InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 251. |
Solve : Scan Results? |
|
Answer» Sorry i didn't clarify. I am running as administrator. Ok. You will have to skip over Secunia but please make sure that Windows and Java are up-to-date.I was able to update all the other programs that came up from Secunia something is just messed up with acrobat reader. My computer makes a strange buzzing/ scraping sound (sounds like the hard drive) when the firewall is turned on/ off. Is that normal? Should I remove it and load another?It sounds like something is amiss in the harddrive or one of the fans. It could be just a coincidence that it started at the same time you installed a third-party Firewall. Try uninstall the firewall altogether and see what happens.Will do. Also another question do you know how to unlock a registry key so i can install the latest Acrobat reader/ I keep getting the error: Error 1402.could not open key: HKEY_local_Machine\software\microsoft\windows\currentversion\Run\optionalcomponents\MSFS. Verify that you have sufficient access to that key of contact support personel When i try to install the latest version of acrobat reader. I tried going through the steps at http://johnsonyip.com/index.php?option=com_content&view=article&id=96&Itemid=198 but hit a wall around step 11 because i don't have a "other users or groups..." button. I'd really need to have acrobat reader on my computer.Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. link # 1 Link # 2 If you are using Firefox, make sure that your download settings are as follows: * Tools->Options->Main tab * Set to "Always ask me where to Save the files". Re-running ComboFix to remove infections:
ComboFix 11-04-25.02 - Admin 04/25/2011 20:43:34.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2476 [GMT -7:00] Running from: c:\documents and settings\Admin\My Documents\Downloads\ComboFix.exe Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A} . . ((((((((((((((((((((((((( Files Created from 2011-03-26 to 2011-04-26 ))))))))))))))))))))))))))))))) . . 2011-04-25 18:58 . 2011-04-25 18:5828752----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\MpKsl6656390c.sys 2011-04-25 18:58 . 2011-04-11 07:047071056----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\mpengine.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll 2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll 2011-04-22 20:35 . 2011-04-22 20:36--------d-----w-c:\program files\QuickTime 2011-04-22 08:09 . 2011-04-22 08:09--------d-----w-c:\documents and settings\Matthew\Application Data\OnlineArmor 2011-04-22 06:51 . 2011-04-22 07:28--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor 2011-04-22 06:51 . 2011-04-22 06:51--------d-----w-c:\documents and settings\Admin\Application Data\OnlineArmor 2011-04-22 06:50 . 2011-04-06 20:0239048----a-w-c:\windows\system32\drivers\oahlp32.sys 2011-04-22 06:50 . 2011-04-06 20:0129464----a-w-c:\windows\system32\drivers\OAnet.sys 2011-04-22 06:50 . 2011-04-06 20:0125192----a-w-c:\windows\system32\drivers\OAmon.sys 2011-04-22 06:50 . 2011-04-06 20:01205864----a-w-c:\windows\system32\drivers\OADriver.sys 2011-04-22 06:49 . 2011-04-22 07:26--------d-----w-c:\program files\Online Armor 2011-04-21 01:20 . 2011-04-21 01:20--------d-----w-c:\documents and settings\Admin\Application Data\Hi-Rez Studios 2011-04-21 01:18 . 2011-04-21 01:18--------d-----w-c:\documents and settings\All Users\Application Data\Hi-Rez Studios 2011-04-21 01:18 . 2011-04-21 18:46--------d-----w-c:\program files\Hi-Rez Studios 2011-04-20 19:18 . 2011-04-11 07:047071056----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-20 06:55 . 2011-04-20 06:55--------d-----w-c:\program files\ESET 2011-04-19 06:25 . 2010-10-19 20:51222080------w-c:\windows\system32\MpSigStub.exe 2011-04-19 06:22 . 2011-04-19 06:23--------d-----w-c:\program files\Microsoft Security Client 2011-04-17 20:03 . 2011-04-17 20:03--------d-----w-c:\program files\Ventrilo 2011-04-17 20:02 . 2011-04-21 05:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2011-04-16 04:33 . 2011-04-16 04:33--------d-----w-c:\program files\Common Files\Java 2011-04-16 04:32 . 2011-02-03 04:40472808----a-w-c:\windows\system32\deployJava1.dll 2011-04-16 04:03 . 2011-04-16 04:03--------d-----w-c:\documents and settings\Admin\Application Data\Malwarebytes 2011-04-16 03:22 . 2011-04-16 03:22--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2011-04-15 22:35 . 2011-04-15 22:35--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2011-04-13 05:33 . 2011-04-13 05:33--------d-----w-c:\documents and settings\Matthew\Local Settings\Application Data\Mozilla 2011-04-13 03:06 . 2011-04-13 03:06--------d-----w-c:\documents and settings\Kary\Application Data\Wacom 2011-04-13 03:06 . 2011-04-13 03:06--------d-----w-c:\documents and settings\Kary\Application Data\WTablet 2011-04-12 23:00 . 2011-04-12 23:00--------d-----w-c:\program files\GameSpy Arcade 2011-04-12 22:57 . 2011-04-12 22:57--------d-----w-c:\program files\Irrational Games 2011-04-08 06:11 . 2010-12-02 09:12837224----a-w-c:\windows\system32\nvgenco32hda.dll 2011-04-06 10:43 . 2011-01-08 03:27941160----a-w-c:\windows\system32\nvdispco322090.dll 2011-04-06 10:43 . 2011-01-08 03:27837736----a-w-c:\windows\system32\nvgenco322040.dll 2011-04-06 09:43 . 2011-04-06 09:43--------d-----w-c:\program files\Common Files\Creative 2011-04-06 09:42 . 2011-04-06 09:44--------d--h--w-c:\program files\Creative Installation Information 2011-04-06 09:27 . 2011-04-06 09:27--------d-----w-c:\documents and settings\All Users\Application Data\Creative 2011-04-06 09:24 . 2003-06-13 06:257062----a-w-c:\windows\system32\audiopid.vxd 2011-04-06 09:24 . 2011-04-06 09:24--------d-----w-c:\program files\Common Files\Creative Labs Shared 2011-04-06 09:23 . 2011-04-06 09:23445016----a-w-c:\windows\system32\wrap_oal.dll 2011-04-06 09:23 . 2004-07-13 01:53585728----a-w-c:\windows\system32\ctaudfx.dll 2011-04-06 09:23 . 2003-11-13 10:04606208----a-w-c:\windows\system32\ctsblfx.dll 2011-04-06 09:23 . 2003-11-13 10:02114688----a-w-c:\windows\system32\commonfx.dll 2011-04-06 09:14 . 2003-11-11 01:14729088----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2011-04-06 09:14 . 2003-11-11 01:1369715----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2011-04-06 09:14 . 2003-11-11 01:12266240----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2011-04-06 09:14 . 2003-11-11 01:12192512----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2011-04-06 09:14 . 2003-11-11 01:115632----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2011-04-06 09:14 . 2011-04-06 09:14188548----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2011-04-06 09:14 . 2011-04-06 09:14311428----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2011-04-06 09:12 . 2011-04-06 09:12--------d-----w-c:\documents and settings\Matthew\Application Data\InstallShield Installation Information 2011-04-02 09:23 . 2011-04-02 09:23--------d-----w-c:\documents and settings\Admin\Application Data\SystemRequirementsLab 2011-04-02 09:16 . 2011-04-02 09:16--------d-----w-c:\documents and settings\Admin\Local Settings\Application Data\Mozilla 2011-04-02 01:54 . 2011-04-02 01:54--------d-----w-c:\documents and settings\Admin\Application Data\NVIDIA 2011-04-02 01:31 . 2010-11-11 23:1026216----a-w-c:\windows\system32\nvhdap32.dll 2011-04-02 01:31 . 2010-11-11 23:10100456----a-w-c:\windows\system32\drivers\nvhda32.sys 2011-04-02 01:31 . 2010-06-21 22:07232040----a-w-c:\windows\system32\nvcohda.dll 2011-04-02 01:29 . 2011-04-08 06:11252080----a-w-c:\windows\system32\nvdrsdb0.bin 2011-04-02 01:29 . 2011-04-08 06:111----a-w-c:\windows\system32\nvdrssel.bin 2011-04-02 01:29 . 2011-04-08 06:11252080----a-w-c:\windows\system32\nvdrsdb1.bin 2011-03-28 23:13 . 2011-03-28 23:17--------d-----w-c:\program files\SIW . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-06 09:23 . 2009-05-21 01:18109144----a-w-c:\windows\system32\OpenAL32.dll 2011-03-07 05:33 . 2009-05-20 21:35692736----a-w-c:\windows\system32\inetcomm.dll 2011-03-04 06:45 . 2004-08-04 12:00434176----a-w-c:\windows\system32\vbscript.dll 2011-03-03 13:21 . 2004-08-04 12:001857920----a-w-c:\windows\system32\win32k.sys 2011-02-17 19:00 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll 2011-02-17 19:00 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll 2011-02-17 19:00 . 2004-08-04 12:001830912------w-c:\windows\system32\inetcpl.cpl 2011-02-17 19:00 . 2004-08-04 12:0017408------w-c:\windows\system32\corpol.dll 2011-02-17 13:18 . 2004-08-04 12:00455936----a-w-c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 12:00357888----a-w-c:\windows\system32\drivers\srv.sys 2011-02-17 12:32 . 2009-05-22 22:185120----a-w-c:\windows\system32\xpsp4res.dll 2011-02-17 11:44 . 2004-08-04 12:00389120----a-w-c:\windows\system32\html.iec 2011-02-15 12:56 . 2004-08-04 12:00290432----a-w-c:\windows\system32\atmfd.dll 2011-02-09 13:53 . 2004-08-04 12:00270848----a-w-c:\windows\system32\sbe.dll 2011-02-09 13:53 . 2004-08-04 12:00186880----a-w-c:\windows\system32\encdec.dll 2011-02-08 13:33 . 2004-08-04 12:00978944----a-w-c:\windows\system32\mfc42.dll 2011-02-08 13:33 . 2004-08-04 12:00974848----a-w-c:\windows\system32\mfc42u.dll 2011-02-03 02:19 . 2009-07-29 08:5173728----a-w-c:\windows\system32\javacpl.cpl 2011-02-02 07:58 . 2009-05-20 21:342067456----a-w-c:\windows\system32\mstscax.dll 2011-01-27 11:57 . 2009-05-20 21:34677888----a-w-c:\windows\system32\mstsc.exe 2011-03-18 17:53 . 2011-04-02 09:16142296----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-03-16 127037] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400] "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344] "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608] "BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-02-10 629336] "AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144] "CTHelper"="CTHELPER.EXE" [2010-03-19 19456] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-08 13880424] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-08 111208] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888] . c:\documents and settings\Admin\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "d:\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "d:\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"= "d:\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "d:\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"= "d:\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"= "d:\\World of Warcraft\\WoW-3.2.2.10505-to-3.3.0.10958-enUS-downloader.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Fantasy Grounds II\\FantasyGrounds.exe"= "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Hi-Rez Studios\\games\\global agenda live\\Binaries\\GlobalAgenda.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 . R1 MpKsl6656390c;MpKsl6656390c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\MpKsl6656390c.sys [4/25/2011 11:58 AM 28752] R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [4/21/2011 11:50 PM 205864] R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [4/21/2011 11:50 PM 39048] R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [4/21/2011 11:50 PM 25192] R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [4/21/2011 11:50 PM 29464] R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [3/8/2011 2:54 AM 401920] R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2/14/2011 5:28 AM 21992] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\Hi-Rez Studios\HiPatchService.exe [4/13/2011 1:02 PM 23680] R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [4/21/2011 11:49 PM 381512] R2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2/10/2011 4:04 PM 4869488] R2 TouchServicePen;Wacom CONSUMER Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2/10/2011 4:05 PM 416112] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [4/1/2011 6:31 PM 100456] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2/10/2011 4:04 PM 16240] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/24/2011 11:29 PM 136176] S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416] S3 cpuz134;cpuz134;\??\c:\docume~1\Admin\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\Admin\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [4/6/2011 2:24 AM 79360] S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952] S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/24/2011 11:29 PM 136176] S3 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [4/21/2011 11:49 PM 4326472] S4 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys --> c:\windows\system32\DRIVERS\AVGIDSShim.Sys [?] . Contents of the 'Scheduled Tasks' folder . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 01:49] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 01:49] . 2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1004Core.job - c:\documents and settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 14:55] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1004UA.job - c:\documents and settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 14:55] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1005Core.job - c:\documents and settings\Kary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 16:50] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1005UA.job - c:\documents and settings\Kary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 16:50] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1006Core.job - c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 09:31] . 2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1006UA.job - c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 09:31] . 2011-04-26 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 19:26] . . ------- SUPPLEMENTARY Scan ------- . uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\ee30ac2q.default\ . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-25 20:50 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . HKLM\Software\Microsoft\Windows\CurrentVersion\Run CTHelper = CTHELPER.EXE? . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(2156) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvsvc32.exe c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\program files\Creative\Shared Files\CTAudSvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTsvcCDA.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Tablet\Pen\Pen_TouchUser.exe c:\windows\system32\wscntfy.exe c:\program files\Tablet\Pen\Pen_TabletUser.exe c:\windows\system32\RUNDLL32.EXE c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2011-04-25 20:53:29 - machine was rebooted ComboFix-quarantined-files.txt 2011-04-26 03:53 . Pre-Run: 169,950,330,880 bytes free Post-Run: 170,042,322,944 bytes free . - - End Of File - - 19BC45C840308F97D27905FDDB2E5623 Were you able to install Acrobat Reader?Yes I was. Thank you.Good. Carry on with your cleanup as described in Reply # 25. Please LET me know when you're done.Quote from: darthgaul on April 23, 2011, 01:32:48 PM Will do. The website for http://johnsonyip.com/index.php?option=com_content&view=article&id=96&Itemid=198 moved to http://johnsonyip.com/how-to-unlock-windows-registry-permissions-tuturials.htm You can try turning off UAC and switching to the classic theme to see if it works.Quote from: SuperDave on April 26, 2011, 04:57:52 PM Good. Carry on with your cleanup as described in Reply # 25. Please let me know when you're done. All Done.Very well. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 252. |
Solve : Virus Removal Assistance Needed, Please Help :S? |
Answer»
Dave, it found one malicious problem and it "cured" it! Here's the report... 2011/04/30 01:38:03.0483 4204TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/04/30 01:38:04.0918 4204================================================================================ 2011/04/30 01:38:04.0918 4204SystemInfo: 2011/04/30 01:38:04.0918 4204 2011/04/30 01:38:04.0918 4204OS Version: 6.1.7600 ServicePack: 0.0 2011/04/30 01:38:04.0918 4204Product TYPE: Workstation 2011/04/30 01:38:04.0918 4204ComputerName: LAPTOP 2011/04/30 01:38:04.0918 4204UserName: Chris 2011/04/30 01:38:04.0918 4204Windows directory: C:\windows 2011/04/30 01:38:04.0918 4204System windows directory: C:\windows 2011/04/30 01:38:04.0918 4204Processor architecture: Intel x86 2011/04/30 01:38:04.0918 4204Number of processors: 2 2011/04/30 01:38:04.0918 4204Page size: 0x1000 2011/04/30 01:38:04.0918 4204Boot type: Normal boot 2011/04/30 01:38:04.0918 4204================================================================================ 2011/04/30 01:38:05.0246 4204Initialize success 2011/04/30 01:38:11.0408 4276================================================================================ 2011/04/30 01:38:11.0408 4276Scan started 2011/04/30 01:38:11.0408 4276Mode: Manual; 2011/04/30 01:38:11.0408 4276================================================================================ 2011/04/30 01:38:14.0107 42761394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys 2011/04/30 01:38:14.0216 4276ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys 2011/04/30 01:38:14.0403 4276AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys 2011/04/30 01:38:14.0575 4276adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys 2011/04/30 01:38:14.0746 4276adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys 2011/04/30 01:38:14.0980 4276adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys 2011/04/30 01:38:15.0183 4276AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys 2011/04/30 01:38:15.0433 4276AFS (be913403ed7219894b30e362fd8d4313) C:\windows\system32\drivers\AFS.sys 2011/04/30 01:38:15.0682 4276AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys 2011/04/30 01:38:15.0901 4276agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys 2011/04/30 01:38:16.0072 4276aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys 2011/04/30 01:38:16.0244 4276aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys 2011/04/30 01:38:16.0416 4276amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys 2011/04/30 01:38:16.0556 4276amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys 2011/04/30 01:38:16.0837 4276AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys 2011/04/30 01:38:17.0055 4276AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys 2011/04/30 01:38:17.0196 4276amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys 2011/04/30 01:38:17.0320 4276amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys 2011/04/30 01:38:17.0398 4276amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys 2011/04/30 01:38:17.0492 4276AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys 2011/04/30 01:38:17.0648 4276arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys 2011/04/30 01:38:17.0742 4276arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys 2011/04/30 01:38:17.0913 4276AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys 2011/04/30 01:38:17.0991 4276atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys 2011/04/30 01:38:18.0241 4276atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys 2011/04/30 01:38:18.0459 4276AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys 2011/04/30 01:38:18.0615 4276AVGIDSDriver (b93c0f409482d6c0e581caca51ae9c02) C:\windows\system32\DRIVERS\AVGIDSDriver.Sys 2011/04/30 01:38:18.0802 4276AVGIDSEH (13256fc72fa5b3f6d6e8c5957e579b7c) C:\windows\system32\DRIVERS\AVGIDSEH.Sys 2011/04/30 01:38:18.0943 4276AVGIDSFilter (fa0685cc51de5cfd804e7deaa6488e0e) C:\windows\system32\DRIVERS\AVGIDSFilter.Sys 2011/04/30 01:38:19.0052 4276AVGIDSShim (f788b51100d0f40ea176798cce954a1a) C:\windows\system32\DRIVERS\AVGIDSShim.Sys 2011/04/30 01:38:19.0208 4276Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\windows\system32\DRIVERS\avgldx86.sys 2011/04/30 01:38:19.0348 4276Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\windows\system32\DRIVERS\avgmfx86.sys 2011/04/30 01:38:19.0489 4276Avgrkx86 (ffbe8adeb1fd8640540bf6e4a137b3ef) C:\windows\system32\DRIVERS\avgrkx86.sys 2011/04/30 01:38:19.0614 4276Avgtdix (69e6adf5cbbdeb5f2b727c93937a5823) C:\windows\system32\DRIVERS\avgtdix.sys 2011/04/30 01:38:19.0832 4276b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys 2011/04/30 01:38:19.0988 4276b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys 2011/04/30 01:38:20.0113 4276Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys 2011/04/30 01:38:20.0269 4276blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys 2011/04/30 01:38:20.0394 4276bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys 2011/04/30 01:38:20.0456 4276BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys 2011/04/30 01:38:20.0550 4276BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys 2011/04/30 01:38:20.0706 4276Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys 2011/04/30 01:38:20.0877 4276BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys 2011/04/30 01:38:20.0986 4276BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys 2011/04/30 01:38:21.0064 4276BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys 2011/04/30 01:38:21.0158 4276BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys 2011/04/30 01:38:21.0283 4276cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys 2011/04/30 01:38:21.0392 4276cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys 2011/04/30 01:38:21.0548 4276circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys 2011/04/30 01:38:21.0626 4276CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys 2011/04/30 01:38:21.0751 4276CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys 2011/04/30 01:38:21.0829 4276cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys 2011/04/30 01:38:21.0938 4276CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys 2011/04/30 01:38:22.0063 4276Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys 2011/04/30 01:38:22.0172 4276CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys 2011/04/30 01:38:22.0312 4276crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys 2011/04/30 01:38:22.0500 4276DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys 2011/04/30 01:38:22.0640 4276discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys 2011/04/30 01:38:22.0749 4276Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys 2011/04/30 01:38:22.0921 4276Dot4 (b5e479eb83707dd698f66953e922042c) C:\windows\system32\DRIVERS\Dot4.sys 2011/04/30 01:38:23.0248 4276Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\windows\system32\DRIVERS\Dot4Prt.sys 2011/04/30 01:38:23.0451 4276dot4usb (cf491ff38d62143203c065260567e2f7) C:\windows\system32\DRIVERS\dot4usb.sys 2011/04/30 01:38:23.0623 4276drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys 2011/04/30 01:38:23.0888 4276DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\windows\System32\drivers\dxgkrnl.sys 2011/04/30 01:38:24.0465 4276ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys 2011/04/30 01:38:24.0684 4276elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys 2011/04/30 01:38:24.0824 4276epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\windows\system32\epmntdrv.sys 2011/04/30 01:38:24.0886 4276ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys 2011/04/30 01:38:25.0011 4276EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\windows\system32\EuGdiDrv.sys 2011/04/30 01:38:25.0120 4276exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys 2011/04/30 01:38:25.0214 4276fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys 2011/04/30 01:38:25.0308 4276fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys 2011/04/30 01:38:25.0370 4276FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys 2011/04/30 01:38:25.0448 4276Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys 2011/04/30 01:38:25.0495 4276flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys 2011/04/30 01:38:25.0604 4276FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys 2011/04/30 01:38:25.0713 4276FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys 2011/04/30 01:38:25.0932 4276Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys 2011/04/30 01:38:26.0119 4276fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys 2011/04/30 01:38:26.0275 4276gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys 2011/04/30 01:38:26.0368 4276GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2011/04/30 01:38:26.0540 4276hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys 2011/04/30 01:38:26.0665 4276HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys 2011/04/30 01:38:26.0790 4276HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/04/30 01:38:26.0868 4276HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys 2011/04/30 01:38:26.0946 4276HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys 2011/04/30 01:38:27.0008 4276HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys 2011/04/30 01:38:27.0102 4276HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys 2011/04/30 01:38:27.0242 4276HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys 2011/04/30 01:38:27.0351 4276HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys 2011/04/30 01:38:27.0507 4276hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys 2011/04/30 01:38:27.0679 4276i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys 2011/04/30 01:38:27.0804 4276iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys 2011/04/30 01:38:27.0975 4276iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys 2011/04/30 01:38:28.0162 4276IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys 2011/04/30 01:38:28.0318 4276intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys 2011/04/30 01:38:28.0459 4276intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys 2011/04/30 01:38:28.0584 4276IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/04/30 01:38:28.0708 4276IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys 2011/04/30 01:38:28.0818 4276IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys 2011/04/30 01:38:28.0942 4276IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys 2011/04/30 01:38:29.0052 4276isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys 2011/04/30 01:38:29.0176 4276iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys 2011/04/30 01:38:29.0286 4276kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys 2011/04/30 01:38:29.0395 4276kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys 2011/04/30 01:38:29.0520 4276KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys 2011/04/30 01:38:29.0629 4276KSecPkg (26c046977e85b95036453d7b88ba1820) C:\windows\system32\Drivers\ksecpkg.sys 2011/04/30 01:38:29.0754 4276Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 2011/04/30 01:38:29.0878 4276Lbd (336abe8721cbc3110f1c6426da633417) C:\windows\system32\DRIVERS\Lbd.sys 2011/04/30 01:38:30.0003 4276lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys 2011/04/30 01:38:30.0159 4276LPCFilter (6e3d3816749e107883eec5734ce44493) C:\windows\system32\DRIVERS\LPCFilter.sys 2011/04/30 01:38:30.0331 4276LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys 2011/04/30 01:38:30.0471 4276LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys 2011/04/30 01:38:30.0658 4276LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys 2011/04/30 01:38:30.0861 4276LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys 2011/04/30 01:38:31.0080 4276luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys 2011/04/30 01:38:31.0220 4276megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys 2011/04/30 01:38:31.0360 4276MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys 2011/04/30 01:38:31.0485 4276Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys 2011/04/30 01:38:31.0657 4276monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys 2011/04/30 01:38:31.0766 4276mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys 2011/04/30 01:38:31.0875 4276mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys 2011/04/30 01:38:32.0031 4276mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys 2011/04/30 01:38:32.0187 4276mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys 2011/04/30 01:38:32.0312 4276mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys 2011/04/30 01:38:32.0421 4276MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys 2011/04/30 01:38:32.0530 4276mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/04/30 01:38:32.0718 4276mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/04/30 01:38:32.0889 4276mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/04/30 01:38:33.0076 4276msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys 2011/04/30 01:38:33.0232 4276msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys 2011/04/30 01:38:33.0404 4276Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys 2011/04/30 01:38:33.0591 4276mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys 2011/04/30 01:38:33.0763 4276msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys 2011/04/30 01:38:33.0997 4276MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys 2011/04/30 01:38:34.0122 4276MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys 2011/04/30 01:38:34.0184 4276MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys 2011/04/30 01:38:34.0278 4276MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys 2011/04/30 01:38:34.0387 4276mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys 2011/04/30 01:38:34.0512 4276MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys 2011/04/30 01:38:34.0574 4276MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys 2011/04/30 01:38:34.0668 4276Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys 2011/04/30 01:38:34.0777 4276MxlW2k (d37a535bbe77a16c232969c6882b524b) C:\windows\system32\drivers\MxlW2k.sys 2011/04/30 01:38:34.0855 4276NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys 2011/04/30 01:38:34.0933 4276NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys 2011/04/30 01:38:35.0058 4276NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys 2011/04/30 01:38:35.0167 4276NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys 2011/04/30 01:38:35.0260 4276Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys 2011/04/30 01:38:35.0307 4276NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys 2011/04/30 01:38:35.0416 4276NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys 2011/04/30 01:38:35.0557 4276NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys 2011/04/30 01:38:35.0650 4276NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys 2011/04/30 01:38:35.0822 4276nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys 2011/04/30 01:38:35.0947 4276nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\windows\system32\drivers\ccdcmb.sys 2011/04/30 01:38:36.0150 4276nmwcdc (3859c69a77793180548802dac9f34a38) C:\windows\system32\drivers\ccdcmbo.sys 2011/04/30 01:38:36.0337 4276npf (b9730495e0cf674680121e34bd95a73b) C:\windows\system32\drivers\npf.sys 2011/04/30 01:38:36.0477 4276Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys 2011/04/30 01:38:36.0586 4276nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys 2011/04/30 01:38:36.0774 4276Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys 2011/04/30 01:38:36.0898 4276Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys 2011/04/30 01:38:37.0101 4276nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys 2011/04/30 01:38:37.0257 4276nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys 2011/04/30 01:38:37.0382 4276nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys 2011/04/30 01:38:37.0600 4276ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys 2011/04/30 01:38:37.0772 4276Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys 2011/04/30 01:38:37.0866 4276partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys 2011/04/30 01:38:37.0990 4276Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys 2011/04/30 01:38:38.0146 4276pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\windows\system32\DRIVERS\pccsmcfd.sys 2011/04/30 01:38:38.0287 4276pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys 2011/04/30 01:38:38.0365 4276pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys 2011/04/30 01:38:38.0474 4276pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys 2011/04/30 01:38:38.0630 4276pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys 2011/04/30 01:38:38.0786 4276PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys 2011/04/30 01:38:39.0020 4276PGEffect (1b5011dd8d57f53aed31ff0f7d635802) C:\windows\system32\DRIVERS\pgeffect.sys 2011/04/30 01:38:39.0270 4276PortlUSB (895dbe112ef6435dda75c8c9698e400b) C:\windows\system32\DRIVERS\H10USB.sys 2011/04/30 01:38:39.0457 4276PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys 2011/04/30 01:38:39.0613 4276Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys 2011/04/30 01:38:39.0769 4276Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys 2011/04/30 01:38:39.0987 4276ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys 2011/04/30 01:38:40.0143 4276ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys 2011/04/30 01:38:40.0315 4276QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys 2011/04/30 01:38:40.0424 4276RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys 2011/04/30 01:38:40.0611 4276RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys 2011/04/30 01:38:40.0767 4276Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys 2011/04/30 01:38:40.0923 4276RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys 2011/04/30 01:38:41.0079 4276RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys 2011/04/30 01:38:41.0235 4276rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys 2011/04/30 01:38:41.0485 4276rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys 2011/04/30 01:38:41.0672 4276RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys 2011/04/30 01:38:41.0844 4276RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys 2011/04/30 01:38:42.0062 4276RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys 2011/04/30 01:38:42.0265 4276RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys 2011/04/30 01:38:42.0405 4276rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys 2011/04/30 01:38:42.0624 4276RegGuard (7634b1f964f8d5c12d3a2d0b8c458568) C:\windows\system32\Drivers\regguard.sys 2011/04/30 01:38:42.0811 4276rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys 2011/04/30 01:38:43.0029 4276RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\system32\Drivers\RtsUStor.sys 2011/04/30 01:38:43.0216 4276RTL8167 (26a9d6227d12b9d9da5a81bb9b55d810) C:\windows\system32\DRIVERS\Rt86win7.sys 2011/04/30 01:38:43.0310 4276RTL8187Se (5bd298bdf62e6a8a0fc69f73a82a52bb) C:\windows\system32\DRIVERS\RTL8187Se.sys 2011/04/30 01:38:43.0482 4276SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/04/30 01:38:43.0528 4276SASENUM (7ce61c25c159f50f9eaf6d77fc83fa35) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 2011/04/30 01:38:43.0622 4276SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/04/30 01:38:43.0747 4276SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\windows\system32\Drivers\SBKUPNT.SYS 2011/04/30 01:38:43.0856 4276sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys 2011/04/30 01:38:43.0996 4276scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys 2011/04/30 01:38:44.0137 4276secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys 2011/04/30 01:38:44.0277 4276Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys 2011/04/30 01:38:44.0355 4276Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys 2011/04/30 01:38:44.0449 4276sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys 2011/04/30 01:38:44.0605 4276sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys 2011/04/30 01:38:44.0886 4276sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys 2011/04/30 01:38:45.0088 4276sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys 2011/04/30 01:38:45.0385 4276sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys 2011/04/30 01:38:45.0572 4276sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys 2011/04/30 01:38:45.0962 4276SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys 2011/04/30 01:38:46.0212 4276SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys 2011/04/30 01:38:46.0446 4276Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys 2011/04/30 01:38:46.0680 4276spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys 2011/04/30 01:38:46.0929 4276srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\windows\system32\DRIVERS\srv.sys 2011/04/30 01:38:47.0179 4276srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\windows\system32\DRIVERS\srv2.sys 2011/04/30 01:38:47.0631 4276srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\windows\system32\DRIVERS\srvnet.sys 2011/04/30 01:38:48.0302 4276stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys 2011/04/30 01:38:48.0895 4276swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys 2011/04/30 01:38:52.0389 4276SynTP (8bd10dc8809dc69a1c5a795cb10add76) C:\windows\system32\DRIVERS\SynTP.sys 2011/04/30 01:38:53.0013 4276Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\windows\system32\drivers\tcpip.sys 2011/04/30 01:38:53.0278 4276TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\windows\system32\DRIVERS\tcpip.sys 2011/04/30 01:38:53.0497 4276tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys 2011/04/30 01:38:53.0684 4276tdcmdpst (4084ea00d50c858d6f9038f86ae2e2d0) C:\windows\system32\DRIVERS\tdcmdpst.sys 2011/04/30 01:38:53.0856 4276TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys 2011/04/30 01:38:54.0043 4276TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys 2011/04/30 01:38:54.0261 4276tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys 2011/04/30 01:38:54.0417 4276TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys 2011/04/30 01:38:54.0620 4276tos_sps32 (969377943fe7284609babbab4e06b93c) C:\windows\system32\DRIVERS\tos_sps32.sys 2011/04/30 01:38:54.0760 4276tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys 2011/04/30 01:38:54.0916 4276tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys 2011/04/30 01:38:55.0041 4276TVALZ (fc24015b4052600c324c43e3a79c0664) C:\windows\system32\DRIVERS\TVALZ_O.SYS 2011/04/30 01:38:55.0150 4276TVALZFL (866462f5ae3f375ef83ef9dce436031c) C:\windows\system32\DRIVERS\TVALZFL.sys 2011/04/30 01:38:55.0275 4276uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys 2011/04/30 01:38:55.0369 4276udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys 2011/04/30 01:38:55.0728 4276uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys 2011/04/30 01:38:55.0899 4276umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys 2011/04/30 01:38:56.0040 4276UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys 2011/04/30 01:38:56.0149 4276UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys 2011/04/30 01:38:56.0305 4276upperdev (0ccadc7391021376edbb8aa649d04e68) C:\windows\system32\DRIVERS\usbser_lowerflt.sys 2011/04/30 01:38:56.0508 4276usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys 2011/04/30 01:38:56.0648 4276usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys 2011/04/30 01:38:56.0820 4276usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys 2011/04/30 01:38:56.0976 4276usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys 2011/04/30 01:38:57.0178 4276usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys 2011/04/30 01:38:57.0334 4276usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys 2011/04/30 01:38:57.0522 4276usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys 2011/04/30 01:38:57.0631 4276usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\windows\system32\DRIVERS\usbscan.sys 2011/04/30 01:38:57.0724 4276usbser (88701eca76145e2c011c0eeff0f7b70e) C:\windows\system32\drivers\usbser.sys 2011/04/30 01:38:57.0818 4276UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\windows\system32\DRIVERS\usbser_lowerfltj.sys 2011/04/30 01:38:57.0896 4276USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS 2011/04/30 01:38:57.0990 4276usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys 2011/04/30 01:38:58.0068 4276usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\windows\system32\Drivers\usbvideo.sys 2011/04/30 01:38:58.0161 4276vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys 2011/04/30 01:38:58.0239 4276vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys 2011/04/30 01:38:58.0333 4276VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys 2011/04/30 01:38:58.0411 4276vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys 2011/04/30 01:38:58.0489 4276viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys 2011/04/30 01:38:58.0536 4276ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys 2011/04/30 01:38:58.0598 4276viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys 2011/04/30 01:38:58.0692 4276volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys 2011/04/30 01:38:58.0754 4276volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys 2011/04/30 01:38:58.0832 4276volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys 2011/04/30 01:38:58.0941 4276vsbus (1c8a783e90c34d205596f1ab4a97e261) C:\windows\system32\DRIVERS\vsb.sys 2011/04/30 01:38:59.0035 4276vserial (3377daa1cb8cac46a538c236f5f3d58f) C:\windows\system32\DRIVERS\vserial.sys 2011/04/30 01:38:59.0144 4276vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys 2011/04/30 01:38:59.0347 4276vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys 2011/04/30 01:38:59.0503 4276vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys 2011/04/30 01:38:59.0643 4276WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys 2011/04/30 01:38:59.0721 4276WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2011/04/30 01:38:59.0768 4276Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2011/04/30 01:38:59.0940 4276Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys 2011/04/30 01:39:00.0033 4276Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys 2011/04/30 01:39:00.0189 4276WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys 2011/04/30 01:39:00.0236 4276WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys 2011/04/30 01:39:00.0470 4276WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys 2011/04/30 01:39:00.0657 4276WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys 2011/04/30 01:39:00.0798 4276ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys 2011/04/30 01:39:00.0876 4276WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys 2011/04/30 01:39:00.0969 4276WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys 2011/04/30 01:39:01.0094 4276================================================================================ 2011/04/30 01:39:01.0094 4276Scan finished 2011/04/30 01:39:01.0094 4276================================================================================ 2011/04/30 01:39:17.0817 5444================================================================================ 2011/04/30 01:39:17.0817 5444Scan started 2011/04/30 01:39:17.0817 5444Mode: Manual; 2011/04/30 01:39:17.0817 5444================================================================================ 2011/04/30 01:39:18.0878 54441394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys 2011/04/30 01:39:18.0940 5444ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys 2011/04/30 01:39:19.0050 5444AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys 2011/04/30 01:39:19.0206 5444adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys 2011/04/30 01:39:19.0377 5444adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys 2011/04/30 01:39:19.0518 5444adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys 2011/04/30 01:39:19.0627 5444AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys 2011/04/30 01:39:19.0689 5444AFS (be913403ed7219894b30e362fd8d4313) C:\windows\system32\drivers\AFS.sys 2011/04/30 01:39:19.0892 5444AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys 2011/04/30 01:39:20.0017 5444agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys 2011/04/30 01:39:20.0079 5444aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys 2011/04/30 01:39:20.0282 5444aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys 2011/04/30 01:39:20.0391 5444amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys 2011/04/30 01:39:20.0469 5444amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys 2011/04/30 01:39:20.0578 5444AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys 2011/04/30 01:39:20.0656 5444AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys 2011/04/30 01:39:20.0844 5444amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys 2011/04/30 01:39:21.0031 5444amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys 2011/04/30 01:39:21.0124 5444amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys 2011/04/30 01:39:21.0187 5444AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys 2011/04/30 01:39:21.0374 5444arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys 2011/04/30 01:39:21.0514 5444arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys 2011/04/30 01:39:21.0748 5444AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys 2011/04/30 01:39:21.0873 5444atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys 2011/04/30 01:39:22.0232 5444atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys 2011/04/30 01:39:22.0357 5444AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys 2011/04/30 01:39:22.0497 5444AVGIDSDriver (b93c0f409482d6c0e581caca51ae9c02) C:\windows\system32\DRIVERS\AVGIDSDriver.Sys 2011/04/30 01:39:22.0638 5444AVGIDSEH (13256fc72fa5b3f6d6e8c5957e579b7c) C:\windows\system32\DRIVERS\AVGIDSEH.Sys 2011/04/30 01:39:22.0731 5444AVGIDSFilter (fa0685cc51de5cfd804e7deaa6488e0e) C:\windows\system32\DRIVERS\AVGIDSFilter.Sys 2011/04/30 01:39:22.0840 5444AVGIDSShim (f788b51100d0f40ea176798cce954a1a) C:\windows\system32\DRIVERS\AVGIDSShim.Sys 2011/04/30 01:39:22.0996 5444Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\windows\system32\DRIVERS\avgldx86.sys 2011/04/30 01:39:23.0090 5444Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\windows\system32\DRIVERS\avgmfx86.sys 2011/04/30 01:39:23.0215 5444Avgrkx86 (ffbe8adeb1fd8640540bf6e4a137b3ef) C:\windows\system32\DRIVERS\avgrkx86.sys 2011/04/30 01:39:23.0355 5444Avgtdix (69e6adf5cbbdeb5f2b727c93937a5823) C:\windows\system32\DRIVERS\avgtdix.sys 2011/04/30 01:39:23.0464 5444b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys 2011/04/30 01:39:23.0605 5444b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys 2011/04/30 01:39:23.0667 5444Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys 2011/04/30 01:39:23.0808 5444blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys 2011/04/30 01:39:23.0901 5444bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys 2011/04/30 01:39:23.0964 5444BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys 2011/04/30 01:39:24.0057 5444BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys 2011/04/30 01:39:24.0135 5444Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys 2011/04/30 01:39:24.0229 5444BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys 2011/04/30 01:39:24.0291 5444BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys 2011/04/30 01:39:24.0385 5444BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys 2011/04/30 01:39:24.0447 5444BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys 2011/04/30 01:39:24.0556 5444cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys 2011/04/30 01:39:24.0619 5444cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys 2011/04/30 01:39:24.0728 5444circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys 2011/04/30 01:39:24.0775 5444CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys 2011/04/30 01:39:24.0884 5444CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys 2011/04/30 01:39:24.0978 5444cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys 2011/04/30 01:39:25.0040 5444CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys 2011/04/30 01:39:25.0102 5444Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys 2011/04/30 01:39:25.0165 5444CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys 2011/04/30 01:39:25.0243 5444crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys 2011/04/30 01:39:25.0321 5444DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys 2011/04/30 01:39:25.0399 5444discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys 2011/04/30 01:39:25.0461 5444Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys 2011/04/30 01:39:25.0555 5444Dot4 (b5e479eb83707dd698f66953e922042c) C:\windows\system32\DRIVERS\Dot4.sys 2011/04/30 01:39:25.0648 5444Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\windows\system32\DRIVERS\Dot4Prt.sys 2011/04/30 01:39:25.0758 5444dot4usb (cf491ff38d62143203c065260567e2f7) C:\windows\system32\DRIVERS\dot4usb.sys 2011/04/30 01:39:25.0867 5444drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys 2011/04/30 01:39:25.0914 5444DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\windows\System32\drivers\dxgkrnl.sys 2011/04/30 01:39:26.0054 5444ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys 2011/04/30 01:39:26.0179 5444elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys 2011/04/30 01:39:26.0241 5444epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\windows\system32\epmntdrv.sys 2011/04/30 01:39:26.0319 5444ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys 2011/04/30 01:39:26.0413 5444EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\windows\system32\EuGdiDrv.sys 2011/04/30 01:39:26.0506 5444exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys 2011/04/30 01:39:26.0569 5444fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys 2011/04/30 01:39:26.0631 5444fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys 2011/04/30 01:39:26.0725 5444FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys 2011/04/30 01:39:26.0803 5444Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys 2011/04/30 01:39:26.0850 5444flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys 2011/04/30 01:39:26.0928 5444FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys 2011/04/30 01:39:26.0990 5444FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys 2011/04/30 01:39:27.0068 5444Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys 2011/04/30 01:39:27.0130 5444fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys 2011/04/30 01:39:27.0193 5444gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys 2011/04/30 01:39:27.0271 5444GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2011/04/30 01:39:27.0333 5444hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys 2011/04/30 01:39:27.0411 5444HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys 2011/04/30 01:39:27.0489 5444HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/04/30 01:39:27.0583 5444HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys 2011/04/30 01:39:27.0676 5444HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys 2011/04/30 01:39:27.0786 5444HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys 2011/04/30 01:39:27.0879 5444HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys 2011/04/30 01:39:28.0004 5444HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys 2011/04/30 01:39:28.0098 5444HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys 2011/04/30 01:39:28.0238 5444hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys 2011/04/30 01:39:28.0363 5444i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys 2011/04/30 01:39:28.0472 5444iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys 2011/04/30 01:39:28.0581 5444iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys 2011/04/30 01:39:28.0737 5444IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys 2011/04/30 01:39:28.0846 5444intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys 2011/04/30 01:39:28.0956 5444intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys 2011/04/30 01:39:29.0018 5444IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/04/30 01:39:29.0096 5444IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys 2011/04/30 01:39:29.0205 5444IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys 2011/04/30 01:39:29.0299 5444IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys 2011/04/30 01:39:29.0392 5444isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys 2011/04/30 01:39:29.0439 5444iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys 2011/04/30 01:39:29.0533 5444kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys 2011/04/30 01:39:29.0626 5444kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys 2011/04/30 01:39:29.0720 5444KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys 2011/04/30 01:39:29.0767 5444KSecPkg (26c046977e85b95036453d7b88ba1820) C:\windows\system32\Drivers\ksecpkg.sys 2011/04/30 01:39:29.0860 5444Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 2011/04/30 01:39:29.0923 5444Lbd (336abe8721cbc3110f1c6426da633417) C:\windows\system32\DRIVERS\Lbd.sys 2011/04/30 01:39:29.0985 5444lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys 2011/04/30 01:39:30.0079 5444LPCFilter (6e3d3816749e107883eec5734ce44493) C:\windows\system32\DRIVERS\LPCFilter.sys 2011/04/30 01:39:30.0188 5444LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys 2011/04/30 01:39:30.0297 5444LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys 2011/04/30 01:39:30.0391 5444LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys 2011/04/30 01:39:30.0500 5444LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys 2011/04/30 01:39:30.0594 5444luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys 2011/04/30 01:39:30.0687 5444megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys 2011/04/30 01:39:30.0796 5444MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys 2011/04/30 01:39:30.0890 5444Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys 2011/04/30 01:39:30.0968 5444monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys 2011/04/30 01:39:31.0077 5444mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys 2011/04/30 01:39:31.0171 5444mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys 2011/04/30 01:39:31.0264 5444mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys 2011/04/30 01:39:31.0358 5444mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys 2011/04/30 01:39:31.0452 5444mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys 2011/04/30 01:39:31.0561 5444MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys 2011/04/30 01:39:31.0654 5444mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/04/30 01:39:31.0764 5444mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/04/30 01:39:31.0857 5444mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/04/30 01:39:31.0951 5444msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys 2011/04/30 01:39:32.0029 5444msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys 2011/04/30 01:39:32.0138 5444Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys 2011/04/30 01:39:32.0232 5444mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys 2011/04/30 01:39:32.0278 5444msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys 2011/04/30 01:39:32.0372 5444MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys 2011/04/30 01:39:32.0466 5444MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys 2011/04/30 01:39:32.0575 5444MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys 2011/04/30 01:39:32.0653 5444MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys 2011/04/30 01:39:32.0762 5444mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys 2011/04/30 01:39:32.0856 5444MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys 2011/04/30 01:39:32.0949 5444MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys 2011/04/30 01:39:33.0012 5444Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys 2011/04/30 01:39:33.0090 5444MxlW2k (d37a535bbe77a16c232969c6882b524b) C:\windows\system32\drivers\MxlW2k.sys 2011/04/30 01:39:33.0199 5444NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys 2011/04/30 01:39:33.0308 5444NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys 2011/04/30 01:39:33.0402 5444NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys 2011/04/30 01:39:33.0495 5444NdisTapi (e4a8aec125a2e43a9e32afeea7Please try running ComboFix again.Wow, you certainly know your stuff!! the gadgets on my desktop are now displaying properly again and Combofix actually worked this time!! Thanks heaps Dave! Although Combofix did ask me to remove AVG in order to run, which I did. Just about to reinstall AVG now. Below is Combofix's log... ----------------------------------------------------------------------------------------------------------------------------------------------- ComboFix 11-05-02.03 - Chris 03/05/2011 10:49:04.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.2942.1963 [GMT 10:00] Running from: c:\users\Chris\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\xp c:\programdata\xp\EBLib.dll c:\programdata\xp\TPwSav.sys c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73} c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome.manifest c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome\content\_cfg.js c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome\content\overlay.xul c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\install.rdf c:\users\Chris\AppData\Local\Temp\explorer.dat c:\users\Chris\AppData\Local\Temp\wininit.dat c:\users\Chris\AppData\Roaming\Adobe\plugs c:\users\Chris\AppData\Roaming\Adobe\shed c:\users\Chris\AppData\Roaming\Bitrix Security c:\users\Chris\AppData\Roaming\Bitrix Security\bnnhjx_shrd c:\users\Chris\AppData\Roaming\Bitrix Security\ddljzh c:\users\Chris\AppData\Roaming\Bitrix Security\fg.txt c:\users\Chris\AppData\Roaming\Bitrix Security\jje.txt c:\users\Chris\AppData\Roaming\Bitrix Security\ljgh.txt c:\users\Chris\AppData\Roaming\Bitrix Security\mcx.txt c:\users\Chris\AppData\Roaming\Bitrix Security\mxd1.txt c:\users\Chris\AppData\Roaming\Bitrix Security\qnf.txt c:\users\Chris\AppData\Roaming\Xyevw c:\users\Chris\AppData\Roaming\Xyevw\ydird.tui C:\Windows Restore c:\windows restore\Uninstall Windows Restore.lnk c:\windows restore\Windows Restore.lnk c:\windows\desktop . . ((((((((((((((((((((((((( Files Created from 2011-04-03 to 2011-05-03 ))))))))))))))))))))))))))))))) . . 2011-05-03 00:54 . 2011-05-03 00:55--------d-----w-c:\users\Chris\AppData\Local\temp 2011-05-03 00:54 . 2011-05-03 00:54--------d-----w-c:\users\Default\AppData\Local\temp 2011-05-03 00:44 . 2011-05-03 00:45--------d-----w-C:\32788R22FWJFW 2011-04-29 10:51 . 2011-04-29 10:52--------d-----w-c:\program files\Common Files\Nero 2011-04-29 10:51 . 2011-04-29 10:51--------d-----w-c:\program files\Nero 2011-04-29 09:26 . 2011-04-29 09:26--------d-----w-c:\program files\Nero Wave Editor 2011-04-29 09:26 . 2011-04-29 09:26--------d-----w-c:\windows\Nero Wave Editor 2011-04-27 07:23 . 2011-04-27 07:23--------d-----w-c:\users\Chris\AppData\Roaming\AVG10 2011-04-27 04:31 . 2011-05-03 00:40--------d-----w-c:\programdata\AVG10 2011-04-26 12:12 . 2011-05-03 00:39--------d-----w-c:\programdata\MFAData 2011-04-24 13:54 . 2011-04-24 14:43--------d-----w-c:\program files\Toolbar Uninstaller 2011-04-23 16:49 . 2011-04-23 16:49--------d-----w-c:\program files\uTorrent 2011-04-22 23:26 . 2011-04-22 23:26--------d-----w-c:\program files\Bulk Rename Utility 2011-04-22 15:52 . 2011-04-23 16:48--------d-----w-c:\program files\BitTorrent 2011-04-22 15:51 . 2011-04-23 16:48--------d-----w-c:\users\Chris\AppData\Roaming\BitTorrent 2011-04-17 12:10 . 2011-04-17 12:10--------d-----w-c:\program files\TrendMicro 2011-04-17 11:59 . 2011-04-17 11:59--------d-----w-c:\program files\Common Files\Java 2011-04-17 11:59 . 2011-02-02 11:40472808----a-w-c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-04-17 11:59 . 2011-02-02 11:40472808----a-w-c:\windows\system32\deployJava1.dll 2011-04-13 04:10 . 2011-04-07 07:5916432----a-w-c:\windows\system32\lsdelete.exe 2011-04-13 03:18 . 2011-04-01 07:2264512----a-w-c:\windows\system32\drivers\Lbd.sys 2011-04-13 03:17 . 2011-04-13 03:1798392----a-w-c:\windows\system32\drivers\SBREDrv.sys 2011-04-13 03:17 . 2011-04-13 03:17--------d-----w-c:\users\Chris\AppData\Local\Sunbelt Software 2011-04-13 03:15 . 2011-04-13 03:15--------dc-h--w-c:\programdata\{6A395471-4AA3-4072-AE1B-9B69A97AD164} 2011-04-13 03:12 . 2011-04-13 03:16--------d-----w-c:\programdata\Lavasoft 2011-04-13 03:12 . 2011-04-13 03:12--------d-----w-c:\program files\Lavasoft 2011-04-13 03:08 . 2011-04-17 08:31--------d-----w-c:\programdata\Spybot - Search & Destroy 2011-04-13 03:08 . 2011-04-13 03:08--------d-----w-c:\program files\Spybot - Search & Destroy 2011-04-13 01:25 . 2011-04-13 01:32--------d-----w-c:\users\Chris\AppData\Roaming\GetRightToGo 2011-04-12 06:55 . 2011-04-12 06:55--------d-----w-C:\VundoFix Backups 2011-04-12 02:16 . 2008-12-08 02:5357344----a-w-c:\windows\system32\ff_vfw.dll 2011-04-12 02:16 . 2008-06-08 12:5860273----a-w-c:\windows\system32\pthreadGC2.dll 2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\ffdshow 2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\Haali 2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\AviSynth 2.5 2011-04-12 02:15 . 2010-08-26 13:45147456----a-w-c:\windows\system32\stQTSource.ax 2011-04-12 02:15 . 2010-07-15 01:30290816----a-w-c:\windows\system32\stFLVSource.ax 2011-04-12 02:15 . 2011-04-12 02:16--------d-----w-c:\program files\Sothink Video Converter 2011-04-12 02:15 . 2009-08-16 23:541184984----a-w-c:\windows\system32\wvc1dmod.dll 2011-04-12 02:15 . 2009-08-16 23:54438272----a-w-c:\windows\system32\Mpeg2DecFilter.ax 2011-04-12 02:15 . 2009-08-16 23:54217088----a-w-c:\windows\system32\CoreFLACDecoder.ax 2011-04-12 02:15 . 2009-03-17 07:3870656----a-w-c:\windows\system32\RLAPEDec.ax 2011-04-12 02:12 . 2011-04-12 02:15--------d-----w-c:\program files\Common Files\SourceTec 2011-04-12 02:12 . 2011-04-12 02:12--------d-----w-c:\program files\SourceTec 2011-04-07 10:18 . 2011-04-12 05:32--------d-----w-c:\windows\PIF . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-12 02:15 . 2010-08-15 01:580----a-w-c:\users\Chris\AppData\Local\Xxepobesitefe.bin 2011-03-11 10:50 . 2010-06-21 10:4636734----a-w-c:\windows\system32\OggDSuninst.exe 2011-03-11 10:22 . 2011-03-11 10:22119350----a-w-c:\windows\File Renamer - Basic Uninstaller.exe 2011-03-01 09:31 . 2011-03-01 09:3177004----a-w-c:\windows\system32\drivers\AFS.SYS 2011-02-12 15:09 . 2011-02-12 15:09388096----a-r-c:\users\Chris\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-01-26 12:11 . 2011-03-08 14:17444283----a-w-c:\program files\Common Files\WinPcapNmap.exe . . ((((((((((((((((((((((((((((((((((((( REG Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun" [X] "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-10 352256] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 425984] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-07-14 8704] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] "{F552DDE6-2090-4bf4-B924-6141E87789A5}"= "c:\program files\Greatis\RegRunSuite\RRShell.dll" [2004-11-01 368711] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GabPath . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPlusAgent] 2005-02-18 19:49225280----a-w-c:\program files\iriver\iriver plus\iAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray] 2010-05-14 00:321479680----a-w-c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Regrun2] 2006-12-19 02:43350208----a-w-c:\progra~1\Greatis\REGRUN~1\WatchDog.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2009-07-29 04:127625248------w-c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-10-29 04:49249064----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe . R0 AFS;AFS; R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 135664] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-05-11 14216] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-05-11 8456] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 135664] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys R3 PortlUSB;PortlUSB;c:\windows\system32\DRIVERS\H10USB.sys [2004-06-24 7552] R3 RegGuard;RegGuard;c:\windows\system32\Drivers\regguard.sys [2010-08-15 25773] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-31 171520] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872] R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-01 64512] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-04-26 2146496] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704] S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\RSelect\RSelSvc.exe [2009-07-07 62832] S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and GENERAL Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-01 15232] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-23 24064] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-23 167936] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPServiceREG_MULTI_SZ HPSLPSVC hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-05-03 c:\windows\Tasks\GlaryInitialize.job - c:\program files\Glary Utilities\initialize.exe [2010-11-13 10:55] . 2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 10:00] . 2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 10:00] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\ceofca98.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=LMW2&o=16054&locale=en_US&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: PC Sync 2 Synchronisation Extension: [emailprotected] - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync FF - Ext: HP Smart Web Printing: [emailprotected] - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} FF - Ext: TVU Web Player: [emailprotected] - %profile%\extensions\[emailprotected] FF - Ext: Sothink Web Video Downloader for Firefox: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08} - %profile%\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08} FF - Ext: Conduit Engine : [emailprotected] - %profile%\extensions\[emailprotected] FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} FF - Ext: HP Smart Web Printing: [emailprotected] - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file) HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe MSConfigStartUp-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe MSConfigStartUp-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe AddRemove-TOSHIBA Software Modem - c:\windows\agrsmdel . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-3225168310-450358799-2518029026-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0619892F-D16A-973B-E705-9F49F072D162}*] "lahilkapdgongndefaipeipf"=hex:65,62,64,62,62,6d,62,66,70,63,67,6a,62,6e,67,6b, 65,63,6f,6a,67,6f,65,6d,63,62,68,67,6d,6f,6a,68,6d,6e,67,6f,64,6a,6b,62,61,\ "haihofnpmgmhjfmc"=hex:63,62,6e,66,68,69,6c,6e,68,67,68,6e,64,6d,6b,61,61,6c, 6c,6f,61,6e,6c,66,6b,6b,6b,64,6d,62,70,66,6b,6b,6c,6f,6f,66,00,00 "haihofnpbfmnlepb"=hex:6f,61,66,69,65,67,64,68,62,66,6c,6e,63,62,6c,6c,6b,6d, 67,70,6d,65,64,6c,68,62,6c,67,61,61,00,66 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:00000009 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . COMPLETION time: 2011-05-03 10:56:22 ComboFix-quarantined-files.txt 2011-05-03 00:56 . Pre-Run: 201,441,955,840 bytes free POST-Run: 203,345,326,080 bytes free . - - End Of File - - 6E37FEA35733863D493B0D741ABB367EThat looks good. Don't despair. We're almost at the end. P2P - I see you have P2P software installed on your machine (\uTorrent and BitTorrent). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. ************************************************* Re-running ComboFix to remove infections:
Download Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. |
|
| 253. |
Solve : Major Virus Problem? |
|
Answer» Downloaded comodo. Also, if in the near future I get a new PC, I take it no matter what I should]You don't need CCleaner. You can do the same thing by doing a disk cleanup regularly. SAS and MBAM are not active programs unless you buy them. You can have them on your computer and make it a habit to update them and run them on a regular basis. A third-party firewall is a good idea and spywareblaster is also a good idea. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 254. |
Solve : Re: My computer is sending out emails! Virus?? |
|
Answer» NEED some help PLEASE??? my hotmail account has STARTED to send out SPAM mail?? |
|
| 255. |
Solve : Multiple Copies of explorer.exe? |
|
Answer» That's good. If there are no other issues, let's do some cleanup.
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run UNINTERRUPTED until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************************** Use the Secunia Software INSPECTOR to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all CRITICAL updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Dave, I ran combofix /uninstall, but it did not remove the folders etc that I think it created. It actually added one c:\combofix. Here's a screenshot of the root of c:\: http://clip2net.com/clip/m80407/1306275960-clip-70kb.jpg. I don't think c:\boot(which has language folders and memtest.exe), c:\combofix, c:\perflogs(empty except for admin sub folder), c:\programdata, c:\recovery(empty), and c:\virtualroot(empty) were there prior to this malware removal process. What should I do about these? I think I could delete the empty ones, but will wait until I hear from you. I noticed a new exe called nircmd.exe that's appeared that comodo firewall sandboxed. There is one folder missing that was on c:\ called c:\ooobox or something like that, that had combofix files in it. skilz853Quote I ran combofix /uninstall, but it did not remove the folders etc that I think it created. It actually added one c:\combofix.I cleaned a computer this weekend in my home and the same thing happened when I tried to uninstall ComboFix. I ended up deleting it. I'm going to investigate the validity of that method of uninstalling ComboFix. This should remove it. Download OTL to your desktop. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
I think all is well now. Thanks again, skilz853You're welcome. I will lock this thread. If you need it re-opened, please send me a pm or start a new thread. |
|
| 256. |
Solve : PC Performance and Stability Report? |
|
Answer» Do you have any idea where this sorta thing would have come from? This isn't the first time I've gotten it on my computer.Quote I just noticed that I now have a shortcut to that Windows Vista Recovery thing on my desktop. Can i just delete it? or not just yet?Your choice. If you don't want it, delete it. It's not something your going to use very often, if ever. Quote Do you have any idea where this sorta thing would have come from? This isn't the first time I've gotten it on my computer.Probably from out-of-date programs. See here. Download Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * UNZIP SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.Results of screen317's Security Check version 0.99.11 Windows Vista Service Pack 2 (UAC is enabled) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! ESET Online Scanner v3 Microsoft Security Essentials WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) SE Runtime Environment 6 Adobe Flash Player Adobe Reader 7.0.8 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSMpEng.exe Microsoft Security Essentials msseces.exe ``````````End of Log```````````` Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. ****************************************************** Once the above is done we can do some cleanup. To uninstall ComboFix
(Note: Make sure there's a SPACE between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the CLEANING process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. **************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thanks so much for your help!!!!!!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 257. |
Solve : "System Tool 2011" virus + Taskbar keeps swithching themes? |
|
Answer» Thanks for the fix Okay, the complete scan finished, however, there is no option to report incurable. Should I just save the report list and exit the program afterwards? Please try running the ESET scan again.Dr web Report list
********************************************** To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. This will give you a new, clean Restore Point. ******************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make SURE you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ****************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! What are the programs that OTL is supposed to remove? If they are not removed will it make my computer slow to start up?Quote What are the programs that OTL is supposed to remove?They will not make your slow to start unless you have them running at startup. Here's a handy program to check to see what's running at startup. !Killbox *.run _backupD _OTL _OTListIt _OTM _OTMoveIt _OTS _OTScanIt 404fix.exe Avenger avenger.exe avenger.txt avenger.zip AWF.txt BFU bfu.zip catchme catchme.exe cleanup.txt ComboFix ComboFix*.txt combofix.exe combo-fix.exe Combo-Fix.sys dds.com dds.pif dds.scr Deckard delete.bat deljob deljob.exe dss.exe dumphive.exe erdnt\subs Extras.txt fdsv.exe FindAWF.exe fixwareout fixwareout.exe fsbl*.log fsbl.exe gmer gmer.dll gmer.exe gmer.ini gmer.log gmer.sys gmer_uninstall.cmd grep.exe haxfix.exe haxfix.txt iedfix.exe killbox.exe logit.txt Lop SD lopR.txt LopSD.exe moveex.exe nircmd.exe NoLop.exe NoLop.txt NoLopOLD.txt OTL.exe OTL.txt OTListIt.txt OTListIt2.exe OTM.exe OTMoveIt.exe OTMoveIt2.exe OTMoveIt3.exe OTS.exe OTS.txt OTScanIt OTScanIt.exe OTScanIt2 OTScanIt2.exe OTViewIt.exe OTViewIt.txt QooBox rapport.txt Rooter$ Rooter.exe Rooter.txt RSIT RSIT.exe Runscanner Runscanner.exe Runscanner.net Runscanner.zip Rustbfix rustbfix.exe SDFix sdfix.exe sed.exe Silent Runners.vbs SmitfraudFix SmitfraudFix.exe swreg.exe Swsc.exe Swxcacls.exe SysInsite tmp.reg vacfix.exe vcclsid.exe VFind.exe VundoFix Backups VundoFix.exe vundofix.txt vundofix.vft win32delfkil.exe windelf.txt WinPfind winpfind.exe WinPFind35u WinPFind35u.exe WinPFind3u WinPFind3u.exe WS2Fix.exe zip.exe StartupLite Download StartupLite by MalwareBytes to your Desktop. Doubleclick StartupLite.exe to launch the program. Ensure the DISABLE box is checked. Click CONTINUE. A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer. Re-start your computer. |
|
| 258. |
Solve : Laptop infected...? |
|
Answer» It would appear that your computer is clean. Any other issues?Nicest words I have heard all week. Thank you so much. Any recommendations in terms of how often to run the Avira AntiVirus, Malware and Spybot?Your AV is active all the time. You shouldn't need to run any scans with it. You can update and run SAS and MBAM weekly to keep the bugs out. The same for Spybot. If you have SpywareBlaster, keep it up-to- date also. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a SPACE between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your WORK before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- GO to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Good luck from New Brunswick and have a good playoff run. |
|
| 259. |
Solve : Something blocking me from AV websites, have done required steps? |
|
Answer» Okay, i EASILY went to the Start>Run and did that.
|
|
| 260. |
Solve : HJT made an evaluation? |
|
Answer» My PC can not access the internet. DIRECTX 9 was uninstalled "per se" and can not reinstall it. I can not access CD drive. Would LIKE your recommendations DirectX 9 was uninstalled "per se" DirectX 9 was uninstalled "by itself" ?? How did this happen? Can you install it from here http://directx.en.softonic.com/ I do not know how it happened. Just happened. I can not reinstall it, the message is that it is not compatible with XP! Have you recently done a System restore? Check the 'Important Notes' here http://www.softwarepatch.com/windows/directx.html Quote DirectX is a crucial system component. It cannot be uninstalled without reinstalling your operating system (!) or performing a system restore/system recovery. You can also use the guide.Every TIME I turn on my PC it's getting worse, slower. He must have been INFECTED by a dammed virus. I believe the solution is a complete reinstallation Do you still require help?No thanks. After hours of investigation, i had to reinstall everything. Too bad |
|
| 261. |
Solve : Is my PC infected?? |
|
Answer» OK SuperDave that has been done. What do you suggest next? Please try deleting one of those shortcuts and create a new one and see if it works. Well SuperDave I had tried that several times the other day with no change. Thought that I'd give it another shot tonight and now it appears that the problem now includes more that the desktop. This is new. Most folders /files within Computer/Documents will not open properly now without a lot of coaxing. WOW !!Ok. Let's try this: Please download SREng
Ok. Let's try this: Hi SuperDave I ran the app. it found one error. "VBS handle the VBS open method (whatever that is )" and I deleted it. Since my last post I have done the following; created a few new desktop icons, ran the app. that you just suggested and I'm now trying another USB mouse. Now perhaps it's just wishful thinking but some files/programs(not necessarily the new ones that I created) seem to now open a little easier. I'm going to check with a colleague about this problem. In the meantime, please try this: Do you have your OS CD/DVD? If so, 1/ Click the Start button. 2/ From the Start Menu, Click All programs FOLLOWED by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has COMPLETED, Close the command prompt window. Quote from: SuperDave on February 25, 2011, 05:08:07 PM I'm going to check with a colleague about this problem. In the meantime, please try this: Unfortunately SuperDave all that came with my system is two recovery disks. natregurlHi SuperDave . Well I found the problem (that I was having with opening programs/shortcuts etc.) was caused by (as embarrassing as it is) the mouse double-click speed. Besides everything ELSE I had looked at this several times over the past day or so and thought that it looked OK. All I did was slow it down ever so slightly and the problem appears cured. I certainly have no idea if it was changed,how it was changed or why it required slowing down?? Anyway, very sorry to have put you through this particular problem. So now that this has been overcome, as well as no more corrupted search provider messages, no hanging downloads, no further internet connection problems, is there any other things that you would have me check. My PC now seems to be running great now and I'm wondering if you think my PC is clean? Thanks so much.Quote So now that this has been overcome, as well as no more corrupted search provider messages, no hanging downloads, no further internet connection problems, is there any other things that you would have me check. My PC now seems to be running great now and I'm wondering if you think my PC is clean? Thanks so much. That is good news. I was thinking that it was not infection related. Judging by all the scans we ran, I would say that your computer is clean. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Well SuperDave, I followed your instructions re; last post, and I sincerely appreciate all of your help. I feel very fortunate that you were there to help me and I'm also very confident that all the other CH members that you have helped feel the way that I do. Thank you very much and God Bless. naturegurlYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 262. |
Solve : no windows update, browser redirects, no task bar or icons at startup? |
|
Answer» Dave, when I ran the Secunia Software Inspector it said that I needed to update my Internet Explorer and I should go to windows update to get a bunch of missing patches. But when I go to windows update it TELLS me there are no updates for my computer. What should I do? Here is the info from the scan: when I go to windows update it tells me there are no updates for my computer. What should I do?I would tend to agree with MicroSoft. Quote This installation of Microsoft Internet Explorer 8.x is insecure and potentially exposes your system to security threats!I think IE9 is out now. I'll have to upgrade mine soon. Quote I have downloaded the upgrade several times, and when I check from in firefox it says I am running version 3.5.16. I also checked for updates from within firefox and it said no updates were available.I wouldn't worry about Firefox too MUCH, if I were you. One day you'll open it and it will tell you to upgrade. My version is also 3.5.16 and I upgrade not too long ago.Ok. Followed all your instructions and suggestions. So far machine is running well. Thanks so much for all your help!! |
|
| 263. |
Solve : Annoying Google Redirect? |
|
Answer» Are you still getting the google re-directs?
•Click the button. •Accept any SECURITY warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt No Google re-directs so far. I installed the newest version of Java. The ESET scanner did not find any threatsGood. Let's do some cleanup. You can try this to fix the slow startup. How much time are talking about? StartupLite Download StartupLite by MalwareBytes to your Desktop. Doubleclick StartupLite.exe to launch the program. Ensure the Disable box is checked. Click Continue. A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer. Re-start your computer. **************************************************** To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!I'm having trouble uninstalling ComboFix. I need to deactivate my antivirus, but my desktop(along with the taskbar and start button) is not showing up. It would usually show up in about three minutes, but recently its just stopped appearing.Quote I'm having trouble uninstalling ComboFix. I need to deactivate my antivirusYou don't have to disable your AV to remove ComboFix. Quote but my desktop(along with the taskbar and start button) is not showing up. It would usually show up in about three minutes, but recently its just stopped appearing.Did this just start to happen recently or has it been doing it all along?Ok I ran all the programs and uninstalled ComboFix. Quote Did this just start to happen recently or has it been doing it all along?It has been happening all along.Quote It has been happening all along.I don't believe this is a malware issue. You should create a new thread in the proper software forum concerning this. Can you give me a SCREENPRINT of this? How to post screenshots or images Thanks for the help so far SuperDave. Notice that the Start MENU, desktop items, and taskbar are all gone. Task Manager is the only way for me to open applications/programs Uploaded with ImageShack.usI see. Let's try this.
nothing happens when I click on Run.You're not supposed to click on Run. You're supposed to click on this: Double click unhide.exe to run the tool. ok its been done, but there was no effect. I have been changing settings in msconfig, and the desktop will occasionally show up. However, it only shows up on the diagnostic setting. Maybe the problem is with the settings there. |
|
| 264. |
Solve : Trojan.Vundo and more? |
|
Answer» Ok. Please try uninstalling AVG using this REMOVAL tool.
Download Security CHECK by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.ComboFix 11-05-26.05 - Rebecca Woods 05/27/2011 12:17:04.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1438 [GMT -5:00] Running from: c:\documents and settings\Rebecca Woods\Desktop\ComboFix.exe AV: AVG Anti-Virus *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A} . . ((((((((((((((((((((((((( Files Created from 2011-04-27 to 2011-05-27 ))))))))))))))))))))))))))))))) . . 2011-05-27 17:05 . 2011-05-09 18:466962000----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-05-27 17:04 . 2011-05-09 18:466962000----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F37D01F6-A895-4DC3-B951-56B8F9E6E01D}\mpengine.dll 2011-05-27 12:32 . 2011-05-27 12:33--------d-----w-c:\windows\system32\MpEngineStore 2011-05-25 22:39 . 2011-05-25 22:39--------d-----w-C:\Pro 2011-05-21 19:49 . 2011-05-21 19:49--------d-----w-C:\_OTL 2011-05-21 12:06 . 2011-05-21 12:06388096----a-r-c:\documents and settings\Rebecca Woods\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-05-19 01:55 . 2011-05-19 01:55--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\Malwarebytes 2011-05-19 01:54 . 2010-12-20 23:0938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-19 01:54 . 2011-05-19 01:54--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2011-05-19 01:54 . 2010-12-20 23:0820952----a-w-c:\windows\system32\drivers\mbam.sys 2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\SUPERAntiSpyware.com 2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2011-05-18 22:12 . 2011-05-18 22:123063136----a-w-C:\ccsetup306.exe 2011-05-18 18:27 . 2011-05-18 19:16--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor 2011-05-18 18:27 . 2011-05-18 18:27--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\OnlineArmor 2011-05-18 18:26 . 2011-04-06 18:0239048----a-w-c:\windows\system32\drivers\oahlp32.sys 2011-05-18 18:26 . 2011-04-06 18:0129464----a-w-c:\windows\system32\drivers\OAnet.sys 2011-05-18 18:26 . 2011-04-06 18:0125192----a-w-c:\windows\system32\drivers\OAmon.sys 2011-05-18 18:26 . 2011-04-06 18:01205864----a-w-c:\windows\system32\drivers\OADriver.sys 2011-05-18 14:16 . 2011-05-18 18:11--------d-----w-c:\documents and settings\All Users\Application Data\iolo 2011-05-17 21:01 . 2011-05-17 21:01--------d--h--w-c:\windows\system32\GroupPolicy 2011-05-17 20:31 . 2010-10-19 20:51222080------w-c:\windows\system32\MpSigStub.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-14 10:07 . 2010-07-07 13:42472808----a-w-c:\windows\system32\deployJava1.dll 2011-04-14 07:40 . 2008-06-26 08:3073728----a-w-c:\windows\system32\javacpl.cpl 2011-03-07 05:33 . 2004-08-10 18:02692736---ha-w-c:\windows\system32\inetcomm.dll 2011-03-04 06:37 . 2004-08-10 17:51420864---ha-w-c:\windows\system32\vbscript.dll 2011-03-03 14:47 . 2010-01-06 16:51398760---ha-r-c:\windows\system32\cpnprt2.cid 2011-03-03 13:21 . 2004-08-10 17:511857920---ha-w-c:\windows\system32\win32k.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-25 2424192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 162584] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 2183168] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936] "SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 405504] "KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320] "eBook Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\eBook Library Launcher.exe" [2009-10-20 902504] "AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144] "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-17 98304] "@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-04-06 2477032] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "StartUp This"="c:\program files\Laplink\PCmover\LaunchSt.exe" [2007-11-01 247088] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2008-07-21 13:4510536----a-w-c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2010-10-28 10:1364592----a-w-c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"= "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= "c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"= "c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"= "c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"= "c:\\Program Files\\real\\realplayer\\realplay.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC "67:UDP"= 67:UDP:DHCP Discovery Service . R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/18/2011 1:26 PM 205864] R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [5/18/2011 1:26 PM 39048] R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/18/2011 1:26 PM 25192] R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/18/2011 1:26 PM 29464] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 1:27 PM 1074568] R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/29/2010 10:30 AM 10448] S1 MpKslf74c7e6c;MpKslf74c7e6c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys [?] S2 gupdate1ca25d2787f1ffc;Google Update Service (gupdate1ca25d2787f1ffc);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104] S2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [5/18/2011 1:26 PM 381512] S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [5/18/2011 1:26 PM 4326472] S3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/12/2009 4:20 PM 401920] S3 cpuz134;cpuz134;\??\c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/2/2010 3:46 PM 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104] S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [8/3/2005 3:59 PM 4736] S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [8/3/2005 3:59 PM 8960] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 . Contents of the 'Scheduled Tasks' folder . 2011-05-27 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-26 22:20] . 2011-05-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21] . 2011-05-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21] . 2011-05-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-109568239-1760306711-3351161423-1009.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09] . 2011-05-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-109568239-1760306711-3351161423-1009.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080626 TCP: DhcpNameServer = 208.180.42.68 208.180.42.100 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-05-27 12:25 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(592) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\windows\System32\BCMLogon.dll c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\MFC80.DLL c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll . - - - - - - - > 'explorer.exe'(2492) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2011-05-27 12:27:58 ComboFix-quarantined-files.txt 2011-05-27 17:27 ComboFix2.txt 2011-05-26 16:09 . Pre-Run: 107,173,453,824 bytes free Post-Run: 107,162,755,072 bytes free . - - End Of File - - BC2C36FF47868 i would still like to see the Security Check log. SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
esults of screen317's Security Check version 0.99.12 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Online Armor 5.0 Microsoft Security Essentials Antivirus out of date! (On Access scanning disabled!) ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) 6 Update 25 Adobe Flash Player Adobe Reader 9.4.2 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSMpEng.exe Tall Emu Online Armor OAhlp.exe Microsoft Security Essentials msseces.exe Microsoft Security Client Antimalware MsMpEng.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe ``````````End of Log```````````` Thanks. Your MicroSoft Security Essentials is out-of-date. Please update it. Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and ENTER Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version.As soon as I started to run the Sysprot program I got the lovely blue screen that said windows encountered a problem and was shutting down. Now my computer won't load past the desktop background. RebeccaQuote Now my computer won't load past the desktop background. Once you get to the desktop, it's loaded. Do you mean you can't open anything? Can you give me a screenshot. How to post screenshots or images No desktop icons, no start menu. Just the background nothing on it with the mouse arrow frozen. RebeccaPlease see if you can re-boot in Safe Mode. If you can, please try System Restore to a date before you tried Sysprot. It looks like everything is restored. I updated MS Essentials and Adobe Reader. Rebecca |
|
| 265. |
Solve : white smoke translator help!? |
|
Answer» BUMPHi susan. Something must have HAPPENED to DMJ. I'll try to get a message to him. Don't despair.Sorry, my ISP situation has been crazy.
|
|
| 266. |
Solve : XP virus? |
|
Answer» I managed to find the original LOG. This is much easier now, as I can access the web on this laptop now and windows has stopped crashing. 2011/01/12 20:52:46.0158TDSS rootkit removing tool 2.4.13.0 Jan 12 2011 09:51:11 That's great. Now let's run another scan, just to make sure. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop USING a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt There was an issue HALF way through the scan. I was working on my Vista laptop and turned to my right to look at the XP (this) laptop and I was at about 45mins in and the laptop started a restart. No idea why as I was not watching the screen. I could then no longer connect to the internet. I logged off and logged back on and everything was fine. I restarted the scan and these are the results. Quote C:\WINDOWS\Temp\tpqf.tmp\setup.exeWin32/TrojanDownloader.Agent.QME trojancleaned by deleting - quarantinedThese computers are strange devices. If there are no other issues, let's do some cleanup. You may keep SAS and MBAM, if you wish. Update them and run them regularly. All the others can be uninstalled/deleted To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. This will give you a new, clean Restore POINT. ****************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Thank you for the help. I'm already a member of WOT as they have given both my websites a clean bill of health. Although I'm shutting geek-shack down in about 10mins. Your a star and thank you so much for spending your free time to help me. It is much appreciated. |
|
| 267. |
Solve : Trojan downloader/dropper/virus(es)? |
|
Answer» So Windows Security Essentials has been detecting trojan viruses lately, which I have been removing/quarantining as appropriate and then following up with a MBAM scan and removing whatever is shown there. Last night, however, a virus Trojan:DOS/Alureon.A was detected and can't be deleted. I also noticed that a number of programs have been installed without my permission, namely SweetIM for Messenger 3.4, SweetIM Toobal for Internet Explorer 4.1, Whitesmoke (which seems to be a big problem), and Street-Ads Browser Enhancer, none of which I am able to uninstall. I also seem to have a Google redirect virus, but only when I am using Astrill (VPN) which I use as I am in China currently. For future reference, installing a new hard drive would fix the problem, right?Yes but you will need to install your OS and, from what I understand, the disk(s) are at home. Download DDS from HERE or HERE and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copying and pasting it into the reply. *************************************************** Download Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. |
|
| 268. |
Solve : Malware after bad link from infected friend? |
|
Answer» Ok. I'm satisfied. How's your computer running? Any other issues?No - other than facebook sometimes (rare) logging me out on its own, but I guess that's a facebook issue.Ok. Let's do some cleanup.
************************************************* To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. ********************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and SCROLL down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ACTIVEX programs to run on your computer. Also stop certain cookies from being ADDED to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. GUIDE: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! I would like to sincerely thank you in helping me deal with this infection!Quote from: Harres on January 16, 2011, 06:11:53 PM I would like to sincerely thank you in helping me deal with this infection!You're welcome. Tell your friends about us here at CH. I will lock this thread. If you need it opened for any reason, pm me. |
|
| 269. |
Solve : Requesting help to clean PC? |
|
Answer» It says "no action taken". Please run it again and clean the infections. Let's do some cleanup.
************************************************ To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When TURNING off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. This will give you a new, clean Restore Point. ********************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a COMPLETE cleaning. ******************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Hi Dave, I'll try your instruction...viruses keep me annoying...hopes it will work and Thanks for advance... These instructions were created for this user and may do more harm to your computer than good. If you're having problems, start your own thread and you will get help.Thank you so much Dave for all your time, effort and expertise. You are an absolute star You're welcome. I will lock this thread. If the original poster needs it re-opened, please pm me. |
|
| 270. |
Solve : Infected with win 7 security 2011? |
|
Answer» This appears to be a problem with your accounts and not malware. One more scan, if you don't mind.
•Click the button. •Accept any security warnings from your browser. •Check •Push the START button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt C:\Qoobox\Quarantine\C\Users\Huy\AppData\Roaming\803F13E0404D4D065A16E363334CEE12\enemies-names.txt.virWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\Huy\AppData\Roaming\803F13E0404D4D065A16E363334CEE12\local.ini.virWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined I still can't browse the internet. Maybe the the virus change some settings and they were not restored when the virus was removed.Quote I still can't browse the internet. Maybe the the virus change some settings and they were not restored when the virus was removed.Mini-toolbox took care of that PLUS most of tools we used were download from the internet. We should do some cleanup and then you should start a new thread in this forum. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these RELIABLE vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before IMMUNIZING. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Okay I will post on a New thread about my browser issue. thanks for all your help Dave!You're welcome. This thread will be locked. If you need it re-opened, please send me a pm. |
|
| 271. |
Solve : Background process almost brings computer to a halt? |
|
Answer» Could you please try to run ESET again?Would it be OK for me to stop the process wuauclt.exe when it runs, as this seems to be the process that brings the computer almost to a halt - or would that do more harm than good? A spurious process is still running each day. It appears to be wuauclt.exe.Are you getting a warning about this file? Wuauclt.exe is the AutoUpdate Client of Windows Update and is used to check for available updates (for the various versions of the MS Windows platform) from Microsoft Update. The wuauclt.exe file is included in the Task Manager’s list of active PROCESSES when it is waiting for a response or an action to be performed by the user. When the spurious process runs, it is sometimes accompanied by a warning message produced by (I think) Norton AV, saying "Win32 Services high memory usage".Please download SystemLook from one of the links below and save it to your DESKTOP. Link # 1 Link # 2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind wuauclt.exe Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt SystemLook log:- ********************************************************************************* SystemLook 04.09.10 by jpshortstuff Log created at 10:21 on 04/06/2011 by Administrator Administrator - Elevation successful ========== filefind ========== Searching for "wuauclt.exe" C:\WINDOWS\ERDNT\cache\wuauclt.exe--a---- 53472 bytes[11:39 18/02/2011][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe------- 111104 bytes[20:18 18/09/2008][00:12 14/04/2008] ED7262E52C31CF1625B65039102BC16C C:\WINDOWS\system32\wuauclt.exe--a---- 53472 bytes[08:00 04/08/2004][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD C:\WINDOWS\system32\dllcache\wuauclt.exe--a---- 53472 bytes[08:00 04/08/2004][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD -= EOF =- ************************************************************************* In the course of clicking on the Link in your post to find out how to temporarily disable my AV software, I noticed information on that website about how to fix corruptions of SVCHOST; so I bought that software (Paretologic PC Health Advisor) and ran it. It lets you do a scan without paying but I had to pay for the software to run the fix. ANYWAY, as one of the messages I was getting referred to high memory usage by SVCHOST, I thought this might fix the problem. In fact, it does seem to have gone quite a long way to fixing it, as SVCHOST now runs quickly and hardly slows the PC down while it's running. There is still one outstanding problem, which gives a 'Generic host process for Win 32 Services - high memory usage' message, which I think is the wuauclt.exe - but this seems to only occur only once every few days. So I think there were 2 problems, one of which has now been fixed and the other of which only happens every so often, rather than every day. I think we might be able to put up with this, unless you have a simple solution to it. If you think we have gone as far as is sensible with this, I would like to thank you for your efforts in dealing with this. Your involvement is appreciated.Quote In fact, it does seem to have gone quite a long way to fixing it, as SVCHOST now runs quickly and hardly slows the PC down while it's running. There is still one outstanding problem, which gives a 'Generic host process for Win 32 Services - high memory usage' message, which I think is the wuauclt.exe - but this seems to only occur only once every few days. So I think there were 2 problems, one of which has now been fixed and the other of which only happens every so often, rather than every day. I think we might be able to put up with this, unless you have a simple solution to it. If you think we have gone as far as is sensible with this, I would like to thank you for your efforts in dealing with this. Your involvement is appreciated. I don't feel that this is a malware issue. Very little showed up in all the scans we've run on this computer. You could start a new thread in the appropriate software forum, if you wish. We should do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
**************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ****************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from ONLINE scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!OK - done that. Thanks for your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm or start a new thread. |
|
| 272. |
Solve : know I have a virus, don't know anything else about it.? |
|
Answer» thanks. I think I am almost back up and running. Now that I've "freshened up" my laptop with a full format, I may go off and do the same THING to my old XP desktop that has a very full hard drive. With spyware programs like you listed, do I have them all on and active? do they run in the background or do I need to get back into the habit of just running them weekly?MBAM has a free trial period of continous scanning. Once that expires, you will probably have to buy the new version. Or, you can keep MBAM and SAS on your computer, update them and run regularyly. Quote Is there a way to settle User Account Control down so it isn't popping up every time I make a change?You can DISABLE it. |
|
| 273. |
Solve : I keep sending everyone in my email address book emails.? |
|
Answer» Quote Is it a serious problem that I get this warning on alot of sites I have to log into?No. That's just there for your protection. It means it might be a dubious website. To uninstall ComboFix
(Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the CLEANING process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the BOX next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't KNOW what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thank you SuperDave for your help. Sorry the "thank you" came so late as once the computer starting working good again I was off and running.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 274. |
Solve : Log analyze (malware removal help)? |
|
Answer» That looks good. If there are no other issues, it's time for some cleanup.
(NOTE: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * DEPENDING on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
*********************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block OUTGOING connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! I greatly thank you for the support you gave me, I will now know how to keep my PC clean in futur.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 275. |
Solve : PC Running Very Slow/Freezing? |
|
Answer» So I take it I should UNCHECK "Remove Found Threats" and just scan and post log?no found threats...can't find log ? no found threats...can't find log ?How's your computer running? Any other issues?It's BETTER than before, though it has it's moments. Is there anything I can do, run, to double check and make sure it checks out? Thanks Dave.Quote Is there anything I can do, run, to double check and make sure it checks out?From all the scans we've run I would say that it's clean. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
If this doesn't remove ComboFix, please let me know Clean out your temporary internet files and temp files. DOWNLOAD TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and SCROLL down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from ONLINE scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! 1) There is no FINAL scan we can do, just to be sure, before book closing? 2) tried combofix uninstall, said windows could not find it. I think I might have already deleted, anyway to confirm?Quote There is no final scan we can do, just to be sure, before book closing?ESET was the final scan. Quote tried combofix uninstall, said windows could not find it. I think I might have already deleted, anyway to confirm?I didn't think it would work because ComboFix was installed in the wrong location. Please try this: Download OTC by OldTimer and save it to your desktop. Double click OTL.exe.
************************************************** To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK.I have done everything but secunia. I was in firefox with secunia and tried it three times, all of which caused the browser to crash. I then tried it with IE, and it caused this message to be displayed continously until I ctrl-alt-dlt it to shut off. Quote Microsoft C++ Runtime Library So is there still something wrong with my PC? What should I do?Quote was in firefox with secunia and tried it three times, all of which caused the browser to crash.That's ok. Secunia acts up sometimes. Just make sure that you have all your updates, especially Windows and Java updates.So it otherwise should be all set and good?Quote from: bluecountry on July 02, 2011, 11:32:00 AM So it otherwise should be all set and good?Yes. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 276. |
Solve : Requesting Help with Malware Removal? |
|
Answer» Okay, just finished the ESET scan. I accidentally hit Finish before exporting, but fortunately found the log in the Program Files location you mentioned, so thanks for that. I'm suddenly getting a lot of "Potentially Unwanted Program Blocked" messages from McAfee regarding "Tool-NirCmd" from OTL, should I allow that program?That looks good. If there are no other issues, we can do some cleanup which will fix that OTL warning. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all PROGRAMS when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet EXPLORER to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the LATEST Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Great, I've done all of this. Once again, thank you so much, Dave!You're welcome. I will lock this thread. If you need it reopened, please send me a pm. |
|
| 277. |
Solve : Troubling Virus? |
|
Answer» I forgot to mention that the Security check indicates that you have Panda Antivirus Pro 2012 and Norton 360 running at the same time on your computer. One of these AV's will have to be disabled/uninstalled.
Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and links posted for each one) * Copy the file path in the below Code box: Code: [Select]c:\windows\system32\x64 c:\windows\system32\igxpun.exe c:\windows\system32\Drivers\utkwnty5.sys * At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning ENGINES. * Important: Wait for all of the scanning engines to complete. * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply. Sorry it took so long to get back to you I've had more problems with my laptop. I checked the files with jotti and found out that I only have 1 of the files......c:\windows\system32\igxpun.exe the others do not exist on my computer. ComboFix 11-07-15.01 - Feutz 07/15/2011 11:58:26.3.2 - x86 NETWORK Running from: c:\users\Feutz\Desktop\ComboFix.exe Command switches used :: c:\users\Feutz\Desktop\CFScript.txt . FILE :: "C:\found.001" "C:\found.002" "C:\found.003" "C:\found.004" "C:\found.005" . . ((((((((((((((((((((((((( Files Created from 2011-06-15 to 2011-07-15 ))))))))))))))))))))))))))))))) . . 2011-07-15 19:12 . 2011-07-15 19:15--------d-----w-c:\users\Feutz\AppData\Local\temp 2011-07-15 19:12 . 2011-07-15 19:12--------d-----w-c:\users\Robin\AppData\Local\temp 2011-07-15 19:12 . 2011-07-15 19:12--------d-----w-c:\users\Default\AppData\Local\temp 2011-07-15 16:44 . 2011-07-15 16:44--------d-----w-C:\found.007 2011-07-15 16:35 . 2011-07-15 16:35--------d-----w-c:\users\Robin\AppData\Local\Panda Security 2011-07-15 16:35 . 2011-07-15 16:35--------d-----w-c:\users\Robin\AppData\Roaming\SUPERAntiSpyware.com 2011-07-15 05:18 . 2011-07-15 05:18--------d-----w-C:\found.006 2011-07-15 04:41 . 2011-07-15 04:55--------d-----w-c:\windows\$regcmp$ 2011-07-12 12:51 . 2011-07-12 12:51404640----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-12 06:42 . 2011-06-20 15:577074640----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2AE3AC5-D19D-420D-820B-E39A120A10E8}\mpengine.dll 2011-07-09 22:14 . 2011-07-10 17:49--------d-----w-c:\users\Feutz\AppData\Local\Conduit 2011-07-09 16:37 . 2011-07-09 16:37--------d-----w-C:\found.005 2011-07-09 16:30 . 2011-07-09 16:30--------d-----w-C:\40d9b26e2a8b3f767a 2011-07-09 03:07 . 2011-07-15 01:58183180----a-w-c:\windows\system32\drivers\APPFCONT.DAT 2011-07-09 03:07 . 2010-09-09 23:23193864----a-w-c:\windows\system32\drivers\idsflt.sys 2011-07-09 03:07 . 2009-09-25 21:5446856----a-w-c:\windows\system32\drivers\wnmflt.sys 2011-07-09 03:07 . 2009-09-25 21:5453256----a-w-c:\windows\system32\drivers\dsaflt.sys 2011-07-09 03:06 . 2011-01-31 23:4183528----a-w-c:\windows\system32\drivers\APPFLT.SYS 2011-07-09 03:06 . 2009-09-25 21:5422024----a-w-c:\windows\system32\drivers\fnetmon.sys 2011-07-09 03:06 . 2009-09-25 21:54159112----a-w-c:\windows\system32\drivers\NETFLTDI.SYS 2011-07-07 10:00 . 2011-07-07 10:00--------d-----w-C:\ef60c58cdd1f56bf95401cfaf20940ef 2011-07-07 00:18 . 2011-07-07 00:18--------d-----w-C:\78584a5e440f81cc72 2011-07-05 10:00 . 2011-07-05 10:00--------d-----w-C:\760eb5305c2b3efcab91dcc17084bd 2011-07-04 23:18 . 2011-07-04 23:18--------d-----w-C:\found.004 2011-07-04 22:45 . 2011-07-04 22:45--------d-----w-c:\windows\system32\x64 2011-07-04 22:45 . 2008-02-12 03:13920088----a-w-c:\windows\system32\igxpun.exe 2011-07-03 18:51 . 2011-07-03 18:51--------d-----w-c:\users\Feutz\AppData\Local\Panda Security 2011-07-03 18:45 . 2010-06-23 01:1326696----a-w-c:\windows\system32\drivers\pavboot.sys 2011-07-03 18:45 . 2007-03-16 02:3854832----a-w-c:\windows\system32\pavcpl.cpl 2011-07-03 18:45 . 2003-10-23 01:23446464----a-w-c:\windows\system32\HHActiveX.dll 2011-07-03 18:45 . 2010-06-22 00:02193344----a-w-c:\windows\system32\TpUtil.dll 2011-07-03 18:45 . 2010-06-22 00:01520000----a-w-c:\windows\system32\PavSHook.dll 2011-07-03 18:45 . 2010-06-22 00:0187360----a-w-c:\windows\system32\PavLspHook.dll 2011-07-03 18:45 . 2010-06-22 00:0155616----a-w-c:\windows\system32\pavipc.dll 2011-07-03 18:45 . 2007-02-08 17:53107568----a-w-c:\windows\system32\SYSTOOLS.DLL 2011-07-03 18:44 . 2011-07-03 18:45--------d-----w-c:\program files\Panda Security 2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\windows\system32\PAV 2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\users\Feutz\AppData\Roaming\Panda Security 2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\programdata\Panda Security 2011-07-03 18:44 . 2010-09-01 18:09201032----a-w-c:\windows\system32\drivers\neti1644.sys 2011-07-03 18:44 . 2010-05-21 20:5054344----a-w-c:\windows\system32\drivers\amm8660.sys 2011-07-03 18:44 . 2010-03-24 19:5555552----a-w-c:\windows\system32\avldr.dll 2011-07-01 20:05 . 2011-07-01 20:05388096----a-r-c:\users\Feutz\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\users\Feutz\AppData\Roaming\SUPERAntiSpyware.com 2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\programdata\SUPERAntiSpyware.com 2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\program files\SUPERAntiSpyware 2011-06-30 13:03 . 2011-06-30 13:03--------d-----w-C:\d6aaef27f533ca95ed452bdd47deb9 2011-06-30 04:59 . 2011-06-30 04:59--------d-----w-C:\60dd7279dace78af16 2011-06-29 14:05 . 2011-06-29 14:05--------d-----w-C:\6bd801315f181fe169cd3798 2011-06-29 13:14 . 2011-06-29 13:14--------d-----w-C:\058d8e97ce6d35b88fe00fef6563 2011-06-29 00:42 . 2011-06-29 00:43--------d-----w-C:\SMCLPAV 2011-06-28 12:54 . 2005-04-04 06:02753664----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll 2011-06-28 12:54 . 2005-04-04 06:0269714----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll 2011-06-28 12:54 . 2005-04-04 06:01274432----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll 2011-06-28 12:54 . 2005-04-04 06:00184320----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll 2011-06-28 12:54 . 2005-04-04 05:595632----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe 2011-06-28 12:54 . 2011-06-28 12:54200836----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll 2011-06-28 12:54 . 2011-06-28 12:54331908----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll 2011-06-26 17:25 . 2011-07-05 05:12--------d-----w-c:\users\Feutz\AppData\Roaming\QuickScan 2011-06-26 17:22 . 2011-06-26 17:22--------d-----w-c:\users\Feutz\AppData\Local\Mozilla 2011-06-26 14:44 . 2011-06-26 14:44--------d-----w-C:\a8b79eb2bb60353fc6 2011-06-25 16:25 . 2011-06-25 16:32--------d-----w-c:\users\Feutz\AppData\Local\ElevatedDiagnostics 2011-06-20 17:40 . 2011-06-20 17:40472808----a-w-c:\windows\system32\deployJava1.dll 2011-06-19 20:15 . 2011-06-19 20:15--------d-----w-c:\program files\BeerSmith2 2011-06-19 16:28 . 2011-06-19 16:28--------d-----w-C:\5cee7e0f1b01fbec51c15a1462 2011-06-19 14:16 . 2011-06-20 17:41--------d-----w-c:\program files\Common Files\Java 2011-06-19 14:16 . 2011-06-19 14:16--------d-----w-C:\4756e36812682c0f88ddac0bd9665fb6 2011-06-19 13:54 . 2011-06-19 13:54--------d-----w-C:\found.003 2011-06-19 01:08 . 2011-06-19 01:08--------d-----w-C:\found.002 2011-06-17 01:28 . 2011-06-17 01:28--------d-----w-C:\found.001 2011-06-17 00:52 . 2011-04-14 14:5975264----a-w-c:\windows\system32\drivers\dfsc.sys 2011-06-17 00:52 . 2011-04-21 13:58273408----a-w-c:\windows\system32\drivers\afd.sys 2011-06-17 00:52 . 2011-04-29 13:25146432----a-w-c:\windows\system32\drivers\srv2.sys 2011-06-17 00:52 . 2011-04-29 13:25102400----a-w-c:\windows\system32\drivers\srvnet.sys 2011-06-17 00:37 . 2011-06-17 00:37--------d-----w-c:\users\Robin\AppData\Roaming\AVG10 2011-06-16 02:54 . 2011-06-16 02:59--------d-----w-c:\users\Feutz\AppData\Roaming\AVG 2011-06-16 02:08 . 2010-12-20 16:35563712----a-w-c:\windows\system32\oleaut32.dll 2011-06-16 02:08 . 2011-05-02 17:16739328----a-w-c:\windows\system32\inetcomm.dll 2011-06-16 02:08 . 2011-04-29 13:24214016----a-w-c:\windows\system32\drivers\mrxsmb10.sys 2011-06-16 02:08 . 2011-04-29 13:2479872----a-w-c:\windows\system32\drivers\mrxsmb20.sys 2011-06-16 02:08 . 2011-04-29 13:24106496----a-w-c:\windows\system32\drivers\mrxsmb.sys 2011-06-16 02:08 . 2011-05-02 12:022409784----a-w-c:\program files\Windows Mail\OESpamFilter.dat 2011-06-16 01:03 . 2011-06-16 01:03--------d-----w-C:\$AVG 2011-06-16 00:29 . 2011-06-16 00:29--------d--h--w-c:\programdata\Common Files 2011-06-16 00:27 . 2011-06-30 00:21--------d-----w-c:\programdata\AVG10 2011-06-16 00:16 . 2011-07-01 00:28--------d-----w-c:\program files\AVG 2011-06-16 00:11 . 2011-06-30 00:21--------d-----w-c:\programdata\MFAData . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-02 12:52 . 2011-06-02 12:52161792----a-w-c:\windows\system32\msls31.dll 2011-06-02 12:52 . 2011-06-02 12:521126912----a-w-c:\windows\system32\wininet.dll 2011-06-02 12:52 . 2011-06-02 12:5286528----a-w-c:\windows\system32\iesysprep.dll 2011-06-02 12:52 . 2011-06-02 12:5276800----a-w-c:\windows\system32\SetIEInstalledDate.exe 2011-06-02 12:52 . 2011-06-02 12:5274752----a-w-c:\windows\system32\RegisterIEPKEYs.exe 2011-06-02 12:52 . 2011-06-02 12:5263488----a-w-c:\windows\system32\tdc.ocx 2011-06-02 12:52 . 2011-06-02 12:5248640----a-w-c:\windows\system32\mshtmler.dll 2011-06-02 12:52 . 2011-06-02 12:52367104----a-w-c:\windows\system32\html.iec 2011-06-02 12:52 . 2011-06-02 12:5274752----a-w-c:\windows\system32\iesetup.dll 2011-06-02 12:52 . 2011-06-02 12:5223552----a-w-c:\windows\system32\licmgr10.dll 2011-06-02 12:52 . 2011-06-02 12:52152064----a-w-c:\windows\system32\wextract.exe 2011-06-02 12:52 . 2011-06-02 12:52150528----a-w-c:\windows\system32\iexpress.exe 2011-06-02 12:52 . 2011-06-02 12:521427456----a-w-c:\windows\system32\inetcpl.cpl 2011-06-02 12:52 . 2011-06-02 12:52420864----a-w-c:\windows\system32\vbscript.dll 2011-06-02 12:52 . 2011-06-02 12:5235840----a-w-c:\windows\system32\imgutil.dll 2011-06-02 12:52 . 2011-06-02 12:522382848----a-w-c:\windows\system32\mshtml.tlb 2011-06-02 12:52 . 2011-06-02 12:521797632----a-w-c:\windows\system32\jscript9.dll 2011-06-02 12:52 . 2011-06-02 12:52142848----a-w-c:\windows\system32\ieUnatt.exe 2011-06-02 12:52 . 2011-06-02 12:5211776----a-w-c:\windows\system32\mshta.exe 2011-06-02 12:52 . 2011-06-02 12:52101888----a-w-c:\windows\system32\admparse.dll 2011-06-02 12:52 . 2011-06-02 12:52110592----a-w-c:\windows\system32\IEAdvpack.dll 2011-05-29 16:11 . 2011-03-30 00:0339984----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-25 02:14 . 2010-06-27 01:40222080------w-c:\windows\system32\MpSigStub.exe 2011-04-14 16:26 . 2011-06-26 17:22142296----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of C:\40d9b26e2a8b3f767a ---- . 2011-07-09 16:30 . 2011-07-09 16:300---ha-w-c:\40d9b26e2a8b3f767a\$shtdwn$.req 2011-03-25 16:08 . 2011-03-25 16:0836514----a-w-c:\40d9b26e2a8b3f767a\1044\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837222----a-w-c:\40d9b26e2a8b3f767a\1045\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836738----a-w-c:\40d9b26e2a8b3f767a\1046\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837656----a-w-c:\40d9b26e2a8b3f767a\1049\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836020----a-w-c:\40d9b26e2a8b3f767a\1053\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836274----a-w-c:\40d9b26e2a8b3f767a\1055\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0827922----a-w-c:\40d9b26e2a8b3f767a\2052\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837404----a-w-c:\40d9b26e2a8b3f767a\2070\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837314----a-w-c:\40d9b26e2a8b3f767a\3082\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0827950----a-w-c:\40d9b26e2a8b3f767a\1028\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836822----a-w-c:\40d9b26e2a8b3f767a\1029\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836050----a-w-c:\40d9b26e2a8b3f767a\1030\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0838050----a-w-c:\40d9b26e2a8b3f767a\1031\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0838958----a-w-c:\40d9b26e2a8b3f767a\1032\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836030----a-w-c:\40d9b26e2a8b3f767a\1035\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837832----a-w-c:\40d9b26e2a8b3f767a\1036\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0832912----a-w-c:\40d9b26e2a8b3f767a\1037\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837822----a-w-c:\40d9b26e2a8b3f767a\1038\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0837192----a-w-c:\40d9b26e2a8b3f767a\1040\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0831108----a-w-c:\40d9b26e2a8b3f767a\1041\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0830194----a-w-c:\40d9b26e2a8b3f767a\1042\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0836962----a-w-c:\40d9b26e2a8b3f767a\1043\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0827950----a-w-c:\40d9b26e2a8b3f767a\3076\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0834086----a-w-c:\40d9b26e2a8b3f767a\1025\LocalizedData.xml 2011-03-25 16:08 . 2011-03-25 16:0865160----a-w-c:\40d9b26e2a8b3f767a\ParameterInfo.xml 2011-03-25 16:03 . 2011-03-25 16:035079552----a-w-c:\40d9b26e2a8b3f767a\NDP40-KB2478663.msp 2011-03-25 15:34 . 2011-03-25 15:343628----a-w-c:\40d9b26e2a8b3f767a\header.bmp 2011-03-25 15:34 . 2011-03-25 15:34196662----a-w-c:\40d9b26e2a8b3f767a\SplashScreen.bmp 2011-03-25 15:34 . 2011-03-25 15:3413606----a-w-c:\40d9b26e2a8b3f767a\Strings.xml 2011-03-25 15:34 . 2011-03-25 15:3436180----a-w-c:\40d9b26e2a8b3f767a\UiInfo.xml 2011-03-25 15:34 . 2011-03-25 15:34104072----a-w-c:\40d9b26e2a8b3f767a\watermark.bmp 2011-03-25 15:34 . 2011-03-25 15:34123035----a-w-c:\40d9b26e2a8b3f767a\1025\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34128333----a-w-c:\40d9b26e2a8b3f767a\1028\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34101146----a-w-c:\40d9b26e2a8b3f767a\1029\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34109464----a-w-c:\40d9b26e2a8b3f767a\1030\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:3491719----a-w-c:\40d9b26e2a8b3f767a\1031\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34102048----a-w-c:\40d9b26e2a8b3f767a\1032\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34138595----a-w-c:\40d9b26e2a8b3f767a\1033\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34111176----a-w-c:\40d9b26e2a8b3f767a\1035\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34133172----a-w-c:\40d9b26e2a8b3f767a\1036\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34125351----a-w-c:\40d9b26e2a8b3f767a\1037\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34110879----a-w-c:\40d9b26e2a8b3f767a\1038\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34124974----a-w-c:\40d9b26e2a8b3f767a\1040\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34111958----a-w-c:\40d9b26e2a8b3f767a\1041\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:3435285----a-w-c:\40d9b26e2a8b3f767a\1043\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:3436083----a-w-c:\40d9b26e2a8b3f767a\1044\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34126541----a-w-c:\40d9b26e2a8b3f767a\1045\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34109574----a-w-c:\40d9b26e2a8b3f767a\1046\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:3449319----a-w-c:\40d9b26e2a8b3f767a\1049\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34125073----a-w-c:\40d9b26e2a8b3f767a\1053\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34112947----a-w-c:\40d9b26e2a8b3f767a\1055\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34110754----a-w-c:\40d9b26e2a8b3f767a\2052\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34125196----a-w-c:\40d9b26e2a8b3f767a\2070\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:342060----a-w-c:\40d9b26e2a8b3f767a\3076\eula.rtf 2011-03-25 15:34 . 2011-03-25 15:34108174----a-w-c:\40d9b26e2a8b3f767a\3082\eula.rtf 2011-03-23 20:12 . 2011-03-23 20:1235802----a-w-c:\40d9b26e2a8b3f767a\1033\LocalizedData.xml 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\2070\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\3082\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\2052\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1049\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1053\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1055\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1045\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1046\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4814680----a-w-c:\40d9b26e2a8b3f767a\1042\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818776----a-w-c:\40d9b26e2a8b3f767a\1043\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1044\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1038\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1040\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4815192----a-w-c:\40d9b26e2a8b3f767a\1041\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1036\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4816216----a-w-c:\40d9b26e2a8b3f767a\1037\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818776----a-w-c:\40d9b26e2a8b3f767a\1032\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4816728----a-w-c:\40d9b26e2a8b3f767a\1033\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1035\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1031\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1030\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\1028\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1029\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\3076\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:48295248----a-w-c:\40d9b26e2a8b3f767a\SetupUi.dll 2011-03-22 18:48 . 2011-03-22 18:4816728----a-w-c:\40d9b26e2a8b3f767a\1025\SetupResources.dll 2011-03-22 18:48 . 2011-03-22 18:48809304----a-w-c:\40d9b26e2a8b3f767a\SetupEngine.dll 2011-03-22 18:48 . 2011-03-22 18:4878152----a-w-c:\40d9b26e2a8b3f767a\Setup.exe 2011-03-22 18:35 . 2011-03-22 18:3516118----a-w-c:\40d9b26e2a8b3f767a\DHtmlHeader.html 2011-03-22 18:35 . 2011-03-22 18:3530120----a-w-c:\40d9b26e2a8b3f767a\SetupUi.xsd 2011-03-22 18:35 . 2011-03-22 18:35144416----a-w-c:\40d9b26e2a8b3f767a\sqmapi.dll 2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\Print.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate1.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate2.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate3.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate4.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate5.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate6.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate7.ico 2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate8.ico 2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\Save.ico 2011-03-22 18:31 . 2011-03-22 18:3136710----a-w-c:\40d9b26e2a8b3f767a\Graphics\Setup.ico 2011-03-22 18:31 . 2011-03-22 18:3110134----a-w-c:\40d9b26e2a8b3f767a\Graphics\stop.ico 2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\SysReqMet.ico 2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\SysReqNotMet.ico 2011-03-22 18:31 . 2011-03-22 18:3110134----a-w-c:\40d9b26e2a8b3f767a\Graphics\warn.ico . ---- Directory of C:\ef60c58cdd1f56bf95401cfaf20940ef ---- . 2011-07-07 10:00 . 2011-07-07 10:00788---ha-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\$shtdwn$.req 2011-04-13 19:05 . 2011-04-13 19:0537404----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537314----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536962----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536514----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537222----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536738----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536020----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536274----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0527922----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0538958----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536030----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537832----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0532912----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537822----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0537192----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0531108----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0530194----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0534086----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0527950----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536822----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0536050----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0538050----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:0527950----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\LocalizedData.xml 2011-04-13 19:05 . 2011-04-13 19:053628----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\header.bmp 2011-04-13 19:05 . 2011-04-13 19:0567018----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\ParameterInfo.xml 2011-04-13 19:05 . 2011-04-13 19:05196662----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SplashScreen.bmp 2011-04-13 19:05 . 2011-04-13 19:0513606----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Strings.xml 2011-04-13 19:05 . 2011-04-13 19:0536180----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\UiInfo.xml 2011-04-13 19:05 . 2011-04-13 19:05104072----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\watermark.bmp 2011-04-13 19:05 . 2011-04-13 19:05123035----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05128333----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05101146----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05109464----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:0591719----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05102048----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05138595----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05111176----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05133172----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05125351----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05110879----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05124974----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05111958----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05149503----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:0535285----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:0536083----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05126541----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05109574----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:0549319----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05125073----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05112947----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05110754----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05125196----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:052060----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\eula.rtf 2011-04-13 19:05 . 2011-04-13 19:05108174----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\eula.rtf 2011-04-13 18:37 . 2011-04-13 18:3719201024----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\NDP40-KB2518870.msp 2011-04-13 13:12 . 2011-04-13 13:1235802----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\LocalizedData.xml 2011-04-12 21:38 . 2011-04-12 21:3815192----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\SetupResources.dll 2011-04-12 21:22 . 2011-04-12 21:2216728----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\SetupResources.dll 2011-04-12 21:08 . 2011-04-12 21:0813656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\SetupResources.dll 2011-04-12 20:50 . 2011-04-12 20:5013656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\SetupResources.dll 2011-04-12 20:50 . 2011-04-12 20:5013656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\SetupResources.dll 2011-04-12 20:36 . 2011-04-12 20:3617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\SetupResources.dll 2011-04-12 20:16 . 2011-04-12 20:1617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\SetupResources.dll 2011-04-12 20:01 . 2011-04-12 20:0118264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\SetupResources.dll 2011-04-12 19:42 . 2011-04-12 19:4218776----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\SetupResources.dll 2011-04-12 19:24 . 2011-04-12 19:2418264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\SetupResources.dll 2011-04-12 19:08 . 2011-04-12 19:0817752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\SetupResources.dll 2011-04-12 18:51 . 2011-04-12 18:5118264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\SetupResources.dll 2011-04-12 18:36 . 2011-04-12 18:3616216----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\SetupResources.dll 2011-04-12 18:20 . 2011-04-12 18:2018264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\SetupResources.dll 2011-04-12 18:06 . 2011-04-12 18:0617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\SetupResources.dll 2011-04-12 17:49 . 2011-04-12 17:4914680----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\SetupResources.dll 2011-04-12 17:31 . 2011-04-12 17:3118776----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\SetupResources.dll 2011-04-12 17:17 . 2011-04-12 17:1717240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\SetupResources.dll 2011-04-12 17:03 . 2011-04-12 17:0317752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\SetupResources.dll 2011-04-12 16:43 . 2011-04-12 16:4317752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\SetupResources.dll 2011-04-12 16:23 . 2011-04-12 16:2318264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\SetupResources.dll 2011-04-12 16:00 . 2011-04-12 16:0018264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\SetupResources.dll 2011-04-12 15:44 . 2011-04-12 15:4417240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\SetupResources.dll 2011-04-12 15:23 . 2011-04-12 15:2316728----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\SetupResources.dll 2011-04-12 15:23 . 2011-04-12 15:2317240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\SetupResources.dll 2011-04-12 15:23 . 2011-04-12 15:23809304----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupEngine.dll 2011-04-12 15:23 . 2011-04-12 15:23295248----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupUi.dll 2011-04-12 15:23 . 2011-04-12 15:2378152----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Setup.exe 2011-04-12 15:16 . 2011-04-12 15:1616118----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\DHtmlHeader.html 2011-04-12 15:16 . 2011-04-12 15:1630120----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupUi.xsd 2011-04-12 15:16 . 2011-04-12 15:16144416----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\sqmapi.dll 2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Print.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate1.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate2.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate3.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate4.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate5.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate6.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate7.ico 2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate8.ico 2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Save.ico 2011-04-12 13:11 . 2011-04-12 13:1136710----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Setup.ico 2011-04-12 13:11 . 2011-04-12 13:1110134----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\stop.ico 2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\SysReqMet.ico 2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\SysReqNotMet.ico 2011-04-12 13:11 . 2011-04-12 13:1110134----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\warn.ico . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-07-04 430080] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "WMPNSCFG"="c:\program files\Windows MEDIA Player\WMPNSCFG.exe" [2008-01-21 202240] "Registry Repair Wizard Scheduler"="c:\program files\SmartPCTools\Registry Repair Wizard\RCHelper.exe" [2011-04-26 1540480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104] "Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-26 413696] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE" [2011-04-13 1000768] "SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe" [2011-02-02 70464] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr] 2010-03-24 19:5555552----a-w-c:\windows\System32\avldr.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail] @="Service" . [HKLM\~\startupfolder\C:^Users^Feutz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\Feutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-09-01 15:32421160----a-w-c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-08-10 12:15421888----a-w-c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel] 2007-11-21 01:151826816----a-w-c:\windows\SkyTel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng] 2008-01-30 00:38583048----a-w-c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2011-02-06 23:25202256----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe] 2010-08-24 09:38247144----a-w-c:\program files\TomTom HOME 2\TomTomHOMERunner.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Persistence"=c:\windows\system32\igfxpers.exe "IgfxTray"=c:\windows\system32\igfxtray.exe "SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R0 30587362;30587362 Boot Guard Driver;c:\windows\system32\DRIVERS\30587362.sys R1 30587361;30587361;c:\windows\system32\DRIVERS\30587361.sys R1 setup_9.0.0.722_17.06.2011_02-59drv;setup_9.0.0.722_17.06.2011_02-59drv;c:\windows\system32\DRIVERS\3058736.sys R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys R3 utkwnty5;AVZ Kernel Driver;c:\windows\system32\Drivers\utkwnty5.sys S0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot.sys [2010-06-23 26696] S1 APPFLT;App FILTER Plugin;c:\windows\system32\Drivers\APPFLT.SYS [2011-01-31 83528] S1 DSAFLT;DSA Filter Plugin;c:\windows\system32\Drivers\DSAFLT.SYS [2009-09-25 53256] S1 FNETMON;NetMon Filter Plugin;c:\windows\system32\Drivers\fnetmon.SYS [2009-09-25 22024] S1 IDSFLT;Ids Filter Plugin;c:\windows\system32\Drivers\IDSFLT.SYS [2010-09-09 193864] S1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\Drivers\NETFLTDI.SYS [2009-09-25 21:54 159112] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm8660.sys [2010-05-21 54344] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960] S2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2012\PskSvc.exe [2010-08-16 28992] S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-08-24 92008] S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976] S3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168] S3 NETIMFLT01060044;PANDA NDIS IM Filter Miniport v1.6.0.44;c:\windows\system32\DRIVERS\neti1644.sys [2010-09-01 201032] S3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys S3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local; uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Feutz\AppData\Roaming\Mozilla\Firefox\Profiles\6ut3ou0q.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file) . . . ************************************************************************** scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-4017210073-3623525190-2501994021-1000\Software\SecuROM\License information*] "datasecu"=hex:c4,80,29,ed,05,d0,45,d9,29,7e,6a,37,9e,64,ce,c2,e9,37,98,c4,c1, 7a,60,54,48,c8,de,53,bb,04,84,f3,48,bf,48,d0,5c,7b,fb,b9,8f,53,3c,c9,29,d9,\ "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44 . [HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*] "value"="?\07\06\09\16\10\02?" . [HKEY_LOCAL_MACHINE\system\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . ------------------------ Other Running Processes ------------------------ . c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\TPSrv.exe c:\windows\system32\WLANExt.exe c:\windows\system32\agrsmsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\AVENGINE.EXE c:\toshiba\IVP\ISM\pinger.exe c:\program files\Panda Security\Panda Antivirus Pro 2012\Firewall\PSHOST.EXE c:\program files\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\toshiba\IVP\swupdate\swupdtmr.exe c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe c:\windows\system32\TODDSrv.exe c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\vssvc.exe c:\windows\system32\msiexec.exe c:\windows\system32\wermgr.exe . ************************************************************************** . Completion time: 2011-07-15 12:35:38 - machine was rebooted ComboFix-quarantined-files.txt 2011-07-15 19:35 ComboFix2.txt 2011-07-10 16:39 . Pre-Run: 64,561,160,192 bytes free Post-Run: 64,469,340,160 bytes free . - - End Of File - - 85ABDEECE7410EEEB37B7FDE0D3D8A5DQuote Sorry it took so long to get back to you I've had more problems with my laptopWhat sort of problems? Quote I checked the files with jotti and found out that I only have 1 of the files......c:\windows\system32\igxpun.exeAnd what did Jotti report about this file? ********************************************************* Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance. Registry Repair Wizard There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry. For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great. Further reading: XP Fixes Myth #1: Registry Cleaners ********************************************************** Re-running ComboFix to remove infections:
I need these files checked. Please show me the results by including the link in your reply. Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and links posted for each one) * Copy the file path in the below Code box: Code: [Select]c:\windows\system32\DRIVERS\30587361.sys c:\windows\system32\DRIVERS\3058736.sys * At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning engines. * Important: Wait for all of the scanning engines to complete. * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply. |
|
| 278. |
Solve : sound and video jittery- suspected malware??? |
|
Answer» Thank you for the Link Dave, I had the laptop apart last week (that was fun!!) and cleaned the fan there wasn't a lot of dust in there tho which surprised me. I am gona have to ask the COMPANY who re-installed for a disc. |
|
| 279. |
Solve : Malware Issues - PE_Perfect pecompact TR/SPy.Keylogger.qme? |
|
Answer» That looks great. Just one more scan. thank you Dave. I have 2 more machines showing same types of problems. Can I run their logs with you to look at and resolve. Thank you again for your help!You should start a new thread for each computer otherwise, it's too confusing. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ****************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, SPYWARE, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest IMMUNIZATIONS always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 280. |
Solve : unregistered files? |
|
Answer» Hi there
Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Completed script processing. ******************* Please do this in the following order. Please download, install and activate MicroSoft Security Essentials from the link below. Then remove McAfee using the tool below and see if you're still getting the error message. Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download Microsoft Security Essentials for Windows XP Download the McAfee Consumer Product Removal Tool to your Desktop. Using McAfee Consumer Product Removal tool: * Double click the MCPR.exe * A Command Line window will be displayed, and then close automatically. * Wait for a second Command Line window to be displayed. Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear. * After the second window appears, the program will begin the cleanup. * Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n] * Press Y on the keyboard. * Wait for the computer to restart. * All McAfee products are now removed from your computer. Done and the reboot produced no repeat of the FP message. Too much to do today to stop and start but expect a cold start to have the same result. As I think you have too, I've come to the conclusion the problem has resided somewhere in McAfee. We shall see! Thanks again. AlexSince last job I've been getting explorer.exe using up between 40-50% of CPU all the time - I'm sure this isn't normal. Any thoughts and suggestions to fix?Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program. Click on View > Select Colunms. In addition to already pre-selected options, make sure, the Command Line is selected, and press OK. Go File>Save As, and save the report as Procexp.txt. Attach the file to your next reply.I already run process explorer - it's more user friendly and detailed than Task Manager. However, as with many diagnostic type tools, I never get round to fully utilising the features available. So I'm glad to have this passed on - thanks. Here's the data: ProcessPIDCPUPrivate BytesWorking SetDescriptionCompany NameCommand Line System Idle Process047.690 K28 K Interruptsn/a0 K0 KHardware Interrupts DPCsn/a0 K0 KDeferred Procedure Calls System40 K140 K smss.exe444204 K116 KWindows NT Session ManagerMicrosoft Corporation\SystemRoot\System32\smss.exe csrss.exe5081,860 K2,756 KClient Server Runtime ProcessMicrosoft CorporationC:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 winlogon.exe5326,656 K2,604 KWindows NT Logon APPLICATIONMICROSOFT Corporationwinlogon.exe services.exe5760.771,932 K2,244 KServices and Controller appMicrosoft CorporationC:\WINDOWS\system32\services.exe a2service.exe74815,736 K440 KEmsisoft Anti-Malware ServiceEmsi Software GmbH"C:\Program Files\Emsisoft Anti-Malware\a2service.exe" svchost.exe8363,228 K1,828 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k DcomLaunch hpgs2wnf.exe1912964 K440 Khpgs2wnf ModuleC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe -Embedding svchost.exe9322,000 K2,284 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k rpcss MsMpEng.exe972170,924 K48,428 KAntimalware Service ExecutableMicrosoft Corporation"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" svchost.exe100819,816 K25,812 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe10802,100 K2,168 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k NetworkService svchost.exe11643,400 K1,212 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService spoolsv.exe12764,508 K1,960 KSpooler SubSystem AppMicrosoft CorporationC:\WINDOWS\system32\spoolsv.exe UMVPFSrv.exe13081,616 K140 KLogitech User mode UMVPF serviceLogitech Inc."C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe" svchost.exe5121,400 K784 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService SASCORE.EXE868732 K212 KCore ServiceSUPERAntiSpyware.com"C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" mDNSResponder.exe1436984 K1,064 KBonjour ServiceApple Inc."C:\Program Files\Bonjour\mDNSResponder.exe" CLCapSvc.exe14485,944 K848 KCLCapSvc Module"C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe" CLMLServer.exe15088,664 K1,080 KNT CLMLServerCyberlink"C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe" SAgent2.exe15801,764 K484 KEPSON Printer Status AgentSEIKO EPSON CORPORATION"C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe" jqs.exe17688,816 K1,380 KJava(TM) Quick Starter ServiceSun Microsystems, Inc."C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" LSSrvc.exe1596632 K140 KHewlett-Packard Company"C:\Program Files\Common Files\LightScribe\LSSrvc.exe" McciCMService.exe22642,036 K1,432 Kmcci+McciCMServiceAlcatel-Lucent"C:\Program Files\Common Files\Motive\McciCMService.exe" MDM.EXE2284964 K476 KMachine Debug ManagerMicrosoft Corporation"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" nvsvc32.exe23362,680 K2,472 KNVIDIA Driver Helper Service, Version 175.19NVIDIA CorporationC:\WINDOWS\system32\nvsvc32.exe HPZIPM12.EXE2352556 K276 KPML DriverHPC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE svchost.exe24162,756 K2,644 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k imgsvc CLSched.exe25041,460 K880 KCLSched Module"C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe" dialdictate.exe254027,956 K404 KDial DictateNCH Software"C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe" -service iPodService.exe30802,472 K1,504 KiPodService Module (32-bit)Apple Inc."C:\Program Files\iPod\bin\iPodService.exe" alg.exe33521,188 K240 KApplication Layer Gateway ServiceMicrosoft CorporationC:\WINDOWS\System32\alg.exe lsass.exe5884,080 K1,416 KLSA Shell (Export Version)Microsoft CorporationC:\WINDOWS\system32\lsass.exe explorer.exe162850.0053,632 K32,584 KWindows ExplorerMicrosoft CorporationC:\WINDOWS\Explorer.EXE hpgs2wnd.exe1800936 K444 Khpgs2wndHewlett-Packard"C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" BTHelpNotifier.exe18121.542,240 K2,584 Kmcci+McciTrayAppAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" BTHelpBrowser.exe676010,112 K18,904 Kmcci+McciBrowserAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" /APPKEY=btbb /URL=file:///C:/Program Files/BT Broadband Desktop Help/btbb/OCB/d153fd8a-965a-4485-845b-effd12a9f06f/Tasks.html BTHelpBrowser.exe68528,840 K16,004 Kmcci+McciBrowserAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" -AppKey=btbb -url=https://pbttbc.bt.motive.com/portal/smptasks.jsp?taskid=1 FUFAXSTM.exe18367,792 K1,188 KFAX Status MonitorSEIKO EPSON CORPORATION"C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe" EEventManager.exe18443,416 K1,004 KEEventManager ApplicationSEIKO EPSON CORPORATION"C:\Program Files\Epson Software\Event Manager\EEventManager.exe" jusched.exe1864856 K200 KJava(TM) 2 Platform Standard Edition binarySun Microsystems, Inc."C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" realsched.exe19001,540 K232 KRealNetworks SchedulerRealNetworks, Inc."C:\program files\real\realplayer\update\realsched.exe" -osboot dialdictate.exe200429,028 K1,520 KDial DictateNCH Software"C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe" -logon msseces.exe1524,880 K2,976 KMicrosoft Security Client User InterfaceMicrosoft Corporation"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey SUPERANTISPYWARE.EXE38431,668 K796 KSUPERAntiSpyware ApplicationSUPERAntiSpyware.com"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" ctfmon.exe4001,188 K2,172 KCTF LoaderMicrosoft Corporation"C:\WINDOWS\system32\ctfmon.exe" procexp.exe148411,660 K13,144 KSysinternals Process ExplorerSysinternals - www.sysinternals.com"C:\Program Files\procexp.exe" firefox.exe664889,488 K102,004 KFirefoxMozilla Corporation"C:\Program Files\Mozilla Firefox\firefox.exe" kbd.exe40163,704 K1,784 KKBD EXEHewlett-Packard CompanyC:\HP\KBD\KBD.EXE hpsysdrv.exe992880 K760 KhpsysdrvHewlett-Packard Companyc:\windows\system\hpsysdrv.exe No messages today on cold start and CPU usage has regularised to average 93% free so, subject to repetitions, looking like a fix. I presume you'd recommend I don't re-install McAfee then? Also, should I get a separate firewall or will MSE manage that too? AlexQuote I presume you'd recommend I don't re-install McAfee then? Also, should I get a separate firewall or will MSE manage that too?I'm not a big fan of McAfee. The Windows Firewall in XP is not much good because it only blocks incoming. Outgoing is the most harmful. I really depends on how much security you want on your pc. If you're doing financial dealings then I would recomment a third-party firewall.See suggestions below. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
********************************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. Good luck!Thanks for your help Dave - HOPE it's been as intriguing for you as it has been frustrating for me. I'll get on with finding a firewall and doing the cleanup. Regards AlexYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 281. |
Solve : cannot use internet on infected computer? |
|
Answer» The default gateway is missing on that computer. That's what I'm trying to repair. Please try this: should I post about this in the networking section???You may just as well post it there. I've reached the bottom of my bag of tricks. If you can succeed in getting connected to the net, please run the ESET scan. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have SAVED all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft WINDOWS Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. |
|
| 282. |
Solve : adobe flash misbehaving? |
|
Answer» yes i have them. TOOK a while to dig up but i have themok i ended up just doing a complete format of my HARD drive and REINSTALLED windows. everythings working fine now. thanks for your patience superdave!Quote from: kamikaze33 on September 05, 2011, 05:30:50 PM ok i ended up just doing a complete format of my hard drive and reinstalled windows. everythings working fine now. thanks for your patience superdave!When I asked for you OS disk I was going to ask you to do a system File CHECK to see if any files were absent or corrupted not a complete re-format. However, now you have a new computer. I will lock this thread. If you need it reopened, PLEASE send me a pm |
|
| 283. |
Solve : computer running slow and locks up intermittently? |
|
Answer» I swear I attached it.
•Click the button. •Accept any security warnings from your browser. •Check •PUSH the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt ok. I ran ESET and attached the log file. My god, every different program you have me use seems to find more things. Am I that infected? WOW As always, THANK you for your time and help. T. [regaining space - attachment deleted by admin]I would say your computer is now clean. If there are no other issues, let's do some cleanup. To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and FOLLOW the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. ************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will CLOSE all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Thank you for all your help. Still running fairly slow but it is a night and day difference from the way it was prior to your assistance. I have implimented all the programs and done all the cleanup that you suggested as well as was recommended in the links you provided. I feel like my computer is well protected now. Thanks again. T.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 284. |
Solve : Need help with Malware removal.? |
|
Answer» That sounds good. I will LOCK this thread. If you need it re-opened, PLEASE SEND me a pm. |
|
| 285. |
Solve : Stubborn Malware!? |
|
Answer» OK, removed a ton of programs, now have 19 GB free, and 19% free space.... censored*, the same 2 pop-ups are still coming upIs it the popup that you posted in your first post? Did you install any new programs just prior to getting this problem? I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and BEGIN scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Quote from: SuperDave on September 17, 2011, 04:24:30 PM Is it the popup that you posted in your first post? Did you install any new programs just prior to getting this problem?Yes, the first popup I posted and the second one as well, they seem to appear within seconds of each other, other then this problem the computer is running quite well, if I could just track down where they are coming from..... ESET scan- C:\Documents and Settings\Sean\Application Data\loaristrojanremover.exea variant of Win32/1AntiVirus applicationdeleted - quarantined C:\Documents and Settings\Sean\desktop\Assorted Shortcuts\New Torrents\Wallpapers(*censored*)(High Quality)[owez77][h33t]\Allok AVI to DVD SVCD VCD Converter v3.6.1107\Allok AVI to DVD SVCD VCD Converter v3.6.1107.rara variant of Win32/Keygen.AT applicationdeleted - quarantined C:\Program Files\Loaris\Trojan Remover\ltr.exea variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined C:\Program Files\Loaris\Trojan Remover\ltr.exe.baka variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined C:\Program Files\Unlocker\eBay_shortcuts_1016.exeWin32/Adware.ADON applicationdeleted - quarantined C:\Program Files\Yahoo Games\Pizza Chef\PizzaChef.exeprobably a variant of Win32/TrojanDownloader.Agent.NBCQTKF trojancleaned by deleting - quarantined C:\Qoobox\Quarantine\C\WINDOWS\system32\FhPVxyxx.ini.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292838.exeprobably a variant of Win32/Agent.CFYQYYM trojandeleted - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306610.exea variant of Win32/1AntiVirus applicationdeleted - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306611.exea variant of Win32/Keygen.AT applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306640.exea variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306642.exeWin32/Adware.ADON applicationdeleted - quarantined C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306643.exeprobably a variant of Win32/TrojanDownloader.Agent.NBCQTKF trojancleaned by deleting - quarantined C:\WINDOWS\system32\drivers\up.exea variant of Win32/Adware.SafeSurf.AA applicationcleaned by deleting - quarantined C:\WINDOWS\system32\weber\updater.exeWin32/Adware.SafeSurf applicationdeleted - quarantined * Go to Start > Run and type mrt.exe then press Enter on the keyboard). * (Vista and Windows 7 users go to Start and type mrt.exe in the search box then press Enter on the keyboard. * Click Next. * Choose Full Scan and click Next. * Once the scan is finished click VIEW detailed results of the scan. Look through the list and let me know if anything was found infected.'No malicious software was detected' I cannot believe how hard this thing is to get rid of....Please download Bootkit Remover by eSage Lab from here. NOTE: This is a file compressed with Winrar. If you do not have the means to unpack it, you can download and install 7-zip from here.
Bootkit Remover (c) 2009 eSage Lab www.esagelab.com Program version: 1.2.0.0 OS Version: Microsoft Windows XP Home Edition Service Pack 3 (build 2600 System volume is \\.\C: \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 Boot sector MD5 is: 6def5ffcbcdbdb4082f1015625e597bd Size Device Name MBR Status -------------------------------------------- 93 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found) Done; Press any key to quit... Any change?Quote from: SuperDave on September 20, 2011, 01:35:09 PM Any change?Nope, they still pop up at least once every half an hour, I think next I'm going to rule out its a firefox addon by running my browser in safe mode for an hour and see what happens.....T think it must be an add-on, when in safe mode it doesn't pop up, now I just have to figure out what add-on it is thats causing it..... Thanx for all your help SuperDave.... Ok. We might as well do some cleanup for now. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
****************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!It happened to me too, when I visit a certain sites it keeps on popping and it's irritating me. Quote from: beckymaccery on September 23, 2011, 02:08:34 AM It happened to me too, when I visit a certain sites it keeps on popping and it's irritating me.Please do not hijack someone else's thread. It's very rude. If you need help, start your own thread. |
|
| 286. |
Solve : Malware or Virus? |
|
Answer» Rooter.exe (v1.0.2) by Eric_71 I continue to run avast! daily, and it still picks up cookies. I wonder if I should uninstall stumble(even though I hardly use it now), it might be collecting more unwanted files on my computer.If you're going on the internet, your bound to pick up cookies unless you set up the browser to not ACCEPT them. Not all cookies are bad. Quote Additionally, there are a few problems I have uninstalling unwanted programs, for example, an old pluggin I used to manage itunes and firefox at once, Foxytunes, won't uninstall from the add/remove programs list, and I don't know how else to remove it since searches come up blank.It's there in your installed programs but it's probably been uninstalled previously. Let's try this to get rid of it. Please download: HiJackThis to your Desktop.
•Start HijackThis •Click on the Open the Misc Tools section •Click on the Open Uninstall Manager button. •Highlight the entry you want to remove. (Foxytunes) •Click Delete this entry ****************************************************** I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt [/list]C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SIGRLK1M\index-functions[1].jsWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\Launcher.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rbmonitor.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rbnotifier.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_move_serial.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_ubm.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\registrybooster.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-24641d49probably a variant of Java/Agent.BR trojandeleted - quarantined C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-506c04d6a variant of Java/Agent.BR trojandeleted - quarantined C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\404cf589-7d48dfdbJava/TrojanDownloader.OpenStream.NCA trojandeleted - quarantined C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\uluf7408.default\extensions\{9c0b4b35-0418-4b05-9889-938f63eac03b}\chrome.manifestWin32/TrojanDownloader.Tracur.F trojancleaned by deleting - quarantined C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\uluf7408.default\extensions\{9c0b4b35-0418-4b05-9889-938f63eac03b}\chrome\xulcache.jarJS/Agent.NDJ trojandeleted - quarantined I tried calling a friend on skype too and I was unable to use my webcam as well, an error came up saying it was already in use... Nevermind, just tried it again, it works. This must have fixed something.How's your computer working now? Any other issues?I think we're ok, is the virus clear? I don't want to stop running scans if there's any issues. Also, are any of the programs you suggested worth keeping around? I want to keep the antivirus software that works best around if I get other symptoms.Quote is the virus clear? I don't want to stop running scans if there's any issues.I would say that your computer is clean. Let's do some cleanup. Quote Also, are any of the programs you suggested worth keeping around? I want to keep the antivirus software that works best around if I get other symptoms.You may keep SAS and MBAM, if you WISH. Update them and run them on a regular basis to keep your computer clean. Also there are other suggestions below. As for the best AV. Everyone has their opinion about which AV is best. Avast is as good or better than most. To uninstall COMBOFIX
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
******************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Ok, I attempted to install the first two firewalls, but they don't seem to work, I think it's the 64-bit OS again. In the comments for the other two I saw the same problems, so I skipped that. I'm not sure if they're really worth the trouble if I'm keeping MBAM, avast!, and SAS. I'm updating windows, and I downloaded TFC and WoT. I was planning a disk defrag soon, since I haven't done one since I downloaded WoW for the first time on this computer, so after windows finishes updating, I'll do just that. Thank you again, Dave. I truly appreciate your help.Quote but they don't seem to work, I think it's the 64-bit OS againYes, you need to pick one that works with 64 bit machines. Quote Thank you again, Dave. I truly appreciate your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 287. |
Solve : relevant knowledge and atdm? |
|
Answer» MBAM seems to be working fine now tyThat sounds good. Let's do some cleanup.
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!could not run TFC or Secuna Software Inspector and I haven't been able to get my emailsQuote I haven't been able to get my emailsWhat happens when you try to get them? What are you using for e-mail?OPENING TFC.exe asks to 'save file' a window opens with 'Downloads' FTC(3).exe is highlighted with no options, so i doulbe click TFC(3).exe and this opens window with 'Open Executable File ?' and says exe files can contain viruses, etc am I sure i want to launch, I click 'ok' popup is 'Open File -Security Warning' i clicked 'Run' and popup with TFC in top left HAND corner and a title that says Temp File Cleaner by OldTimer v 3.1.7.0 I click start and a popup says 'System modification attempt DeepGuard has noticed that a program i trying to manipulate or terminat... What should be done? I click 'I trust" and 'Ok' and same screen a second time. Then some writing shows up in popup window 'TFC 'Getting user folders and Stopping running processes. The mouse arrow is now a solid Hour Glass and nothing happens. I can't click exit, click top x button and "End Program" - TFC= This program is not responding - hour glass is quickly flashing beside smaller mouse arrow, forever clicking 'End program' must reboot, I press reset button under main TURN off button on computer tower, this time i'm allowed to go to Start, shut down and it works Outlook Express is my email, noon today will be 2 days. I thought we were done, i went to another part of this forum and a suggested to find out if my IE 8 was slow or the computer was to download Firefox. I did. Now IE 8 firstly would not load, and now says it's add-ons are turned off with no option in the yellow bar to turn them back on. I didn't turn them off. ty Will send Secuna infoHad to login before using Secunia, used firefox and need to use IE for Microsoft Updates. Got to Microsoft Update Welcome Screen: says Install the Active X but the yellow information bar does not give me the option to right click and click "Install Active Control" Secunia found two older versions of Adobe Flash Player 10 (active x and npapi)installed Adobe Flash Player, IE 8 fired up and so did my Outlook Express email but froze with MESSAGE - Program not responding and sent error report to microsoft. Rebooted and went to start, 'Internet Explorer (no Add-ons) and computer froze again. rebooted using the reset button on computer tower. Secunia needed me to log in and I will run it again. there were many updates not installed according to them, when i went to windows update they found none. I'll be backran Secunia with firefox and I believe it fixed active x (NPAPI) but still says i got two versions of active x and says I need the latest patch version for active x, Please see list below for details and about missing patches. I have hundreds of patches not installed. Can't run Secunia with IE 8 it says: There might be problems loading the Java Applet in you browser. I'll stop posting now and wait for you. tyPlease just forget about Secunia. Sometimes it works well and other times it sort of goes crazy. The most important is to keep your Windows and Java up-to-date. •Please download Dial-A-Fix from one of the following mirrors: Primary mirror Secondary mirror •Extract the zip file to your desktop. •Double click Dial-a-Fix.exe to start the program. Dial-A-Fix might give you a lot errors, just ignore them and Click to continue. •Press the green double checkmark box (Looks like this: UNcheck Empty Temp Folders, as well as Adjust Time/Date in the prep section. The prep section should then look like this: •Click on Go •Wait for Dial-A-Fix to finish (All the checks marks will be all gone) •Close Dial-A-FixI did it Quote from: darcomputer on September 25, 2011, 04:52:42 PM I did it - Dial-A-FixQuote can i try and fix "Internet Explorer is currently running with add-ons disabled.I'm getting that same message on my laptop but I haven't tried to fix it. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 288. |
Solve : browser hijacking....help please!? |
|
Answer» Quote This may sound stupid, I wasn't sure if deleting would cause them to be re-installed later down the line somehow, but is it okay to just go ahead and delete the quarantined FILES ESET found?Yes, you can. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the TOOLS we used and the files and folders they created do the following: Double click OTL.exe.
******************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * DEPENDING on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO REPLACEMENT for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Awesome. Did everything, cleaned up the programs, downloaded a couple virus protection programs and got a new firewall. Everything still seems to be running good. Anything else I should do?Quote from: wiiman86 on September 27, 2011, 10:26:35 PM Awesome. Did everything, cleaned up the programs, downloaded a couple virus protection programs and got a new firewall. Everything still seems to be running good. Anything else I should do?Just stay safe. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 289. |
Solve : help with removal of http://gooogle-analytics.com/ga.min.js problem? |
|
Answer» Quote the problem is still there because it in firefox ABP part when I OPEN that up. Plus it doing strange things in firefox when I go to some websites.I'm not really sure what exactly the problem is with FireFox. Please explain it to me.The problem with firefox is that http://gooogle-analytics.com/ga.min.js was popping up all the time as malware in avast. The last several things you had me did stop the pop ups. Now it has integrate into adblockedplus script as this http://gooogle-analytics.com/ga.min.js as a script. The this makes sense.Quote The problem with firefox is that http://gooogle-analytics.com/ga.min.js was popping up all the time as malware in avast.Will Avast fix it?Avast was reporting it problem. With help it not popping up no more in Avast. But it still in adblocked plus scripted in firefox. The Avast pop up is gone now. The only worry is that adblocked plus is still has gooogle problem is in the script. I have not bank site yet or during my online class.Quote The only worry is that adblocked plus is still has gooogle problem is in the scriptSorry. I can't help you with this. We can now do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
*************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is FINISHED. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!I uninstall combofix and the google problem came back and Avast is going crazy again. SighsCould not get TFC by oldtimer to work on vista ultimate. It froze my computer three times and stall out was not responding. |
|
| 290. |
Solve : Google redirect problem? |
|
Answer» You can use this tool to remove McAfee.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next REPLY. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Dave, I ran the ESET OnlineScanner and no threats were found. It took about four hours to scan my system's seventy thousand files. My observations of my current system status: my system does not have the redirect problem and I have sound thanks to your directions to remedy those problems. However, I think I still have some less serious issues regarding connection. During the mid-afternoon portion of the day (between about 2pm and 5pm) and mid-evening (about 7pm to 9pm) I have problems connecting to the Internet or, while on the Internet during those time periods, my system is so slow it seems as though my machine has locked up. I think this might be a problem with the Internet service provider (Earthlink) because my wife's computer, with whom I share that service via a wireless connection, has a similar problem but her's is not as severe. Also, I think some of my connection problem might be caused by my wireless network connection (Trendnet to Linksys router) since the signal STRENGTH changes occasionally; the signal strength is not steady since it changes from excellent or good to average on occasion. Additionally, I think an icon in the system tray on my computer is indicating intermittent or loss of wireless network connection when the wave symbol, that normally lights up periodically (white color to green color) next to the monitor symbol, either freezes in the on position (green light) or fails to light (white color). Any suggestions? What do I do next? I'm interested in making sure all viruses and malware have been removed from my system. I do appreciate all your help; my improved Internet experience due to your help has allowed me to explore and navigate all the health care options for my ailing father and mother in-law. Again, thank you. Ken Quote Any suggestions? What do I do next? I'm interested in making sure all viruses and malware have been removed from my system.I'm quite confident that your computer is clean. Let's run one more scan to check that connection problem Please download MiniToolBox to Desktop and run it. Checkmark the following boxes:
The MiniToolBox log: MiniToolBox by Farbar Ran by User (administrator) on 06-09-2011 at 11:45:46 Microsoft Windows XP Service Pack 3 (X86) *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ # ---------------------------------- # Interface IP Configuration # ---------------------------------- pushd interface ip # Interface IP Configuration for "Local Area Connection" set address name="Local Area Connection" source=dhcp set dns name="Local Area Connection" source=dhcp register=PRIMARY set wins name="Local Area Connection" source=dhcp # Interface IP Configuration for "Wireless Network Connection 11" set address name="Wireless Network Connection 11" source=dhcp set dns name="Wireless Network Connection 11" source=dhcp register=PRIMARY set wins name="Wireless Network Connection 11" source=dhcp popd # End of interface IP configuration Windows IP Configuration Host Name . . . . . . . . . . . . : KenComputer Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Unknown IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Media State . . . . . . . . . . . : Media disconnected Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet for hp Physical Address. . . . . . . . . : 00-0F-20-6F-6B-2E Ethernet adapter Wireless Network Connection 11: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : TRENDnet TEW-424UB 54M USB Dongle Physical Address. . . . . . . . . : 00-14-D1-48-33-9E Dhcp Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IP Address. . . . . . . . . . . . : 192.168.2.102 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.2.1 DHCP Server . . . . . . . . . . . : 192.168.2.1 DNS Servers . . . . . . . . . . . : 192.168.1.1 Lease Obtained. . . . . . . . . . : Tuesday, September 06, 2011 9:31:46 AM Lease Expires . . . . . . . . . . : Wednesday, September 07, 2011 9:31:46 AM Server: UnKnown Address: 192.168.1.1 Name: google.com Addresses: 74.125.93.106, 74.125.93.103, 74.125.93.147, 74.125.93.105 74.125.93.99, 74.125.93.104 Pinging google.com [74.125.93.99] with 32 bytes of data: Reply from 74.125.93.99: bytes=32 time=95ms TTL=53 Reply from 74.125.93.99: bytes=32 time=94ms TTL=53 Ping statistics for 74.125.93.99: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 94ms, Maximum = 95ms, Average = 94ms Server: UnKnown Address: 192.168.1.1 Name: yahoo.com Addresses: 209.191.122.70, 67.195.160.76, 69.147.125.65, 72.30.2.43 98.137.149.56 Pinging yahoo.com [98.137.149.56] with 32 bytes of data: Reply from 98.137.149.56: bytes=32 time=41ms TTL=56 Reply from 98.137.149.56: bytes=32 time=71ms TTL=56 Ping statistics for 98.137.149.56: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 41ms, Maximum = 71ms, Average = 56ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 0x1 ........................... MS TCP Loopback interface 0x10003 ...00 0f 20 6f 6b 2e ...... Broadcom NetXtreme Gigabit Ethernet for hp 0x10004 ...00 14 d1 48 33 9e ...... TRENDnet TEW-424UB 54M USB Dongle =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.102 25 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 192.168.2.0 255.255.255.0 192.168.2.102 192.168.2.102 25 192.168.2.102 255.255.255.255 127.0.0.1 127.0.0.1 25 192.168.2.255 255.255.255.255 192.168.2.102 192.168.2.102 25 224.0.0.0 240.0.0.0 192.168.2.102 192.168.2.102 25 255.255.255.255 255.255.255.255 192.168.2.102 10003 1 255.255.255.255 255.255.255.255 192.168.2.102 192.168.2.102 1 Default Gateway: 192.168.2.1 =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list SEQUENCE number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. Error: (08/29/2011 00:11:04 PM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. System errors: ============= Error: (09/06/2011 09:30:46 AM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/04/2011 10:37:16 AM) (Source: Windows Update Agent) (User: ) Description: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error: (09/04/2011 10:35:32 AM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/01/2011 09:57:19 PM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/01/2011 09:30:57 PM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/01/2011 09:08:36 PM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/01/2011 08:19:46 PM) (Source: Service Control Manager) (User: ) Description: The IPSEC Services service terminated with the following error: %%1747 Error: (09/01/2011 08:18:51 PM) (Source: Service Control Manager) (User: ) Description: The Remote Access Connection Manager service failed to start due to the following error: %%231 Error: (09/01/2011 08:18:51 PM) (Source: Service Control Manager) (User: ) Description: The Remote Access Connection Manager service failed to start due to the following error: %%231 Error: (09/01/2011 08:18:22 PM) (Source: Service Control Manager) (User: ) Description: The Remote Access Connection Manager service DEPENDS on the Telephony service which failed to start because of the following error: %%1070 Microsoft Office Sessions: ========================= Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. Error: (08/29/2011 00:11:04 PM) (Source: crypt32)(User: ) Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist. ========================= Memory info: =================================== Percentage of memory in use: 36% Total physical RAM: 1527.48 MB Available physical RAM: 966.02 MB Total Pagefile: 2904.86 MB Available Pagefile: 2485.6 MB Total Virtual: 2047.88 MB Available Virtual: 1905.03 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:74.53 GB) (Free:51.72 GB) NTFS ========================= Users: ======================================== User accounts for \\ Administrator ASPNET Guest HelpAssistant SUPPORT_388945a0 User **** End of log **** The signal is going through but, like you said, it is intermittent. Have you tried hardwiring your computer to the modem? It would appear to be a problem with the wireless. Also, please reset your modem and router. Unplug them for a minute. Dave, With a hardwire connecting my computer to the router located at my wife's computer, I have a good Internet connection. My wife reset the router (pushed the button and unplugged the unit) and disconnected the modem (turned it off at the switch as well as unplugged the unit). It was a lot of work to follow the instructions to get the router, that is wired directly to my wife's system, back up and running but she was finally able to accomplish the task and she has her Internet phone and Internet connection back. There was a side benefit of all this work: we found and properly filed our computer system literature and found some other missing items as well! My system required more work and was not entirely successful. My wireless Internet connection is worse since the router/modem reset and my reinstalling the wireless software & adapter. After the resetting the modem and router, I could not hookup my system to the Internet (my system: Trendnet wireless USB adapter [TEW-424UB] to Linksys router [Wireless-G Broadband Router--mdl. WRT54G2]). After checking on the Trendnet status, I reentered the security key and was able to get some activity on that device (searching to establish a connection with the router) but still no connection. I decided to reinstall the Trendnet software on my computer. Immediately after reinstalling, I got fifteen minutes of uninterrupted, though slow, Internet connection until I was disconnected. I could only continue intermittent connection by repairing the connection (by clicking on the icon in the system tray to pop-up a window for that device and then clicking on "Repair"). I had to do this continually to receive about a minute or two of connection. I kept an eye on the signal strength during this phase of the problem and noticed that it would go from a good connection (multi-bar green) to weak connection (single bar red) back to fair connection (no bar) back to good connection and so forth. The Internet connection was slow during this time frame (for a minute or two) until I loss the connection entirely (red "X"). I have not had this condition in the past. Before the router/modem reset and my reinstalling the Trendnet software and adapter, I would routinely get periods of no connection to connection periods of an hour or two. Things have gone downhill in regard to wireless connectivity. By the way, I wonder if the wireless connection is having problems due to the building structure where I live. My place is a small townhouse and has concrete party walls (the wall between units) with wood framing in the interior of the unit. The router is located about twenty five feet away from my computer and is in another room. Again, the hardwire connection between my computer and the router is working very well and the Google redirect problem has been solved due to your direction. I have an uninterrupted Internet connection with the hardwire. I'm not sure if my wireless Internet connection problem is a virus\malware issue; perhaps I should start a new post? If so, please advise if I should uninstall the various anti virus software packages that I have installed on my system at your direction. Please include any tips on making the uninstalls successful. Thank you for your help to date. Ken Quote I'm not sure if my wireless Internet connection problem is a virus\malware issueFrom what you described to me, it would appear that the problem is with the router sending the signal or the receiver. Unfortunately, I can't help you with this. You could start another thread in another forum. Perhaps that may help. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Dave, I successfully completed the uninstall of ComboFix. I don't have OTL.exe on my system; it must have been removed by my running my anti-virus during this Google redirect problem process (see my reply #12, August 10--I shouldn't have done that as you mention in your introductory instructions). Do I delete or try to uninstall the following programs that are on my desktop that I downloaded at your direction? 1. TDSKiller.exe 2. tdskiller zip 3. Support-LogMeInRescue.exe 4. RootRepeal zip 5. MiniToolBox.exe 6. HjackThisInstaller.exe 7. esetsmartinstalaler_enu.exe I want to make sure I don't accidentally run these programs again. To delete I should double right click on the icon and left click on delete in that window? If I need to uninstall any of these programs, please provide instructions. Are there any other things I have to do to take care of any possible buried files from my deletion of programs that were on my system prior to my reply #12 of August 10 (deleted due to my errant running of my Deluxe Shield anti virus and PC Tools Spyware Doctor)? Those programs were: 1. Super Antispyware (SAS) 2. Malawarebytes 3. DDS 4. RKill 5. Combo.fix 6. Jotti's Malaware scan (I don't think this was a downloaded program?) The following describes what I did at that time of deletion of those programs (from my reply #12 in August): "I re-enabled my Deluxe Shield as well as my PC Tools Spyware Doctor antivirus checkers and ran them after the ComboFix scan. I'm not sure I did a good thing. The PC Tools Spyware caught a lot of items, though did not defined what items it caught, and fixed those files and the system does not run better." Thank you, KenQuote Do I delete or try to uninstall the following programs that are on my desktop that I downloaded at your direction?Yes. If the programs are installed on your desktop, simply delete them or drag them to your Recycling bin. If not installed on your desktop, uninstall them. Support-LogMeInRescue.exe is not one of the programs I asked you to install. You may keep SAS and MBAM, if you wish. Update them and run them on a regular basis. All the others can go. Dave, I got the other programs off my system per your direction. My system is running very well--thank you. Sorry about the "Support-LogMeIn" program citing. That was the Shield Deluxe anti-virus personnel log-in to help me install their new 2011 program after I thought I lost my password for the 2010 edition. That was a big mess and totally my fault. I now take better care of my passwords. I think I have one last question. To prevent the loss of my files on the hard drive, I saved some of my files (personal files and not programs I think) on thumb drives (two or three thumb drives up to 1GB capacity each) prior to all your work on my system. I want to know if I can reuse those thumb drives without jeopardizing my system? In other words, can I can plug those thumb drives back into my system, delete the contents, and reuse the thumb drives? I thought I should be safe rather than sorry and ask you before I do this. Ken Quote In other words, can I can plug those thumb drives back into my system, delete the contents, and reuse the thumb drives? I thought I should be safe rather than sorry and ask you before I do this.Yes. When you plug in the thumb drives hold the Shift key down for about 10 secs. while inserting them in the USB drive. Then, scan them with your AV and also with SAS and MBAM to be sure that they're clean. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 291. |
Solve : remove Virus? |
|
Answer» Need Help with REMOVE Trojon And Adware VirusPlease GO to this link and FOLLOW the directions and post the required LOGS. |
|
| 292. |
Solve : Please help - Fake Spy Pro issues? |
|
Answer» Ok. One more scan. |
|
| 293. |
Solve : IE 7 Redirects? |
|
Answer» Please download the newest version of Adobe Acrobat Reader from Adobe.com
RESIDENT Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into GIVING them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
| 294. |
Solve : fake "windows security center" virus; won't allow me to run any programs? |
|
Answer» Results of screen317's Security Check version 0.99.4 |
|
| 295. |
Solve : "Ssytem" at top of Task Manager? |
|
Answer» But if I remove AVG free edition, what will I protect my computer with?That was why I said to install Avira free from http://www.free-av.comDragonMaster Jay, I renounce God and now pray to you!! Thank you for the miracle!! My SYSTEM is ridonculously low. from 97K to 240 stable, not EVEN fluctuating at all. Just 240.Glad that worked. |
|
| 296. |
Solve : Re: Need some help? |
|
Answer» i have the exact same problem however I have been able to run combofix. Here is the output file:
|
|
| 297. |
Solve : Application is executed the file --------- maybe infected? |
|
Answer» Malwarebytes' Anti-Malware 1.46
something strange happened. The first time i rant eh scan it foudn 3 objects infected, then before it could finish the scan it restarted my computer. I had to start all over again, and when it was finished it found no viruses. this is the log it created ------------- [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 esets_scanner_update returned -1 esets_gle=53251Ok good. Anymore alerts? Cleanup time?nope no more alerts. any other steps?If there are no more issues, then it is time to clean up. To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 298. |
Solve : Need some help? |
|
Answer» Ok it rebooted and automatically opened note pad, heres the report
the computer is definatly still connected to the internetPlease run a free online scan with the ESET Online Scanner
OnlineScanner.ocx - registred OK To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows Vista Service Pack 1 (UAC is enabled) Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! avast! Antivirus ESET Online Scanner v3 McAfee SecurityCenter WMI entry may not exist for antivirus; attempting automatic update. avast! successfully updated! ``````````````````````````````` Anti-malware/Other Utilities Check: Java(TM) 6 Update 20 Adobe Flash Player 10.0.45.2 Adobe Reader 9 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Alwil Software Avast4 aswUpdSv.exe Alwil Software Avast4 ashServ.exe Alwil Software Avast4 ashMaiSv.exe Alwil Software Avast4 ashWebSv.exe McAfee VIRUSS~1 mcshield.exe McAfee VIRUSS~1 mcsysmon.exe ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Please consider updating to Windows Vista Service Pack 2 (SP2). Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards. It is now available via Windows Update or as a standalone installation here. ============================= Please download the NEWEST version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. ============================= See this page for more info about malware and prevention.Updated everythingGood. cheers for your help |
|
| 299. |
Solve : ?!?!?!?! - new malware problem - need help please - ?!?!?!?!? |
|
Answer» You're WELCOME. |
|
| 300. |
Solve : Getting pop-ups & Error messages!? |
|
Answer» Non more pop-ups but,10+ alerts from MicroSoft Security Essentials. Is this the log from ESET or MSE? Anymore alerts? ESET. And not as of yet Ok. If there are no other issues, it's time for some clean-up. * Click START then RUN - Vista users press the Windows KEY and the R keys for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a NEW, clean Restore Point. ========================= Uninstall GMER Click on Start > Run and type in or copy/paste all of the Red text into the Run box. %windir%\gmer_uninstall.cmd Click OK to remove GMER. ============================= Download OTC by OldTimer and save it to your desktop. 1. Double-click OTC to run it. 2. Click the CleanUp! button. 3. Select Yes when the "Begin cleanup Process?" prompt appears. 4. If you are prompted to Reboot during the cleanup, select Yes 5. OTC should delete itself once it finishes, if not delete it yourself. =============================== Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ================================= Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ===================================== Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|