.exe is infected.?

Answer» SEEMS to be working very well right now. I can once again access internet and am no longer getting any of the pop-ups, etc.

Thanks for your helpcould i suggest you read and download this it will WARN you about untrusted web sites

http://www.mywot.com/en/download/ieSounds good. Let's do some cleanup.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

===================================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

==================================

Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and MALICIOUS intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block OUTGOING connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

=================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Just finished knocking out a majority of the items from your last post. Computer seems to be running great and I feel pretty good about going back to business on it. I plan to run through a bunch of the steps you have MENTIONED on some of my other computers to safeguard them.

Thanks!
4774.

Solve : uncontrollable scrolling - not the mouse -- is it a virus???

Answer»

Hoping that someone can help me with this -- for the PAST MONTH or so my Dell laptop has had a problem with UNCONTROLLABLE scrolling up and to the left. This is now getting worse and happens in all programs including Word, Adobe, all internet browsers, etc. Even to type this message is DIFFICULT because the cursor periodically jumps back to the top left corner of this text box. I have tried attaching a new external mouse but this does not help. The problem occurs even when not using the touchpad. I have scanned my computer with multiple anti-virus programs but no LUCK. It is getting difficult to use the computer for anything. Even holding the down / right arrows does not help. PLEASE ADVISE!!

4775.

Solve : Application cannot be executed. The file *** is infected?

Answer»

"I think I am near the end of the process but am after confirmation. Is there anything else I need to do, as the problem isn't resolved fully

Please note that no log came up with the CFScript however there was no log at the end. The first time it asked me to reboot the computer, the second time nothing really happened...

Thank you Hi.

Could you please run ComboFix again without doing the CFScript so I can be sure no malware remains in your logs.

Hi

I have tried your last instruction and could not get going so i did the following:

i have a log from ESET Nod32 Antivirus 4.2.58.3 - computer scan

it worked and found 6 THREATS..see below:Is what done ok or am i going backwards?

Scan Log
Version of virus signature database: 5353 (20100809)
Date: 10/08/2010 Time: 2:23:32 PM
Scanned disks, folders and files: Operating memory;C:\BOOT sector;D:\Boot sector;C:\:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC239.tmp - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC2B3.tmp - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC2FB.tmp - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC31B.tmp - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC357.tmp - error opening [4]
C:\found.000\dir0000.chk\Temp\~DFC37E.tmp - error opening [4]
C:\found.001\dir0000.chk\Microsoft\Windows Live Mail\Sentinel\WLMailSearchSentinel.eml » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\EnterWW.cab » CAB » PROCESS_LIBRARY.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\EnterWW.cab » CAB » HIRING_REQUISITION_CUSTOMIZED.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\EnterWW.cab » CAB » HIRING_REQUISITION.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\EnterWW.cab » CAB » TRACK_ISSUES.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{90120000-0030-0000-0000-0000000FF1CE}-C\EnterWW.cab » CAB » POLICIES.FDT » MIME - is OK (internal scanning not performed)
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » translations.Slovenian - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » translations.Spanish - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » translations.Swedish - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » translations.Vietnamese - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » welcome.dfm - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » wizard.dfm - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/hu/tab_2_on.png » 7ZIP » mMSIExec.dll - error - unknown compression method
C:\Preload\MSAPP\UNInstall\Microsoft Office Activation Assistant.exe » 7ZIP » data/OFFLINE/IFSECOTH07CRATATNABUDTTAEDFFFF0/el/resources.xml - error - unknown compression method
C:\Preload\NERO7962\Installation\Cab\0A72FAFE.cab » CAB » CDI_VCD335C15F1.CFG » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Cab\E4060BF5.cab » CAB » rootFEAA0A71.img » GZIP » - archive damaged
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.94516D55_6406_464D_ 9270_8D4D33342AE2 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.A1FFBB52_4F2E_44F1_ 8614_5D66C2EF43F0 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.03A77D79_488A_445D_ B528_0E0089E3FCB3 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D495C848_F235_46BF_ A9A0_77D7C2120E3B » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.445237FC_7259_4EAD_ ACEF_7ED7A95D32D7 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.79A89863_540B_470E_ 9C71_D57F22BFA44D » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.5ACB9F6A_C06C_4121_ B854_7133C2ED29A8 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.15989D71_6BEB_424A_ 88DF_78A882081F91 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.1C571119_9D2B_4542_ 84BD_0CD3AA24E739 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C4EB4D09_95BA_4DC2_ 9551_B6E637DA2230 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.BC3B29D8_FFCF_4BFA_ B238_F79FEAB1AF5E » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C39C5B26_ED03_4B04_ 9CFD_166FDC7523D1 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C05C46CB_E961_4BBA_ 86BE_4FE1A4426A32 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.87E45AFF_C0E7_4B6E_ 8E37_52EEB71BF5B7 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.E34CAC5A_4546_4E3A_ BFFA_CE28E0CED140 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.14AFC4D4_5454_4AD5_ B7FC_10D4FAB85CF3 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B4924446_617C_4229_ 8C33_089CD780544D » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.F02247A4_BA3B_4A1D_ B7EA_2CB2F17490B7 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.7E03236B_A15C_465D_ 8924_859B2954BFA2 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.0F75E4D6_4C58_47F6_ B626_BA408BA6F03B » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B3E4ACDE_961E_474B_ 87CC_22A67A5E77CB » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D8256176_51D5_41D4_ B965_C7B0BC9E4A27 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D073AD43_9C5B_4759_ A404_ED1717BEEAD7 » MIME - is OK (internal scanning not performed)
C:\Preload\NERO7962\Installation\Redist\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/deploy/ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.94516D55_6406_464D_ 9270_8D4D33342AE2 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.A1FFBB52_4F2E_44F1_ 8614_5D66C2EF43F0 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.03A77D79_488A_445D_ B528_0E0089E3FCB3 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D495C848_F235_46BF_ A9A0_77D7C2120E3B » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.445237FC_7259_4EAD_ ACEF_7ED7A95D32D7 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.79A89863_540B_470E_ 9C71_D57F22BFA44D » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.5ACB9F6A_C06C_4121_ B854_7133C2ED29A8 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.15989D71_6BEB_424A_ 88DF_78A882081F91 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.1C571119_9D2B_4542_ 84BD_0CD3AA24E739 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C4EB4D09_95BA_4DC2_ 9551_B6E637DA2230 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.BC3B29D8_FFCF_4BFA_ B238_F79FEAB1AF5E » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C39C5B26_ED03_4B04_ 9CFD_166FDC7523D1 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C05C46CB_E961_4BBA_ 86BE_4FE1A4426A32 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.87E45AFF_C0E7_4B6E_ 8E37_52EEB71BF5B7 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.E34CAC5A_4546_4E3A_ BFFA_CE28E0CED140 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.14AFC4D4_5454_4AD5_ B7FC_10D4FAB85CF3 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B4924446_617C_4229_ 8C33_089CD780544D » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.F02247A4_BA3B_4A1D_ B7EA_2CB2F17490B7 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.7E03236B_A15C_465D_ 8924_859B2954BFA2 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.0F75E4D6_4C58_47F6_ B626_BA408BA6F03B » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B3E4ACDE_961E_474B_ 87CC_22A67A5E77CB » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D8256176_51D5_41D4_ B965_C7B0BC9E4A27 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D073AD43_9C5B_4759_ A404_ED1717BEEAD7 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\LS_HSI.msi » MSI » Data1.cab » CAB » Getting_Started.mht » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\LightScribe\Content\Getting Started.mht » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\deploy\ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft CAPICOM 2.1.0.2\License\license.mht » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\Hiring Requisition - Customized.fdt » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\Hiring Requisition.fdt » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\POLICIES.FDT » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\Process Library.fdt » MIME - is OK (internal scanning not performed)
C:\Program Files\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\Track Issues.fdt » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\browser.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\comm.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\pippki.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\reporter.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\toolkit.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Nero\Nero 7\Core\CDI\CDI_VCD.CFG » MIME - is OK (internal scanning not performed)
C:\Program Files\RealVNC\VNC4\winvnc4.exe » ZIP » META-INF/ - archive damaged
C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe » NSIS - bad archive
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\212100a23b7da4d332372db72b457c92_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\53a0b9b51d2a4017299159b35ae880a7_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\87951249b624be272de202fdd3f83281_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8dc6fe1f893c797d3f6691c3adb20f4c_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\98de0aab982ac4799f8b0994dbfd3fe1_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a99969662aa5f8782fe0552e56d76337_1db7a67c-f4c3-4ae9-b98c-2bfaddf8fb48 - error opening [4]
C:\Qoobox\Quarantine\C\Windows\System32\ernel32.dll.vir - a variant of Win32/Kryptik.FIX trojan - cleaned by DELETING - quarantined [1]
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{6dd96b47-a076-11df-b400-8def87395994}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Sentinel\WLMailSearchSentinel.eml » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\05572417-0000002F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\0A6B5F8D-00000007.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\0C102FD4-00000049.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\0D25626B-00000017.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\0D957A9C-0000001D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\0D9A5B10-00000048.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\156E48A1-00000012.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\156F67A5-00000002.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\1A5543AB-00000024.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\1A926A0F-0000002D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\1C6D78FF-00000044.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\1E8E6DB4-00000038.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\201F6C51-0000000F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\20212694-00000030.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\229E2669-00000041.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\242120C4-0000003F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\28A855E5-0000000E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\2B617300-00000005.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\2BF42D8A-00000008.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\2CEF29CB-00000037.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\2FF1430F-00000042.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\33CA0850-00000027.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\34840B35-00000045.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\349214A0-00000046.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\35481B42-00000013.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\39211A47-00000026.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\3C3D715D-0000000B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\3C444E88-00000022.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\3D357033-0000000C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\3FD761EB-0000001B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\3FDA0AB2-00000011.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\44B01CCF-0000002A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\45F6339A-0000002E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\466F044A-0000004C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\47827F39-00000023.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\4B147892-0000000D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\4CCF396B-0000004B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\4E6321DE-0000000A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\504D1F06-00000001.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\53584E35-00000025.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\535E2785-0000003B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\53D90412-0000001A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\54362C34-00000018.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\558B5941-00000019.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\55DB715E-00000009.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\576B426B-0000004A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\58822B59-00000036.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\59360E4F-00000031.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\59AD7202-0000001E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\5EF017F8-00000015.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\5FBE71E6-00000028.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\63096287-0000002B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\63D22863-0000001F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\650D090F-00000010.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\65135347-0000001C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\66220C42-0000003A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\66A36482-00000004.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\68FA3168-00000040.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\697332B2-00000014.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\699F24B5-00000039.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6B387652-00000032.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6BC6400D-00000029.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6C2E0F0D-00000033.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6CD25D11-0000003C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6D5F0450-00000020.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6E5E50C8-00000006.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6F2A5A55-0000003E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\6F441BE6-00000043.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\71CF0CF2-00000035.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\72865517-00000016.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\72B8659C-00000047.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\73BB3E88-0000002C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\740214CD-00000021.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\792572EF-00000003.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\7B48517F-00000034.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a f63\7B8C0366-0000003D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\001266A0-00000024.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\025A6E9B-0000003C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\02BE3C80-00000044.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0507553E-00000018.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\056F5588-00000006.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0649276C-00000038.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\06692CFE-00000049.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\08463044-00000045.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\08961B29-00000009.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0A296100-0000003D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0AF90BB0-00000017.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0B766FB2-00000001.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\0D750C58-0000001F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\12134C70-00000016.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\12787D65-0000001D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1AF4737A-00000041.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1B6D294C-00000011.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1D320A91-0000000C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1EA17417-00000032.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1EBB2BCA-0000001B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\1FA86C4B-0000001C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\200611FC-00000010.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\22BB74E5-00000008.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\24DD68EF-0000000D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\25D16764-0000003A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\285A0C38-00000014.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\29EC7521-00000037.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\2DD934E8-0000003F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\2E4B53C7-00000036.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\2FD63A90-00000002.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\30B12846-00000004.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\31440086-00000040.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\337843A3-00000029.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\33FC675A-00000030.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\3A2878CD-00000005.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\3A821E4C-00000033.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\3FB669D2-0000002D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\40A91313-0000003E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\43B76367-00000020.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\43E24AA1-00000003.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4A605C46-00000028.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4AB220C4-0000004B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4B031E90-0000003B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4E5124DE-0000001A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4F960546-00000025.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\4FA03989-00000021.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\523676D5-0000000F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\53504180-00000035.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\542E5897-00000007.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\5C8B558D-0000002A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\5F2827F0-00000048.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\5F6C3532-00000027.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\63D45E90-00000019.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\64392939-0000002F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\65951BD2-00000047.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\68867A05-00000012.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\6AE2634E-00000023.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\6B7A013A-00000034.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\6DF35CEA-0000004A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\6F8158BD-00000031.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\6FC55703-0000002E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7082386D-00000043.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7128264D-00000042.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\730C245F-00000046.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\75475243-0000000E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\75E87BF5-0000000A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7A756A50-0000001E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7AF32F16-00000013.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7B0109B4-0000002C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7DE3770A-0000000B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7EC13A2C-00000022.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7F2B3A8C-00000026.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7F5D59EA-00000039.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7F896201-0000002B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\Microsoft a fce\7F8D5EF0-00000015.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\00032425-0000010D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0011004F-0000019B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\00B73614-00000106.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\010A18A3-00000157.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\01BA3B6A-000001E0.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\02624D77-0000013A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\02753356-000000E1.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\02CE49A2-00000124.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\03441DDE-00000161.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\04366436-000001B4.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\044A2BD9-00000213.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\044E5D71-000001FC.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\04684850-00000166.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0513242D-000000D4.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\051C76E4-000000F6.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\053938E3-000001FF.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\05BE6ED1-000000D7.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\05DF5944-00000130.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\060007BA-0000013D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\063F2631-000001A7.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\06CC5275-0000012E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\072E3986-000000DF.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\07AB4DA7-00000214.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\07C772BA-00000198.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\08F4424A-00000128.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\091A1ED6-00000165.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0A7F319F-000001D4.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0AC46A44-0000010B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0B1102C4-000001AA.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0B695752-00000105.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0B752EA1-00000126.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0BB3786C-0000016D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0BBD2544-00000221.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0BBD50CD-0000013B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0C7A37E9-0000020A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0CE20811-000000F0.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0CFC52DA-000001CB.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0DF35193-000000DA.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0E342A11-00000201.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0E713FEF-00000144.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0E7666C0-000000D0.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0E880B8A-000001A9.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0EC37664-00000132.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0EF40C7F-000000DB.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0EF6045F-00000193.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0F123105-000000D2.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0F545B7C-000001EC.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\0F996129-00000172.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\102F158E-000000CA.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\103C1590-00000162.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\10670DCC-0000015A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\12032ED2-00000190.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\12936064-0000017B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1410404B-000001FA.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\143F712A-00000182.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\15D70EC9-000000E0.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\16503669-00000178.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\16931FB9-00000175.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\16B82472-000000CF.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\16C31D29-000001B8.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\174F7183-00000210.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\176E4DF2-00000154.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\17783D1D-000001DA.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\17CD6389-000000FC.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\17FB7176-00000181.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\181942CA-000001D9.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\18406582-00000123.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\18826366-000000F3.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\192F6F1D-000001E2.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\19320DAC-000001A5.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\19AF0E0A-00000155.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1A2C6EBE-00000169.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1A3E6217-00000152.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1A631D4C-000001CC.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1A745919-00000101.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1A781BAC-000001A4.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1B233935-0000012B.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1B9969F6-000001ED.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1B9C6B5A-000001C9.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1C1C22CB-000001BB.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1CF37853-000001FE.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1D0A6C8A-000000E3.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1D125180-000001FD.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1D740726-000001EE.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1E065BB4-0000017E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1E8F2973-0000012F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1F2A13CD-0000021F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1F400F22-000000CC.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1F4C0F3E-00000216.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\1FED2AB4-0000016F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\202500A9-0000013F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\207756E5-0000012D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\211F5DF3-00000186.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\213813C1-0000011F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\222740D8-000000E9.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\23273776-000001CE.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\2333390F-0000018F.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\234311BD-000001D5.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\23EB4B97-00000167.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\248927CA-00000204.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\24DD7A74-000001E3.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\24DF418E-00000224.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\24E3484B-000000D6.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\261D4810-0000017A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\268D2B70-0000020E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\26A907E2-0000013C.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\27617541-0000021D.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\276373AC-0000010E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\27D63D1B-0000019A.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\27E15464-00000192.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\28526E00-00000225.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\28852CAE-00000200.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\28B833C2-000001EB.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\28C363F3-000001E9.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\295A07DA-0000018E.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\295F0195-000000FE.rss » MIME - is OK (internal scanning not performed)
C:\Users\scaturchio\AppData\Local\Microsoft\Windows Live Mail\Your Feeds\Microsoft Feeds\MSNBC News\29897Hi.

Please download ComboFix from BleepingComputer.com

Alternate link: GeeksToGo.com

Alternate link: Forospyware.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
  • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is INSTALLED. With malware INFECTIONS being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
4776.

Solve : File Association Error/.Exe Files Not Opening/"Open With" Message Boxes?

Answer»

In May or June of this year, my computer seemed to have GOTTEN a really bad bug. It ruined my desktop by hiding my icons away from me and I wasn't able to access a lot of things. After running some scans (Malewarebytes AntiMalware & SuperAntiSpyware), the virus seemed to have gone away; however, my computer had another issue.

It seems as if my .exe files are not opening correctly. Every time I click on a program on the desktop (such as Microsoft Word or WordPerfect), it gives me the place where the program is located and it SAYS "Application Not Found." I found a way to OPEN my writing programs by opening up Start>My Documents>Document Name, but it is still a problem because it asks for me to "choose the program you want to use to open the FILE" every time I want to access anything such as the internet, paint, etc.

I was wondering if there was a way to FIX this issue. I've looked online for help and I was wondering if this: http://www.winhelponline.com/articles/105/1/File-association-fixes-for-Windows-Vista.html
would be of any use?

Thanks for your time.

4777.

Solve : Laptop won't boot in normal mode?

Answer»

Hey guys, looking for some help here.
As you can tell from the heading, my girlfriends laptop isn't booting in normal mode. Im pretty certain its due to a virus that has done damage or may still be present somewhere on the computer. It was one of the viruses that acts as an anti-virus trying to get you to pay money to download it and fix it.
I'v tried so many DIFFERENT things (scans with mbam,avast,ccleaner,spybot,esetcleaner,sdfix) but nothing has worked so far. I'v tried using system restore but it came back, and now system restore wont work for me when I try to reboot to an earlier state.
Anyone have any idea how to help? I dont have the windows xp cd here to upload it again, which doesnt help me at all.

Thanks in advance.
Can you boot in Safe Mode (by repeatedly pressing F8 before As you boot up), then run scans in Safe Mode.

Or maybe try 'Last Known Good Configuration' firstsorry, i should have mentioned that i tried those. Have done multiple scans today,usually something is picked up and delEted but doesnt seem to fix the problem.
Using last know good configuration doesnt seem to work at all.
and posting the question in 2 different PLACES doesn't MAKE it any easier, especially because if i'd read the other posts you've received, i wouldn't have bothered with mine. Somebody else is looking after you sufficientlySingleTwin: the malware specialists are GOING to need the logs from the THREAD you were linked to in your other thread. Follow the guide here.

The malware expert(s) are going to need at the least the hijackthis log and MBAM log. Post them in a reply here, then have patience, a malware expert should get around to this thread in a day or two

4778.

Solve : Removal of malware.?

Answer»

I am new to using a computer. In ORDER to REMOVE malware accquired by using the internet, can I learn to do this in a fairly shsort time, or do I need to use a computer support COMPANY?Since you are new to computers you will probably have to STUDY for over two years. I've been studying for over 3 years. There is a LOT of information to learn.

4779.

Solve : seeing log of computer?

Answer» HI FRIENDS,

I have a child.he uses computer.I would like to check all the pages he open as well as see his massageing on yahoo messanger.He delete all histories in INTERNET option after each session.Please advice.
Try this

http://download.cnet.com/McGruff-SafeGuard/3000-2162_4-10867757.htmlsina , i had something like that in my PC when the grand daughter lived here she was 14 to 16 , you might be in for a few SHOCKS if your son is a teenager but i felt it was needed at the time
4780.

Solve : iexplore.exe - Application Error?

Answer»

I did a repair of XP and then scanned with ESET online scan.
Here is the log from it.

C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\winlogon.exe.virWin32/Bamital.DX trojandeleted - quarantined

It seems to be runnig fine.
Thank youGood job!


If there are no more malware issues we can finish up now.


Let's clear out the programs we've been USING to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.

* Click START then RUN
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter.

The above procedure will:
* Delete: ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Secunia Software Inspector to check for out of date software.

* Click Start Scanner
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* UPDATE anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I also suggest keeping CCleaner Slim. It is an excellent and safe disk cleaner. Running CCleaner on a daily basis helps to protect your privacy and make your computer faster and more secure.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, SPAM, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy.
* Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

4781.

Solve : Rogue Antivirus only affecting one user!?

Answer»

I've been asked by a friend to fix their virus problem and after looking at their computer it showed they had 3 anti-virus programmes INSTALLED PLUS My Security SHIELD and still had a good few infections. Having never heard of My Security Shield I Googled it, and every page said it was malicious and suggested programmes to download to get rid of it. Seeing as it was not my computer, I was not going to pay for any software (any link given would have scanned the computer and just shown me what was INFECTED & then REQUEST me to pay for it to actually remove anything).

The processes and registry keys given to remove it manually were not actually on the computer and the other users on the computer could not find anything if it was searched for. I'm thinking the easiest thing to do is just delete this user! But I'm still puzzled as to why it was only one user affected!

Has any one had any experience of a rogue antivirus programme affecting just the one user on a computer?Quote

and every page said it was malicious and suggested programmes to download to get rid of it. Seeing as it was not my computer, I was not going to pay for any software (any link given would have scanned the computer and just shown me what was infected & then request me to pay for it to actually remove anything)
These are CONSIDERED rogue antivirus software. Rogue antivirus software are scam programs that allow you to do a scan, it will show fake results of non-existent viruses on your computer, then tell you to pay to remove them.

It was probably not active on the other accounts on the computer.

Do you need help disinfecting that computer?Yes, I do know it was rogue antivirus! No, I dont need help removing it!
I was only asking people's opinion about it only affecting the one user!
4782.

Solve : Blue Screen of Death following virus, unable to boot in safe mode?

Answer»

Hi all,

My computer with Windows XP became infected with the "Security Suite" virus, which I managed to remove (I think) using Malwares and AVG FREE. After my computer became infected when I already had AVG Free anti-virus I decided to change to Avast. Whilst my computer was installing Avast it turned off. When I restarted it, it opened and I saw the BSOD before it quickly restarted itself. I did as it SAID and started it in safe mode, again the BSOD, and if I don't get that the computer turns itself off in safe mode. If it doesn't turn off it just keeps going in a cycle restarting itself, getting to the BSOD and then restarting. I don't have time to read the errors on the BSOD before it restarts.. plus my MACHINE is in French so it takes me awhile to translate into English in my head!

Is there anything I can do?

Thanks in advance for your help,

Kim
Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

*****************************************
Do you have your OS CD?
You could try this but from what you're telling us is that it's not working.

We Need to Diagnose Your BlueScreen
1.When you boot your machine, press F8 to list the STARTUP options, exactly as you would if you were trying to enter Safe Mode
2.Select "Disable Automatic Restart on System Failure", as shown here:


3.When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:


Hi Dave,

Thank you for your help. I didn't get a chance to see your message again before I turned on my computer today. When I turned on my computer today the BSOD had disappeared and I've not seen it since?! While it was not there I took the opportunity to run my antivirus and malware which picked up and quarantined lots of infections. One of which it couldn't delete (and I can't either) a file called lluzdzlq.dat although it says it was created in 2004 (and I've not even had this computer that long). I also backed up all my data. Windows however told me that "it had encountered a serious problem.." and my computer is unusually slow. Even the internet is really really slow with both firefox and IE and I have a reasonably good internet connection. Is there anything else you'd recommend I do? I do have the windows OS cd's available to me if I need.

Kind regards,

KimSUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
*********************************
Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
**************************************
Please download: HiJackThis to your Desktop.
  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
  • Accept the license agreement.
  • Click the Open the Misc Tools section button.
  • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
  • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
  • Please post the log in your next reply.
*************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.Thanks Dave.

Attached are the logs of the scans. The security check "checkup.txt" was without an internet connection, and "checkup2.txt" I was connected to the secured university WIFI. I wasn't at home where I use my internet the most, and I also have a secured WIFI connection there.

[recovering disk space - old attachment deleted by admin]Here is the other log.

Also, malwarebytes still couldn't delete one of the files.

Cheers,

Kim

[recovering disk space - old attachment deleted by admin]Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.
4. Run CCleaner.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

***********************************
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.
*********************************
Download ComboFix by sUBs from one of the below links.

Important! You MUST save ComboFix to your desktop

link # 1
Link # 2

Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click on ComboFix.exe & follow the prompts.

Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

When the scan completes it will open a text window.

Post the contents of that log in your next reply.

Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.Thanks Dave,

Attached is the log of the Combofix, let me know if you need any translation - I realise that the headings maybe in French.

Through reading this forum I've come to realise that the windows firewall is not enough, what firewall would you recommend?

Cheers,

Kim

[recovering disk space - old attachment deleted by admin]Quote
Attached is the log of the Combofix, let me know if you need any translation - I realise that the headings maybe in French.
Not a problem. I live in a city that is 70% french.

Quote
Through reading this forum I've come to realise that the windows firewall is not enough, what firewall would you recommend?
We'll deal with that issue when the computer is clean.

***************************************
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    DirLook::
    c:\windows\system32\NtmsData

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:6522

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
********************************
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
4783.

Solve : How to stop receiving the same message?

Answer»

I keep receiving the same email from the person that used to be in my contact LIST. (i used hotmail).
She informed me that she no longer uses this email (ALSO hotmail). I have blocked this email address, but still keep receiving EMAILS from this address every day promoting some STORE.
Could someone explain to me why it happens? and how should i stop receiving these emails?

many thanks
Their account has probably been HACKED. It is probably sending you emails to spam your inbox.

4784.

Solve : Unable to access removable Storage Devices?

Answer» THANK You. overthehill
4785.

Solve : Free Firrewall?????

Answer»

It seems my subscription to mcaffee is going to run out and I don't want to renew it though it has served me well. I've heard great comments about AVAST and the fact that it is free is very appealing, but it has no firewall. I was just wondering if any one knows of a good FREE firewall out here on the web or has any reccomendations THX.I don't use 3rd party FIREWALLS on any systems, but I've always heard good things about comodo and zonealarm.use the windows firewall its good and also windows security ESSENTIALS from microsoft downloads
Online Armor has always worked for meFirewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only INSTALL ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing CONNECTIONS. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.Thank yous very much I now have DIRECTION

4786.

Solve : Looking for some help?

Answer»

Try not entering anything when it asks for a password. Ok, that worked.

Now what do I type in. It gives me this:

C"/WINDOWS>Please try it again. After you get by the password box, you should get this:
To set up windows xp now, press enter.

To repair a windows xp installation using recovery console, press R.

To quit setup without installing windows xp, press f3.
Press R for repair.I am there. Which one should I pick. And what happens after that.
Thank you.
Choose R for repair and it will repair anything in your OS that needs repairing but all your data will remain intact.Ok, I get to this screen:

To set up windows xp now, press enter.

To repair a windows xp installation using recovery console, press R.

To quit setup without installing windows xp, press f3.

I Pressed R for repair and I get this screen:

Microsoft windows xp(tm) recovery console.
The recovery console provides system repair and recovery functionality.
Type exit to quit the recovery console and restart the computer.

1: C:/windows

Which windows installation would you like to log onto
(to CANCEL, press enter)?

I pressed 1 and enter at this point I pressed 1 because that's all I see.
Then it asks for administrator password, and I pressed enter with no
password and it worked. And it gives me this prompt:


C:/WINDOWS> What do I enter here.

I tried to enter R here but it does'nt work. Here is what it says when I enter R:


The command is not recognized Type HELP for a list of supported commands.I'm sorry but the main PROBLEM now is that there is too little free space and you will have to get at least 15% free space. The only way I of doing this on your computer is to remove the Harddrive and slave it to another computer. Once that is done, you can transfer some files/folders of your data to some DVD's. I realize this is a drastic step but it's the only way I know of GETTING some more space on your C: drive.

Is there a way for me to just start over and wipe it clean. I have braced myself for the fact that I might loose all of my STUFF anyway.

Thank you.That might be the way to go but you can still save all your important data. You can remove the Harddrive and slave it to another computer and save your data on DVD's. You you slave a harddrive on another computer it becomes just another storage device. You can go into it and copy all your data to an external harddrive or to DVD's. If this is a laptop, you can do the same thing but you will need to buy a cable to hook the harddrive to another computer. I've sent a message to my mentor about this problem and I'll contact you when he gets back to me.Try following this guide. http://michaelstevenstech.com/XPrepairinstall.htmOk, I have windows xp back again. Thank you.
I still have no space on my hard drive because it actually kept all of
my programs and files. Now I have to find out how to delete a bunch
of stuff.
Is there a program that I COULD run to tell me what I could safely get
rid of.

Thanks again.
•Start HijackThis
•Click on the Misc Tools button
•Click on the Open Uninstall Manager button.
•Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
Copy and paste this file in your next reply.

Once I see the list I will be able to help you determine which ones can go and which you need to keep. Ok, Here it is. Thank you.

Broadcom 440x 10/100 Integrated Controller
Dell ResourceCD
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB981793)
Intel(R) Extreme Graphics Driver
Mozilla Firefox (3.6.
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB982381)
SoundMAX
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Windows XP Service Pack 3

The only program you can uninstall is HJT. You must have a ton of personel files, pictures, movies etc. to take up that much of your harddrive. The programs that you have presently installed should not take up that much room on your drive. You will have to check you files/folders to see which ones you can move to another drive.Install WinDirStat and see what is taking up the space.

4787.

Solve : Can't Get Onto Windows XP-Possibe Major PC Problem (Long)?

Answer»

You never said which PC to run it from.
The OTL were run off the good PC, since there is no way I could download OTL on the infected PC with no IP access.

Which PC do you want the sfc scan run from?
Could I request in the future, may you specify which PC to do scans/other things from?

Thanks.


Also...since we fixed the infected PC to now sign on normally, why is it that I can not access the internet even though I am connected and what can be done?OK when I tried on the good PC the black cmd screen popped up and vanished instantly.

I tried on the infected PC....it ran until this message popped up

Quote

Files that are required for windows to run properly must be copied to the DLL Cache.

Insert your Windows XP Professional CD-ROM now.

The only CDs I have are
-Windows XP Service Pack 2
-Application (For re-installing Dell Tools System Software)
-Operating System (Reinstallion CD Microsoft Windows XP Professional Including Service Pack 1a)
-Drivers and Utilities (For reinstalling Dell Inspiron System Software)


I inserted the XP Service Pack 2 on the infected PC and was told it was the wrong disc.
I then inserted the Operating System (Reinstallion CD Microsoft Windows XP Professional Including Service Pack 1a) into the infected PC...and the scan resumed

After it finshed the bar vanishes...and I still can't get on the internetQuote
Which PC do you want the sfc scan run from?
Could I request in the future, may you specify which PC to do scans/other things from?
Let's just work on the originally infected computer. You will have to download any programs and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

Ok. We need to clear your DNS cache.

Please navigate to Start>Run and type cmd

in the window that pops up type ipconfig /flushdns

***************************************

Download the Fix IE Utility to your desktop.

Before running the utility, make sure that all your Internet Explorer windows are closed!

* Extract the contents of the .zip file to your desktop.
* Double click the Fix IE Utility button to run the tool.
* Click Run Utility
* Click OK when you see 'Re-registered all files'
* Open Internet Explorer and see how it works.

Quote from: SuperDave on August 15, 2010, 04:13:46 PM
Let's just work on the originally infected computer. You will have to download any programs and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

Ok. We need to clear your DNS cache.

Please navigate to Start>Run and type cmd

in the window that pops up type ipconfig /flushdns

***************************************


Again, I assume you meant on this and here after on the infected pc only.
I did this on the infected PC, and I got the same message I got last night when I typed IPconfig:

Quote
Windows IP Configuration

An internal error occured: The request is not supported.

Please contact Microsoft Product Support Services for further help.

Additional information: Unable to query host name.
Quote
Download the Fix IE Utility to your desktop.

Before running the utility, make sure that all your Internet Explorer windows are closed!

* Extract the contents of the .zip file to your desktop.
* Double click the Fix IE Utility button to run the tool.
* Click Run Utility
* Click OK when you see 'Re-registered all files'
* Open Internet Explorer and see how it works.

........Done...........and told

"Internet Explorer cannot display the webpage"


NOTHING works!!!

I still do not get why I am perfectly connected to the internet but can't access it?
The virus is gone.Try this please. Reset Explorer Settings IE OK...a few things

1) Congratulations! Thanks to both SuperDave and EvilFantasy my PC is running and I am able to access the internet.
-SuperDave got the PC to be able to turn on
-Evil Fantasy and his latest post allowed me to get the internet

I would like to personally thank the both of you for walking me through this complicated problem step-by-step.
I know I lost patience and snapped a few times, this was quite lengthy, but thank you!

How can I officially thank you both in your profile?
I would have updated sooner, but I was out of town last week and only got around to the problem last night.

2) Given my expertise, would it be better to leave it alone or could we say what exactly the problem was?
In your experience, did this come off as one of the more difficult problems?


3) While we fixed this virus, I have a 6 year old PC and want to get a clean bill of health.
I went ahead and ran/download Java and did all the recommended scans.
I have attached the logs below.
Before I go onto business as usual, I want the PC running as safely, fastly, and best as possible.
Would you mind going through these logs so we can get a clean bill of health?
Lemme know so I can clear this out.



Super Anti-Spyware
Quote
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/25/2010 at 02:34 AM

Application Version : 4.41.1000

Core Rules Database Version : 5189
Trace Rules Database Version: 3001

Scan type : Complete Scan
Total Scan Time : 01:56:25

Memory items scanned : 513
Memory threats detected : 0
Registry items scanned : 6647
Registry threats detected : 0
File items scanned : 63752
File threats detected : 0


MBAM
Quote
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4476

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/25/2010 12:29:46 PM
mbam-log-2010-08-25 (12-29-46).txt

Scan type: Quick scan
Objects scanned: 141086
Time elapsed: 12 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{fe4c2c37-edc8-4c00-b864-3c38cf3ba834} (Adware.Adshot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3436ec28-ccde-4a49-83a6-0b8dee619be3} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{486bdd1d-bac7-4f82-8b68-38b1bd5378f2} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\settingsxx.exe (Spyware.SpyEyes) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\settingsxx.exe (Spyware.SpyEyes) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\vugip.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zugip.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\settingsxx.exe\config.bin (Spyware.SpyEyes) -> Quarantined and deleted successfully.



HiJackThis
Quote
Logfile of Trend MICRO HijackThis v2.0.2
Scan saved at 1:23:59 PM, on 8/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot MODE: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Emsisoft\Online Armor\OAcat.exe
C:\Program Files\Emsisoft\Online Armor\oasrv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Emsisoft\Online Armor\oaui.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seagate\Sync\SeaSyncServices.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Emsisoft\Online Armor\OAhlp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=70001
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xfinity.com/?cid=xfactiv_eg_self_main
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Emsisoft\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-21-484763869-630328440-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-484763869-630328440-725345543-1003\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215897936109
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Online Armor Helper Service (OAcat) - Emsi Software GmbH - C:\Program Files\Emsisoft\Online Armor\OAcat.exe
O23 - Service: Seagate Sync Service - Seagate Technology LLC - C:\Program Files\Seagate\Sync\SeaSyncServices.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Emsi Software GmbH - C:\Program Files\Emsisoft\Online Armor\oasrv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9823 bytes









Thanks!4) As I have been trying to clean out old files, I still am unable to delete civ4. Years ago I got this from a friend, pirated style.
It is located under downloads, every time I try and delete it tells me it cannot because "another program or person"
It also is located in the "E" drive of my PC as well.

Lemme know so I can clear this out.

Thanks!You could try deleting it in Safe Mode or download and install Unlocker to delete it.OK so..........

1) Installed unlocker...under downloads in my documents it is now deleted.
-However....in my computer it still shows in the E drive.

-Next time I re-start my PC will it be gone?
-If not how can I remove it from E drive...or is it moot...is it gone?


2) Otherwise given my logs, is my PC now given a clean bill of health?

3) What was the big problem with it, and was this one of the worst you have seen?

4) Thanks again, how can I officially thank you?




Quote
1) Installed unlocker...under downloads in my documents it is now deleted.
-However....in my computer it still shows in the E drive.

-Next time I re-start my PC will it be gone?
-If not how can I remove it from E drive...or is it moot...is it gone?

Is it still there?


Quote
2) Otherwise given my logs, is my PC now given a clean bill of health?

Your logs are clean.

Quote
3) What was the big problem with it, and was this one of the worst you have seen?

No it's far from the worst. Look back through the Malwarebytes and SUPERAntispyware logs and you will see what all was found/removed.

Quote
4) Thanks again, how can I officially thank you?

I think you just did.


4788.

Solve : Ran MBAM – now I get blank blue screen?

Answer»

C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001487.EXEa VARIANT of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001488.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001489.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001490.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001491.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001492.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001493.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001494.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001495.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001496.exea variant of Win32/TrojanDropper.Agent.OCN trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001497.exea variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001498.exea variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001499.EXEa variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001500.EXEa variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001501.EXEa variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001502.EXEa variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP2\A0001503.EXEa variant of Win32/Kryptik.HT trojancleaned by deleting - quarantined
If there are no other issues, we can do some clean-up.

* Click START then RUN - Vista users press the Windows Key and the R KEYS for the Run BOX.
* Now type COMBOFIX /uninstall in the runbox
* Make sure there's a SPACE between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

***********************************

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

*******************************************
Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

******************************************************

Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Dave – thanks for the help in sorting out the trouble I had with my computer and for the advice on preventing further trouble. Today I did the cleanup and installed Comodo Personal Firewall and WOT. Will try SpywareBlaster and SpyBot tomorrow. Again, many thanks.

4789.

Solve : Malware removal help?

Answer»

I have the exact PROBLEM described be evilfantasy "read this before requesting malware removal help", I have Windows XP, service pack 2 installed, AVG Free 8.5, and windows defender, however, I am trying to download the FIRST step, and I cannot get online, the malware is redirecting to porn sites. I am sending this from my work computer with an aircard. NEED to figure out how to get to the sites to download. Help!Download on your work computer, transfer them to the INFECTED SYSTEM, run the logs and copy them back to your work system to post.

4790.

Solve : Qandr Rootkit, all approaches failed?

Answer»

Pardon my english as it is not my first language. Let me try to explain.

When I turn on the computer, it automatically goes online through a wi-fi connection (although the stability of the connection is not very GOOD since Qandr Rootkit infected the laptop). I can use the internet, for example, to connect to Pokerstars or Full Tilt Poker to play online poker. But, when I open IE or Firefox or Chrome, I can't get any webpage to open for a period of around 30 minutes (even if I'm playing poker online at the same time). This only happens with the browsers, but not with any other programs I use online (eg.: Poker programs, P2P). After about 30 minutes of being online, the browsers suddenly start working on an off and I can get to see my email or this forum or whatever website.

Hope I have MADE myself clear

Thanks for your time and patience. Quote

Pardon my english as it is not my first language. Let me try to explain.
Don't apologize. I admire anyone who can speak more than ONE language. I've been trying to learn french for years but I only know the swear words.lol
I can't see any evidence of a rootkit on your computer and my list of tools I can use are nearly exhausted.
Have you given any consideration about the warning I gave you about free space on your C: drive? Low free space can make a computer do strange things.

Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
****************************************

I'd like to scan your machine with ESET OnlineScan

•Hold down CONTROL and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Yes, I have made some more space free in the C drive. I already ran MBAM. Do you want me to run it again?

Here are the ESET results. I didn't clean any of the infected files, though.


C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1dd6a40c-43c6316cJava/TrojanDownloader.Agent.NBK trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\7bb99554-262cb67aJava/TrojanDownloader.Agent.NBL trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\40591084-43a7cc6bJava/TrojanDownloader.Agent.NBL trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\72d19db0-3aa663a6Java/Mugademel.A trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\1eff1eb1-2e5c282fJava/TrojanDownloader.Agent.NBL trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\27c71832-6170d83ea variant of Java/Exploit.Agent.NAC trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\42441975-34b22db5Java/TrojanDownloader.Agent.NBM trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\640c67b5-256c5351Java/TrojanDownloader.Agent.NBM trojan
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\449b676-4e7f46e3multiple threats
C:\Users\Pedro\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3f5641c8-23c8d0b8Java/TrojanDownloader.Agent.NBK trojan

If you want to know some swear words in portuguese, just let me know. Portuguese is a very rich language when it comes to insulting Please run ESET again and clean those infections.I've ran ESET and deleted the infected files. Also ran MBAM again, it popped the "wtxtg.sys" file as a Rootkit Agent and supposedly quarentined it and removed it. I rebooted the laptop and went the the system32\drivers folder and wtxtg.sys is still there as a file that has been modified today. Browsers seem to be working properly but I really can't tell if the infection is gone...Avast just popped up "wtxtg.sys" file as Qandr Rootkit. I'm this close to nuke the laptop...It would appear that the driver file wtxtg.sys is located in the Avast folder. Could you please try this for me. Please download and install MSE. Disable your Avast and run a scan with MSE and let me know what you find.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
Microsoft Security Essentials for Windows XPSD,

Sorry for the late reply. After one month of fighting, I've DECIDED to resort to heavy weaponry: I've reinstalled Windows 7 and deleted the old. I was trying to avoid this, but I couldn't be held hostage by Quandr Rootkit's moods.

That said, I want to thank you for your time and patience.

Best regards,

Pedro
4791.

Solve : nodqq and ca.exe virus on 3 maschines, USB spreading virus?

Answer»

Not sure where my 1st post went, but I'll try again. I have 3 machines ( Desktop, Laptop and Netbook all infected with nodqq.exe/ca.exe virus. Bought a Verbatim 500G usb drive to sync all my stuff between the three about 2 weeks ago. Noticed Friday night that I couldn't access any hidden files with my laptop, either in the drive or on the comp hdd.
Tried on the desktop and found the same issue. Any attempt to show hidden files by Start>MyDocuments>Tools>Folder Options>View didn't work. Selection goes right back to not show.
Have spent most of the weekend fighting this. 1st I updated all my Norton to Internet Security 2010 and ran back to back scans. 2nd downloaded and ran Hijackthis and posted results (Previous post #1 not listed anymore?) 3rd downloaded and ran CCleaner and posted results. Eventually Norton ID'd nodqq and ca.exe among some other unfavorable stuff and removed them from the desktop and laptop.

The problem is that my netbook is still infected. I thought I had it beat yesterday when I found and changed some items in the registry and got it working again. All seemed ok until I restarted and went back to the same issues. This is what I have figured/found out:

I'm not sure where the virus got picked up, but it installed itself into my USB drive disguised as "autorun.inf"
When the drive got plugged in to my netbook, it used autorun to install itself into the windows inf folder. It also added the value "nod32 = %Local Settings%\Temp\nodqq.exe" under the registry key

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

and changes the value Hidden = 02
ShowSuperHidden = 00

under the key

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\folder\showall

I can get into msconfig and deselect nodqq.exe but when I click OK I get an access error message that tells me to sign in as an admin.

I found and deleted 1 exe and 2 dll files with the name nodqq I found by running search, selecting search hidden files and folders. Now no more files with that name are found.
Norton keeps finding and quarantining Trojan.Packed.NsAnti
Each time it says its rosolved but it keeps coming back. It has also picked up and resolved ca.exe once and rpw.exe twice.

I've ran and am running Norton Internet security 2010, CCleaner, Hijackthis and SPYBOT S&D.

I've changed registry values back to normal and removed added items only to have them go back. I need to find where this thing is hiding, how it's coming back and changing reg entries and how I can kill and remove it permanently. I hope I've included enough info. By the way:

ASUS EeePC
Intel Atom
CPU N270 @ 1.60 GHz 0.99Mb RAM
XP Home 2002 SP3
Norton Internet Security 2010
SPybot S&D

Let me know if you want logs posted have the ones from Hijackthis, Norton, and CCleaner.

Also downloaded and running NOautorun USB defender and was able to get into my drive and remove the virus on that front.Hey man, I've registered just to tell you how I finally MANAGED to kill nodqq and its variants.

I was using my USB stick on a networked, public computer at school and when I got home and plugged it into my laptop and PC, I noticed Windows Live Messenger and IE were crashing.

Malwarebytes has always been my go to for getting rid of this kind of thing and it found and deleted nodqq.exe and dlls, repaired registry, etc.

However, upon reboot, the virus managed to keep regenerating itself. I even deselected it from start up in msconfig, but it would magically reappear in the list.

Anyways, I downloaded this PeeTech fix advertised on some tech-blog site and it worked PERFECTLY. Upon reboot, I could instantly see hidden files that nodqq had been BLOCKING. I was weary at first to d/l something that I didn't know anything about, but I figured I'd try it first on my laptop where the damage would be minimal.


Anyways, here's the link to the blog and directly to the fix. Just download, unrar and run. Made my DAY- I'd been losing my mind.

Blog: http://hotzone-it.blogspot.com/2010/04/how-to-remove-dqmexe-nodqqexe.html

Fix: http://www.mediafire.com/?mmlwxnmn2yz

Hope this helps!

Oh, and PS, I'm planning on just throwing the USB drive in the garbage hahaha. rusty , please wait for a malware expert to help you in this topicWanted to update those who were interested. To recap, Norton Internet Security 2010 was able to kill three viruses identified as trojans. Specifically they were: ca.exe, nodqq.exe and pwe.exe. The virus showed up in my Verbatim USB HDD and was named "autorun.inf". As soon as the drive was plugged in to a machine, Bam it downloaded itself to 3 different locations. It also created registry keys, and changed registry values. The keys were created start them on bootup, even if removed from msconfig startup list. The registry values seemed to make them hard to find by not allowing access to hidden files.

All 3 had to be removed in short order or they would be replaced by one of the other two.
When pwe.exe was removed by Norton, you could get access to hidden files by changing them back to a value of (1) in the registry. When this worked I ran search and located each file (nodqq.exe, ca.exe, and pwe.exe, along with nodqq.dll) and deleted them. I also found copies of them in the %temp% file and deleted them. The first try was a bust, but the second time I remembered to empty the recycle bin and then they didn't return.

It was quite a blur, with 3 machines running simultaneously so I'm having trouble recalling it all, but between Norton 2010, CCleaner, Hijackthis & Spybot S&D it seemed to work out. I also installed Noautorun which allowed me to find and kill the original threat disguised as "autorun.inf". All 3 are up and running, the only thing I found is that Norton finds and removes a different trojan 3-4 times/day so something is still going on there. Hope this info helps someone.
Rusty

4792.

Solve : Window security Alert Virus?

Answer»

That looks good. If there are no other issues, it's time for some clean-up. You can uninstall HJT, ESET and Security Check. You may keep SAS and MBAM, if you wish. Update them and run them on a regular basis.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in commy /uninstall
(Note: Make sure there's a space between the word commy and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
=====================================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please LET TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

======================================
Looking over your log it seems you don't have any evidence of a third party FIREWALL.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from ONE of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
======================================
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to FINISH and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search &AMP; Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

Wow ,SuperDave i owe you a cold one!!!Thanks for all you time and excellent instructions to help restore our computer back .This is one great website !!!!

Truly Awesome
4793.

Solve : eset nod32 v4 running automatically in my pc??

Answer»

every TIME i CLOSE eset nod32 it will come again n again what should i do,how to solve it,this is happing BCS of spyware or MALWARE or eset settings,
thanks Please do not post malware advice. If you WANT to help please go to this thread.

4794.

Solve : Malware Problems...Please Help?

Answer»

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet EXPLORER 7.0.5730.13

5/11/2010 9:14:49 AM
mbam-log-2010-05-11 (09-14-49).txt

Scan type: Full scan (C:\|)
Objects scanned: 169617
Time elapsed: 56 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
FOLDERS Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dllcache\termsrv.dll (Trojan.Downloader) -> Quarantined and deleted successfully. Hi

Please download HAMeb_check.exe and save it to your desktop.

  • Double-click on HAMeb_check.exe to run the utility and it will create a log.
  • Copy and paste the contents of that log in your next reply.
Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JAY
4795.

Solve : Is Avast! is better than other antivirus like Norton or AVG???

Answer»

Avast! Now speaks more than 27 Languages...

I want to use it in my PC but have so many doubt ........

Is Avast! Is better than other antivirus like Norton or AVG??


ANYONE can help.. ?I never tried avast. Usage of anti virus is of one's personal INTEREST....
Just check some anti virus rating web sites for further details. Try it once and compare it with your previous anti virus. You can get the difference and you may get experience with them too......
avast
is FREE antivirus with spyware protection --& a package of applications
GO ........I think Avast! is very good. For personal use, I definitely choose the free version of Avast! over Norton or McAfee. I agree totally. I've had Norton and McAfee and paid for both. I have been using Avast free version now for some time and find that is every bit as good. No, better.AVAST is very good. It works very well.

AVG is doing ok I guess, it's on my mom's old pentium 3 computer and it's not giving her problems when she uses the old PC to watch videos.

In my opinion, Avast is loads better than Norton. As for AVG...well, that's really your call. I'd say Avast and AVG are just about even, so it's mostly a matter of which one you like it better. You might as well give it a shot. If you don't like it, all you have to do is uninstall.All support avast
I think that there are better programs, such as pure Kasparsky . But it is not freeI have heard great things about Kaspersky , and I know it's rated very high. Possibly the best? Avast though certainly does the job and I'm very satisfied with it.. So my thinking is; if I can get the milk and meat without cost, why should I buy the cow?CORRECTLY. avast gives the meat and milk
But non-free programs like kaspersky & non-free avira . Add a lot of spices to the meat

Well ,I suppose being Canadian, I don't require a lot of spices.MicroSoft Security Essentials works very well for me. Very effecient and not a resource hog.I personally use (as well as the company) ESET NOD32 Anti Virus. I have had no problems with this anti-virus at all. AVG (especially the free version) wouldn't really be my choice at all. Their detection rates of Newly-Released viruses isn't very good (as tested by ourselves within a controlled environment). Also, it tends to have a file-SCAN lag.. Making full scans TAKE longer. As for Norton, I personally wouldn't bother. It uses too many system resources in order to run, the scan times take long and also it tends to leave alot of files behind once "fully uninstalled".

4796.

Solve : FUBAR?

Answer»

Hey guys,

I'm not sure if this is a registry or virus problem, but I will do my best to EXPLAIN to you what happened.

A couple of days ago, I was trying to clean up my gaming PC. I gave it to my parents to replace their old PC while I went off to college. Unfortunately, my dad did not do a good job keep up with it. Using CCleaner, a program that cleans the registry (missing .dll, unused extensions, ActiveX and Class issues. I am sure you guys are aware of the program). It FOUND 400-odd problems, and I told it to fix them. Before it fixed, I backed up the registry. After the fix, everything appeared normal.

Then,

I uninstalled the free version of Avast, and installed McAfee enterprise edition, that my University gives to students. I figured that McAfee would be better software, so why not use it. I ran a scan, and about 10% of the way through, I check and see that it has found 314 detections. Soon after, then theme of Windows reverts to Windows CLASSIC (like Windows 98). I checked to see what happened, and I saw that McAfee found another detection, making 315 total detections. I tried to switch the theme back, and it said that I have to use the "Computer Management Tool" and TURN the service back on. I try to find the service, and I cannot find it.

So, I reboot, and when it's time to login, it tells me that I have "3 days left to active your windows product." So I ignore it, and when I log in, my desktop bar is gone. I can only see about 5pixels of the very top of it (it is STILL in windows 98 theme). When I finally manage to get it up, I click on the start button and try to do a system restore. It tells me "Your system is not protected. Please restart and try again." So, I restart in Safe-Mode, and got the same error.

I reboot, and login in normally, getting the same errors. I then restore the old registry file that backed up prior to the CCleaner action. I reboot, and got the same problem.

I have the OS re-installation disk if worst comes to worst. However, my dad does his taxes through TurboTax, and the files are on the HD. I tried to save them into my thumb drive, but it will not allow me to transfer them. I tired using Copy and Paste, Send To, and even the CMD promt. Nothing seems to work. I can however save Word and PowerPoint files by opening the program, and saving them to the thumbdrive. Excel will not open correctly, nor will TurboTax.

So I am in kinda of a dilemma. I need those tax files before I can reformat, and I have no idea how to get them.

Any thoughts??

Thanks so much for the help!Your best bet would be to remove your harddrive and slave it to another computer and recover your files. I would get a hdd emclosure from like Best Buy or another electronic retailer and install the hdd in that and hook it up to another computer even a laptop and then you can possibly transfer the files that way. I would also scan the files with the other computer to make sure they are not infected with the virus. Oooh that's sounds painful haha. I have another computer that I can try that with. My dad has an IT employee at work that can take a look at it, but I really dont want to bother him with non-work related issues.

4797.

Solve : virus keeping user from start-up screen?

Answer»

Some type of virus has caused the following problem: After log-in, an Anti-Virus PROTECTION PROGRAM immediately downloads and scans for viruses, followed by a window that asks for registration. I understand that this is BOGUS and some type of Ad-ware or Malware, but I can't seem to get past that scan or registration screen to any kind of start MENU. Neither window has a close button, and although I was able to finally close the window using "alt + f4", my Start toolbar is nowhere to be found. I tried the "ctrl + esc" as well as the windows button to no avail. I can't seem to take a step TOWARD removing this virus without at least getting to the Start menu. Any suggestions?

4798.

Solve : windows sec. alert-- application cannot be executed.?

Answer»

I'm on Windows 7. I have this virus I can't GET rid of, and everything I try to start an application it won't let me. How do I begin to fix this? Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Thanks.

I downloaded this on a different computer, and tried opening it on the computer with the virus, but it won't let me install it.

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Then, try once more.Ok. a lot of hurdles to jump through. I started safe mode with network, but in order to install malware and SPYWARE programs, I had to create a new registry key to add an MSIServer.

I installed and ran the following applications:
rkill, exehelper, superantispyware, malwarebytes, hijackthis, tfc, avri antivir.

I have a OS compability issue with comboFix and a proxy issue with eset online scan-- any alternatives for these guys?

I assume the problem has been FIXED, but want to run combofix and eset online scan just to sure, any suggestions for this?

Thanks.

Hi

Download OTL to your Desktop. (If you already have it downloaded, then just follow the instructions below).

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.sys
%systemroot%\system32\drivers\*.dll
%systemroot%\system32\drivers\*.ini
%systemroot%\system32\drivers\*.exe
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.
%appdata%\*.*
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
disk.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
usbstor.sys
/md5stop
CREATERESTOREPOINT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Run Scan BUTTON. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please COPY (Edit->Select All, Edit->Copy) and paste (Edit->Paste) the contents of these files, one at a time
4799.

Solve : No place for my laptop but the trash now?

Answer»

Unless I can get some guidance, it seems I will have no other alternative but to throw my laptop in the trash. I have an HP with Windows XP Professional. My son obviously downloaded something (a long story-some other time) which has completely taken over. After log-in, an anti-virus/malware program downloads and gives me a summary of all the nasty things that are on my computer, then directs me to the screen where I can remove all the nastiness by purchasing and registering their product.

I understand that this is all bogus, but nevertheless, I have lost all control with the laptop. All of the windows related to this bogus program have no close or minimize capability and it was obviously designed to stay put until the user purchases the product (or until they get your credit card info). I can clear the screen by keying the "alt + f4", but once the anti-virus window closes, I have no tool bar or "Start" key. I've tried to key the "Windows" key and have tried to key the "ctrl + esc", but to no avail. No toolbar.

I have also tried to boot-up in safe mode, but the anti-virus still downloads in the same manner as described above. I viewed some of the suggestions contained within this forum, but with no toolbar or "Start" key, I can't even attempt step one. It also appears that most of the suggestions on how to rid a virus depend on downloading something or visiting some on-line site. I can't even get to a point where I can connect to the internet (or anything else for that MATTER). I see no other alternative but to throw the thing away.

I had thought about trying to change the configuration and settings BACK to the configuration and settings that were in place when I purchased the laptop, but when I boot-up and key "F8" I don't seen to have that OPTION. I heard there are reasons for the inability to do this, but I don't know what they are.

Having read the FORUMS here, I know there some very big brains out there. I am hoping someone can help me rid my laptop of this monster, or at least show me how to I can wipe the slate clean and start over. Please?
You can either reinstall Windows or use the makers system restore feature if there is one.
Thank you for your reply.

Can re-installing Windows be done without having any control over the laptop? Also, if a CD is necessary, I'm not sure I have one anymore. Am I able to purchase one somewhere?

Can you or someone else walk this novice through the steps necessary to re-install Windows or help me locate where the makers system restore feature might be located and/or initiated?
what make and model is it?
As best I can tell (its been awhile) HP Compaq nc 6220If you had the machine from new, did you create a set of recovery CDs when you got it, as advised? if not, you can order an OS install disk

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00810334
Thank you, sir. I will order one today.Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.Hello, just one more tip.
Your collection of photos and documents may be quite valuable to you. If so, you should give attention to some method of making a backup of all your my documents folder before you attempt to reinstall Windows.
One method is remove and slave the laptop hard drive to a desktop machine using a suitable external USB adapter. This way you can save the contents of the my documents to a backup folder on the desktop machine.



4800.

Solve : XP Antivirus Pro 2010...Removed Itself??

Answer»

I have a rather strange situation on my hands.

XP Antivirus Pro 2010 (or some variation on that name) installed itself on my laptop - despite the fact I had Avast! Home working the whole time.

Not wanting to bother with the never-ending process of ATTEMPTING to remove it, I simply planned to back-up my files and restore the OS.

However, I didn't have the time to restore and still needed to access my files on the laptop, so I simply turned off my WiFi so the XP Antivirus Pro 2010 would be unable to communicate with the web.

After about 2 weeks of barely using my laptop, I turned it on and FOUND no trace of XP Antivirus Pro 2010: it didn't start up with Windows, it wasn't present in my system tray, and it didn't block my internet navigation...

Did it literally remove itself or is it likely still present, lurking in the background?

Any reason for me into restore my system?

My Startup:

I really doubt that it REMOVED itself and System Restore does not cure infections. In fact, some infections actually hide in your System Restore files just waiting to re-infect your computer. The only sure way to check if your computer is clean is to follow the ADVICE in instructions below.
Please go to this LINK and follow the directions and post the required logs.