Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

251.

Solve : Scan Results?

Answer»

Sorry i didn't clarify. I am running as administrator. Ok. You will have to skip over Secunia but please make sure that Windows and Java are up-to-date.I was able to update all the other programs that came up from Secunia something is just messed up with acrobat reader.

Windows and Java are up to date.

I was able to remove all the other programs we used also.

One thing I'm noticing it it takes a lot longer for my computer to login to a account (admin or matthew) since I have loaded a 3rd party firewall (Online Armor). My computer makes a strange buzzing/ SCRAPING sound (sounds like the hard drive) when the firewall is turned on/ off. Is that normal? Should I remove it and load another? Quote

My computer makes a strange buzzing/ scraping sound (sounds like the hard drive) when the firewall is turned on/ off. Is that normal? Should I remove it and load another?
It sounds like something is amiss in the harddrive or one of the fans. It could be just a coincidence that it started at the same time you installed a third-party Firewall. Try uninstall the firewall altogether and see what happens.Will do.

Also another question do you know how to unlock a registry key so i can install the latest Acrobat reader/ I keep getting the error:
Error 1402.could not open key:
HKEY_local_Machine\software\microsoft\windows\currentversion\Run\optionalcomponents\MSFS.
Verify that you have sufficient access to that key of contact support personel
When i try to install the latest version of acrobat reader.

I tried going through the steps at http://johnsonyip.com/index.php?option=com_content&view=article&id=96&Itemid=198 but hit a wall around step 11 because i don't have a "other users or groups..." button.

I'd really need to have acrobat reader on my computer.Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

link # 1
Link # 2
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Post the ComboFix log in your next reply.
Please try to install Acrobat Reader now.That worked! you are fricking amazing. Thank you very much. Here is the log:

ComboFix 11-04-25.02 - Admin 04/25/2011 20:43:34.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2476 [GMT -7:00]
Running from: c:\documents and settings\Admin\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-26 to 2011-04-26 )))))))))))))))))))))))))))))))
.
.
2011-04-25 18:58 . 2011-04-25 18:5828752----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\MpKsl6656390c.sys
2011-04-25 18:58 . 2011-04-11 07:047071056----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\mpengine.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-04-22 20:36 . 2011-04-22 20:36159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-04-22 20:35 . 2011-04-22 20:36--------d-----w-c:\program files\QuickTime
2011-04-22 08:09 . 2011-04-22 08:09--------d-----w-c:\documents and settings\Matthew\Application Data\OnlineArmor
2011-04-22 06:51 . 2011-04-22 07:28--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor
2011-04-22 06:51 . 2011-04-22 06:51--------d-----w-c:\documents and settings\Admin\Application Data\OnlineArmor
2011-04-22 06:50 . 2011-04-06 20:0239048----a-w-c:\windows\system32\drivers\oahlp32.sys
2011-04-22 06:50 . 2011-04-06 20:0129464----a-w-c:\windows\system32\drivers\OAnet.sys
2011-04-22 06:50 . 2011-04-06 20:0125192----a-w-c:\windows\system32\drivers\OAmon.sys
2011-04-22 06:50 . 2011-04-06 20:01205864----a-w-c:\windows\system32\drivers\OADriver.sys
2011-04-22 06:49 . 2011-04-22 07:26--------d-----w-c:\program files\Online Armor
2011-04-21 01:20 . 2011-04-21 01:20--------d-----w-c:\documents and settings\Admin\Application Data\Hi-Rez Studios
2011-04-21 01:18 . 2011-04-21 01:18--------d-----w-c:\documents and settings\All Users\Application Data\Hi-Rez Studios
2011-04-21 01:18 . 2011-04-21 18:46--------d-----w-c:\program files\Hi-Rez Studios
2011-04-20 19:18 . 2011-04-11 07:047071056----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-20 06:55 . 2011-04-20 06:55--------d-----w-c:\program files\ESET
2011-04-19 06:25 . 2010-10-19 20:51222080------w-c:\windows\system32\MpSigStub.exe
2011-04-19 06:22 . 2011-04-19 06:23--------d-----w-c:\program files\Microsoft Security Client
2011-04-17 20:03 . 2011-04-17 20:03--------d-----w-c:\program files\Ventrilo
2011-04-17 20:02 . 2011-04-21 05:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2011-04-16 04:33 . 2011-04-16 04:33--------d-----w-c:\program files\Common Files\Java
2011-04-16 04:32 . 2011-02-03 04:40472808----a-w-c:\windows\system32\deployJava1.dll
2011-04-16 04:03 . 2011-04-16 04:03--------d-----w-c:\documents and settings\Admin\Application Data\Malwarebytes
2011-04-16 03:22 . 2011-04-16 03:22--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-15 22:35 . 2011-04-15 22:35--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-13 05:33 . 2011-04-13 05:33--------d-----w-c:\documents and settings\Matthew\Local Settings\Application Data\Mozilla
2011-04-13 03:06 . 2011-04-13 03:06--------d-----w-c:\documents and settings\Kary\Application Data\Wacom
2011-04-13 03:06 . 2011-04-13 03:06--------d-----w-c:\documents and settings\Kary\Application Data\WTablet
2011-04-12 23:00 . 2011-04-12 23:00--------d-----w-c:\program files\GameSpy Arcade
2011-04-12 22:57 . 2011-04-12 22:57--------d-----w-c:\program files\Irrational Games
2011-04-08 06:11 . 2010-12-02 09:12837224----a-w-c:\windows\system32\nvgenco32hda.dll
2011-04-06 10:43 . 2011-01-08 03:27941160----a-w-c:\windows\system32\nvdispco322090.dll
2011-04-06 10:43 . 2011-01-08 03:27837736----a-w-c:\windows\system32\nvgenco322040.dll
2011-04-06 09:43 . 2011-04-06 09:43--------d-----w-c:\program files\Common Files\Creative
2011-04-06 09:42 . 2011-04-06 09:44--------d--h--w-c:\program files\Creative Installation Information
2011-04-06 09:27 . 2011-04-06 09:27--------d-----w-c:\documents and settings\All Users\Application Data\Creative
2011-04-06 09:24 . 2003-06-13 06:257062----a-w-c:\windows\system32\audiopid.vxd
2011-04-06 09:24 . 2011-04-06 09:24--------d-----w-c:\program files\Common Files\Creative Labs Shared
2011-04-06 09:23 . 2011-04-06 09:23445016----a-w-c:\windows\system32\wrap_oal.dll
2011-04-06 09:23 . 2004-07-13 01:53585728----a-w-c:\windows\system32\ctaudfx.dll
2011-04-06 09:23 . 2003-11-13 10:04606208----a-w-c:\windows\system32\ctsblfx.dll
2011-04-06 09:23 . 2003-11-13 10:02114688----a-w-c:\windows\system32\commonfx.dll
2011-04-06 09:14 . 2003-11-11 01:14729088----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-04-06 09:14 . 2003-11-11 01:1369715----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-04-06 09:14 . 2003-11-11 01:12266240----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-04-06 09:14 . 2003-11-11 01:12192512----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-04-06 09:14 . 2003-11-11 01:115632----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-04-06 09:14 . 2011-04-06 09:14188548----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-04-06 09:14 . 2011-04-06 09:14311428----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-04-06 09:12 . 2011-04-06 09:12--------d-----w-c:\documents and settings\Matthew\Application Data\InstallShield Installation Information
2011-04-02 09:23 . 2011-04-02 09:23--------d-----w-c:\documents and settings\Admin\Application Data\SystemRequirementsLab
2011-04-02 09:16 . 2011-04-02 09:16--------d-----w-c:\documents and settings\Admin\Local Settings\Application Data\Mozilla
2011-04-02 01:54 . 2011-04-02 01:54--------d-----w-c:\documents and settings\Admin\Application Data\NVIDIA
2011-04-02 01:31 . 2010-11-11 23:1026216----a-w-c:\windows\system32\nvhdap32.dll
2011-04-02 01:31 . 2010-11-11 23:10100456----a-w-c:\windows\system32\drivers\nvhda32.sys
2011-04-02 01:31 . 2010-06-21 22:07232040----a-w-c:\windows\system32\nvcohda.dll
2011-04-02 01:29 . 2011-04-08 06:11252080----a-w-c:\windows\system32\nvdrsdb0.bin
2011-04-02 01:29 . 2011-04-08 06:111----a-w-c:\windows\system32\nvdrssel.bin
2011-04-02 01:29 . 2011-04-08 06:11252080----a-w-c:\windows\system32\nvdrsdb1.bin
2011-03-28 23:13 . 2011-03-28 23:17--------d-----w-c:\program files\SIW
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 09:23 . 2009-05-21 01:18109144----a-w-c:\windows\system32\OpenAL32.dll
2011-03-07 05:33 . 2009-05-20 21:35692736----a-w-c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2004-08-04 12:00434176----a-w-c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 12:001857920----a-w-c:\windows\system32\win32k.sys
2011-02-17 19:00 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll
2011-02-17 19:00 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll
2011-02-17 19:00 . 2004-08-04 12:001830912------w-c:\windows\system32\inetcpl.cpl
2011-02-17 19:00 . 2004-08-04 12:0017408------w-c:\windows\system32\corpol.dll
2011-02-17 13:18 . 2004-08-04 12:00455936----a-w-c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 12:00357888----a-w-c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-05-22 22:185120----a-w-c:\windows\system32\xpsp4res.dll
2011-02-17 11:44 . 2004-08-04 12:00389120----a-w-c:\windows\system32\html.iec
2011-02-15 12:56 . 2004-08-04 12:00290432----a-w-c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2004-08-04 12:00270848----a-w-c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-04 12:00186880----a-w-c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2004-08-04 12:00978944----a-w-c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2004-08-04 12:00974848----a-w-c:\windows\system32\mfc42u.dll
2011-02-03 02:19 . 2009-07-29 08:5173728----a-w-c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2009-05-20 21:342067456----a-w-c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-05-20 21:34677888----a-w-c:\windows\system32\mstsc.exe
2011-03-18 17:53 . 2011-04-02 09:16142296----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-03-16 127037]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-02-10 629336]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"CTHelper"="CTHELPER.EXE" [2010-03-19 19456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-08 13880424]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-08 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
.
c:\documents and settings\Admin\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"d:\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"d:\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"d:\\World of Warcraft\\WoW-3.2.2.10505-to-3.3.0.10958-enUS-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Fantasy Grounds II\\FantasyGrounds.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Hi-Rez Studios\\games\\global agenda live\\Binaries\\GlobalAgenda.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R1 MpKsl6656390c;MpKsl6656390c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEC163F9-24A5-4CBB-A32E-CC1C6ACAE756}\MpKsl6656390c.sys [4/25/2011 11:58 AM 28752]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [4/21/2011 11:50 PM 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [4/21/2011 11:50 PM 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [4/21/2011 11:50 PM 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [4/21/2011 11:50 PM 29464]
R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [3/8/2011 2:54 AM 401920]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2/14/2011 5:28 AM 21992]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\Hi-Rez Studios\HiPatchService.exe [4/13/2011 1:02 PM 23680]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [4/21/2011 11:49 PM 381512]
R2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2/10/2011 4:04 PM 4869488]
R2 TouchServicePen;Wacom CONSUMER Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2/10/2011 4:05 PM 416112]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [4/1/2011 6:31 PM 100456]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2/10/2011 4:04 PM 16240]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/24/2011 11:29 PM 136176]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416]
S3 cpuz134;cpuz134;\??\c:\docume~1\Admin\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\Admin\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [4/6/2011 2:24 AM 79360]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/24/2011 11:29 PM 136176]
S3 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [4/21/2011 11:49 PM 4326472]
S4 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys --> c:\windows\system32\DRIVERS\AVGIDSShim.Sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 01:49]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 01:49]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1004Core.job
- c:\documents and settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 14:55]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1004UA.job
- c:\documents and settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 14:55]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1005Core.job
- c:\documents and settings\Kary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 16:50]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1005UA.job
- c:\documents and settings\Kary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 16:50]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1006Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 09:31]
.
2011-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1078145449-725345543-1006UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 09:31]
.
2011-04-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 19:26]
.
.
------- SUPPLEMENTARY Scan -------
.
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\ee30ac2q.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-25 20:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2156)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Tablet\Pen\Pen_TouchUser.exe
c:\windows\system32\wscntfy.exe
c:\program files\Tablet\Pen\Pen_TabletUser.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-04-25 20:53:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-26 03:53
.
Pre-Run: 169,950,330,880 bytes free
Post-Run: 170,042,322,944 bytes free
.
- - End Of File - - 19BC45C840308F97D27905FDDB2E5623
Were you able to install Acrobat Reader?Yes I was. Thank you.Good. Carry on with your cleanup as described in Reply # 25. Please LET me know when you're done.Quote from: darthgaul on April 23, 2011, 01:32:48 PM
Will do.

Also another question do you know how to unlock a registry key so i can install the latest Acrobat reader/ I keep getting the error:
Error 1402.could not open key:
HKEY_local_Machine\software\microsoft\windows\currentversion\Run\optionalcomponents\MSFS.
Verify that you have sufficient access to that key of contact support personel
When i try to install the latest version of acrobat reader.

I tried going through the steps at http://johnsonyip.com/index.php?option=com_content&view=article&id=96&Itemid=198 but hit a wall around step 11 because i don't have a "other users or groups..." button.

I'd really need to have acrobat reader on my computer.

The website for http://johnsonyip.com/index.php?option=com_content&view=article&id=96&Itemid=198 moved to http://johnsonyip.com/how-to-unlock-windows-registry-permissions-tuturials.htm

You can try turning off UAC and switching to the classic theme to see if it works.Quote from: SuperDave on April 26, 2011, 04:57:52 PM
Good. Carry on with your cleanup as described in Reply # 25. Please let me know when you're done.

All Done.Very well. I will lock this thread. If you need it re-opened, please send me a pm.
252.

Solve : Virus Removal Assistance Needed, Please Help :S?

Answer»
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
Dave, it found one malicious problem and it "cured" it!

Here's the report...





2011/04/30 01:38:03.0483 4204TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/04/30 01:38:04.0918 4204================================================================================
2011/04/30 01:38:04.0918 4204SystemInfo:
2011/04/30 01:38:04.0918 4204
2011/04/30 01:38:04.0918 4204OS Version: 6.1.7600 ServicePack: 0.0
2011/04/30 01:38:04.0918 4204Product TYPE: Workstation
2011/04/30 01:38:04.0918 4204ComputerName: LAPTOP
2011/04/30 01:38:04.0918 4204UserName: Chris
2011/04/30 01:38:04.0918 4204Windows directory: C:\windows
2011/04/30 01:38:04.0918 4204System windows directory: C:\windows
2011/04/30 01:38:04.0918 4204Processor architecture: Intel x86
2011/04/30 01:38:04.0918 4204Number of processors: 2
2011/04/30 01:38:04.0918 4204Page size: 0x1000
2011/04/30 01:38:04.0918 4204Boot type: Normal boot
2011/04/30 01:38:04.0918 4204================================================================================
2011/04/30 01:38:05.0246 4204Initialize success
2011/04/30 01:38:11.0408 4276================================================================================
2011/04/30 01:38:11.0408 4276Scan started
2011/04/30 01:38:11.0408 4276Mode: Manual;
2011/04/30 01:38:11.0408 4276================================================================================
2011/04/30 01:38:14.0107 42761394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
2011/04/30 01:38:14.0216 4276ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
2011/04/30 01:38:14.0403 4276AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
2011/04/30 01:38:14.0575 4276adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
2011/04/30 01:38:14.0746 4276adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
2011/04/30 01:38:14.0980 4276adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
2011/04/30 01:38:15.0183 4276AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys
2011/04/30 01:38:15.0433 4276AFS (be913403ed7219894b30e362fd8d4313) C:\windows\system32\drivers\AFS.sys
2011/04/30 01:38:15.0682 4276AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys
2011/04/30 01:38:15.0901 4276agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
2011/04/30 01:38:16.0072 4276aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
2011/04/30 01:38:16.0244 4276aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
2011/04/30 01:38:16.0416 4276amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
2011/04/30 01:38:16.0556 4276amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
2011/04/30 01:38:16.0837 4276AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
2011/04/30 01:38:17.0055 4276AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
2011/04/30 01:38:17.0196 4276amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
2011/04/30 01:38:17.0320 4276amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
2011/04/30 01:38:17.0398 4276amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
2011/04/30 01:38:17.0492 4276AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
2011/04/30 01:38:17.0648 4276arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
2011/04/30 01:38:17.0742 4276arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
2011/04/30 01:38:17.0913 4276AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
2011/04/30 01:38:17.0991 4276atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
2011/04/30 01:38:18.0241 4276atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys
2011/04/30 01:38:18.0459 4276AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys
2011/04/30 01:38:18.0615 4276AVGIDSDriver (b93c0f409482d6c0e581caca51ae9c02) C:\windows\system32\DRIVERS\AVGIDSDriver.Sys
2011/04/30 01:38:18.0802 4276AVGIDSEH (13256fc72fa5b3f6d6e8c5957e579b7c) C:\windows\system32\DRIVERS\AVGIDSEH.Sys
2011/04/30 01:38:18.0943 4276AVGIDSFilter (fa0685cc51de5cfd804e7deaa6488e0e) C:\windows\system32\DRIVERS\AVGIDSFilter.Sys
2011/04/30 01:38:19.0052 4276AVGIDSShim (f788b51100d0f40ea176798cce954a1a) C:\windows\system32\DRIVERS\AVGIDSShim.Sys
2011/04/30 01:38:19.0208 4276Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\windows\system32\DRIVERS\avgldx86.sys
2011/04/30 01:38:19.0348 4276Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\windows\system32\DRIVERS\avgmfx86.sys
2011/04/30 01:38:19.0489 4276Avgrkx86 (ffbe8adeb1fd8640540bf6e4a137b3ef) C:\windows\system32\DRIVERS\avgrkx86.sys
2011/04/30 01:38:19.0614 4276Avgtdix (69e6adf5cbbdeb5f2b727c93937a5823) C:\windows\system32\DRIVERS\avgtdix.sys
2011/04/30 01:38:19.0832 4276b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
2011/04/30 01:38:19.0988 4276b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
2011/04/30 01:38:20.0113 4276Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
2011/04/30 01:38:20.0269 4276blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
2011/04/30 01:38:20.0394 4276bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys
2011/04/30 01:38:20.0456 4276BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
2011/04/30 01:38:20.0550 4276BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
2011/04/30 01:38:20.0706 4276Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
2011/04/30 01:38:20.0877 4276BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
2011/04/30 01:38:20.0986 4276BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
2011/04/30 01:38:21.0064 4276BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
2011/04/30 01:38:21.0158 4276BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
2011/04/30 01:38:21.0283 4276cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
2011/04/30 01:38:21.0392 4276cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
2011/04/30 01:38:21.0548 4276circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
2011/04/30 01:38:21.0626 4276CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
2011/04/30 01:38:21.0751 4276CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
2011/04/30 01:38:21.0829 4276cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
2011/04/30 01:38:21.0938 4276CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
2011/04/30 01:38:22.0063 4276Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
2011/04/30 01:38:22.0172 4276CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
2011/04/30 01:38:22.0312 4276crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
2011/04/30 01:38:22.0500 4276DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys
2011/04/30 01:38:22.0640 4276discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
2011/04/30 01:38:22.0749 4276Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
2011/04/30 01:38:22.0921 4276Dot4 (b5e479eb83707dd698f66953e922042c) C:\windows\system32\DRIVERS\Dot4.sys
2011/04/30 01:38:23.0248 4276Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\windows\system32\DRIVERS\Dot4Prt.sys
2011/04/30 01:38:23.0451 4276dot4usb (cf491ff38d62143203c065260567e2f7) C:\windows\system32\DRIVERS\dot4usb.sys
2011/04/30 01:38:23.0623 4276drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
2011/04/30 01:38:23.0888 4276DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\windows\System32\drivers\dxgkrnl.sys
2011/04/30 01:38:24.0465 4276ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
2011/04/30 01:38:24.0684 4276elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
2011/04/30 01:38:24.0824 4276epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\windows\system32\epmntdrv.sys
2011/04/30 01:38:24.0886 4276ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
2011/04/30 01:38:25.0011 4276EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\windows\system32\EuGdiDrv.sys
2011/04/30 01:38:25.0120 4276exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
2011/04/30 01:38:25.0214 4276fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
2011/04/30 01:38:25.0308 4276fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
2011/04/30 01:38:25.0370 4276FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
2011/04/30 01:38:25.0448 4276Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
2011/04/30 01:38:25.0495 4276flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
2011/04/30 01:38:25.0604 4276FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
2011/04/30 01:38:25.0713 4276FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
2011/04/30 01:38:25.0932 4276Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
2011/04/30 01:38:26.0119 4276fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys
2011/04/30 01:38:26.0275 4276gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
2011/04/30 01:38:26.0368 4276GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
2011/04/30 01:38:26.0540 4276hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
2011/04/30 01:38:26.0665 4276HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
2011/04/30 01:38:26.0790 4276HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
2011/04/30 01:38:26.0868 4276HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
2011/04/30 01:38:26.0946 4276HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
2011/04/30 01:38:27.0008 4276HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
2011/04/30 01:38:27.0102 4276HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
2011/04/30 01:38:27.0242 4276HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
2011/04/30 01:38:27.0351 4276HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
2011/04/30 01:38:27.0507 4276hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
2011/04/30 01:38:27.0679 4276i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
2011/04/30 01:38:27.0804 4276iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
2011/04/30 01:38:27.0975 4276iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
2011/04/30 01:38:28.0162 4276IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys
2011/04/30 01:38:28.0318 4276intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
2011/04/30 01:38:28.0459 4276intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
2011/04/30 01:38:28.0584 4276IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
2011/04/30 01:38:28.0708 4276IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
2011/04/30 01:38:28.0818 4276IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
2011/04/30 01:38:28.0942 4276IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
2011/04/30 01:38:29.0052 4276isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
2011/04/30 01:38:29.0176 4276iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
2011/04/30 01:38:29.0286 4276kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
2011/04/30 01:38:29.0395 4276kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
2011/04/30 01:38:29.0520 4276KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
2011/04/30 01:38:29.0629 4276KSecPkg (26c046977e85b95036453d7b88ba1820) C:\windows\system32\Drivers\ksecpkg.sys
2011/04/30 01:38:29.0754 4276Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2011/04/30 01:38:29.0878 4276Lbd (336abe8721cbc3110f1c6426da633417) C:\windows\system32\DRIVERS\Lbd.sys
2011/04/30 01:38:30.0003 4276lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
2011/04/30 01:38:30.0159 4276LPCFilter (6e3d3816749e107883eec5734ce44493) C:\windows\system32\DRIVERS\LPCFilter.sys
2011/04/30 01:38:30.0331 4276LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
2011/04/30 01:38:30.0471 4276LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
2011/04/30 01:38:30.0658 4276LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
2011/04/30 01:38:30.0861 4276LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
2011/04/30 01:38:31.0080 4276luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
2011/04/30 01:38:31.0220 4276megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
2011/04/30 01:38:31.0360 4276MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
2011/04/30 01:38:31.0485 4276Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
2011/04/30 01:38:31.0657 4276monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
2011/04/30 01:38:31.0766 4276mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
2011/04/30 01:38:31.0875 4276mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
2011/04/30 01:38:32.0031 4276mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
2011/04/30 01:38:32.0187 4276mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
2011/04/30 01:38:32.0312 4276mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
2011/04/30 01:38:32.0421 4276MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
2011/04/30 01:38:32.0530 4276mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\windows\system32\DRIVERS\mrxsmb.sys
2011/04/30 01:38:32.0718 4276mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\windows\system32\DRIVERS\mrxsmb10.sys
2011/04/30 01:38:32.0889 4276mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\windows\system32\DRIVERS\mrxsmb20.sys
2011/04/30 01:38:33.0076 4276msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
2011/04/30 01:38:33.0232 4276msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
2011/04/30 01:38:33.0404 4276Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
2011/04/30 01:38:33.0591 4276mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
2011/04/30 01:38:33.0763 4276msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
2011/04/30 01:38:33.0997 4276MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
2011/04/30 01:38:34.0122 4276MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
2011/04/30 01:38:34.0184 4276MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
2011/04/30 01:38:34.0278 4276MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
2011/04/30 01:38:34.0387 4276mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
2011/04/30 01:38:34.0512 4276MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
2011/04/30 01:38:34.0574 4276MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
2011/04/30 01:38:34.0668 4276Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
2011/04/30 01:38:34.0777 4276MxlW2k (d37a535bbe77a16c232969c6882b524b) C:\windows\system32\drivers\MxlW2k.sys
2011/04/30 01:38:34.0855 4276NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
2011/04/30 01:38:34.0933 4276NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
2011/04/30 01:38:35.0058 4276NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
2011/04/30 01:38:35.0167 4276NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
2011/04/30 01:38:35.0260 4276Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
2011/04/30 01:38:35.0307 4276NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
2011/04/30 01:38:35.0416 4276NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
2011/04/30 01:38:35.0557 4276NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
2011/04/30 01:38:35.0650 4276NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
2011/04/30 01:38:35.0822 4276nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
2011/04/30 01:38:35.0947 4276nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\windows\system32\drivers\ccdcmb.sys
2011/04/30 01:38:36.0150 4276nmwcdc (3859c69a77793180548802dac9f34a38) C:\windows\system32\drivers\ccdcmbo.sys
2011/04/30 01:38:36.0337 4276npf (b9730495e0cf674680121e34bd95a73b) C:\windows\system32\drivers\npf.sys
2011/04/30 01:38:36.0477 4276Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
2011/04/30 01:38:36.0586 4276nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
2011/04/30 01:38:36.0774 4276Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys
2011/04/30 01:38:36.0898 4276Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
2011/04/30 01:38:37.0101 4276nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys
2011/04/30 01:38:37.0257 4276nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys
2011/04/30 01:38:37.0382 4276nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
2011/04/30 01:38:37.0600 4276ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
2011/04/30 01:38:37.0772 4276Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
2011/04/30 01:38:37.0866 4276partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
2011/04/30 01:38:37.0990 4276Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
2011/04/30 01:38:38.0146 4276pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\windows\system32\DRIVERS\pccsmcfd.sys
2011/04/30 01:38:38.0287 4276pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
2011/04/30 01:38:38.0365 4276pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
2011/04/30 01:38:38.0474 4276pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
2011/04/30 01:38:38.0630 4276pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
2011/04/30 01:38:38.0786 4276PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
2011/04/30 01:38:39.0020 4276PGEffect (1b5011dd8d57f53aed31ff0f7d635802) C:\windows\system32\DRIVERS\pgeffect.sys
2011/04/30 01:38:39.0270 4276PortlUSB (895dbe112ef6435dda75c8c9698e400b) C:\windows\system32\DRIVERS\H10USB.sys
2011/04/30 01:38:39.0457 4276PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
2011/04/30 01:38:39.0613 4276Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
2011/04/30 01:38:39.0769 4276Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
2011/04/30 01:38:39.0987 4276ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
2011/04/30 01:38:40.0143 4276ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
2011/04/30 01:38:40.0315 4276QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
2011/04/30 01:38:40.0424 4276RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
2011/04/30 01:38:40.0611 4276RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
2011/04/30 01:38:40.0767 4276Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
2011/04/30 01:38:40.0923 4276RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
2011/04/30 01:38:41.0079 4276RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
2011/04/30 01:38:41.0235 4276rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
2011/04/30 01:38:41.0485 4276rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
2011/04/30 01:38:41.0672 4276RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
2011/04/30 01:38:41.0844 4276RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
2011/04/30 01:38:42.0062 4276RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
2011/04/30 01:38:42.0265 4276RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
2011/04/30 01:38:42.0405 4276rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
2011/04/30 01:38:42.0624 4276RegGuard (7634b1f964f8d5c12d3a2d0b8c458568) C:\windows\system32\Drivers\regguard.sys
2011/04/30 01:38:42.0811 4276rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
2011/04/30 01:38:43.0029 4276RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\system32\Drivers\RtsUStor.sys
2011/04/30 01:38:43.0216 4276RTL8167 (26a9d6227d12b9d9da5a81bb9b55d810) C:\windows\system32\DRIVERS\Rt86win7.sys
2011/04/30 01:38:43.0310 4276RTL8187Se (5bd298bdf62e6a8a0fc69f73a82a52bb) C:\windows\system32\DRIVERS\RTL8187Se.sys
2011/04/30 01:38:43.0482 4276SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/04/30 01:38:43.0528 4276SASENUM (7ce61c25c159f50f9eaf6d77fc83fa35) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
2011/04/30 01:38:43.0622 4276SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/04/30 01:38:43.0747 4276SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\windows\system32\Drivers\SBKUPNT.SYS
2011/04/30 01:38:43.0856 4276sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
2011/04/30 01:38:43.0996 4276scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
2011/04/30 01:38:44.0137 4276secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
2011/04/30 01:38:44.0277 4276Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
2011/04/30 01:38:44.0355 4276Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
2011/04/30 01:38:44.0449 4276sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
2011/04/30 01:38:44.0605 4276sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
2011/04/30 01:38:44.0886 4276sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
2011/04/30 01:38:45.0088 4276sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys
2011/04/30 01:38:45.0385 4276sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
2011/04/30 01:38:45.0572 4276sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
2011/04/30 01:38:45.0962 4276SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
2011/04/30 01:38:46.0212 4276SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
2011/04/30 01:38:46.0446 4276Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
2011/04/30 01:38:46.0680 4276spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
2011/04/30 01:38:46.0929 4276srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\windows\system32\DRIVERS\srv.sys
2011/04/30 01:38:47.0179 4276srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\windows\system32\DRIVERS\srv2.sys
2011/04/30 01:38:47.0631 4276srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\windows\system32\DRIVERS\srvnet.sys
2011/04/30 01:38:48.0302 4276stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
2011/04/30 01:38:48.0895 4276swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
2011/04/30 01:38:52.0389 4276SynTP (8bd10dc8809dc69a1c5a795cb10add76) C:\windows\system32\DRIVERS\SynTP.sys
2011/04/30 01:38:53.0013 4276Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\windows\system32\drivers\tcpip.sys
2011/04/30 01:38:53.0278 4276TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\windows\system32\DRIVERS\tcpip.sys
2011/04/30 01:38:53.0497 4276tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
2011/04/30 01:38:53.0684 4276tdcmdpst (4084ea00d50c858d6f9038f86ae2e2d0) C:\windows\system32\DRIVERS\tdcmdpst.sys
2011/04/30 01:38:53.0856 4276TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
2011/04/30 01:38:54.0043 4276TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
2011/04/30 01:38:54.0261 4276tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
2011/04/30 01:38:54.0417 4276TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
2011/04/30 01:38:54.0620 4276tos_sps32 (969377943fe7284609babbab4e06b93c) C:\windows\system32\DRIVERS\tos_sps32.sys
2011/04/30 01:38:54.0760 4276tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
2011/04/30 01:38:54.0916 4276tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
2011/04/30 01:38:55.0041 4276TVALZ (fc24015b4052600c324c43e3a79c0664) C:\windows\system32\DRIVERS\TVALZ_O.SYS
2011/04/30 01:38:55.0150 4276TVALZFL (866462f5ae3f375ef83ef9dce436031c) C:\windows\system32\DRIVERS\TVALZFL.sys
2011/04/30 01:38:55.0275 4276uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
2011/04/30 01:38:55.0369 4276udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
2011/04/30 01:38:55.0728 4276uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
2011/04/30 01:38:55.0899 4276umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
2011/04/30 01:38:56.0040 4276UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
2011/04/30 01:38:56.0149 4276UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
2011/04/30 01:38:56.0305 4276upperdev (0ccadc7391021376edbb8aa649d04e68) C:\windows\system32\DRIVERS\usbser_lowerflt.sys
2011/04/30 01:38:56.0508 4276usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
2011/04/30 01:38:56.0648 4276usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys
2011/04/30 01:38:56.0820 4276usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
2011/04/30 01:38:56.0976 4276usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys
2011/04/30 01:38:57.0178 4276usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys
2011/04/30 01:38:57.0334 4276usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys
2011/04/30 01:38:57.0522 4276usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
2011/04/30 01:38:57.0631 4276usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\windows\system32\DRIVERS\usbscan.sys
2011/04/30 01:38:57.0724 4276usbser (88701eca76145e2c011c0eeff0f7b70e) C:\windows\system32\drivers\usbser.sys
2011/04/30 01:38:57.0818 4276UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/04/30 01:38:57.0896 4276USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS
2011/04/30 01:38:57.0990 4276usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys
2011/04/30 01:38:58.0068 4276usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\windows\system32\Drivers\usbvideo.sys
2011/04/30 01:38:58.0161 4276vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
2011/04/30 01:38:58.0239 4276vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
2011/04/30 01:38:58.0333 4276VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
2011/04/30 01:38:58.0411 4276vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
2011/04/30 01:38:58.0489 4276viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
2011/04/30 01:38:58.0536 4276ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
2011/04/30 01:38:58.0598 4276viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
2011/04/30 01:38:58.0692 4276volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
2011/04/30 01:38:58.0754 4276volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
2011/04/30 01:38:58.0832 4276volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
2011/04/30 01:38:58.0941 4276vsbus (1c8a783e90c34d205596f1ab4a97e261) C:\windows\system32\DRIVERS\vsb.sys
2011/04/30 01:38:59.0035 4276vserial (3377daa1cb8cac46a538c236f5f3d58f) C:\windows\system32\DRIVERS\vserial.sys
2011/04/30 01:38:59.0144 4276vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
2011/04/30 01:38:59.0347 4276vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
2011/04/30 01:38:59.0503 4276vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
2011/04/30 01:38:59.0643 4276WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
2011/04/30 01:38:59.0721 4276WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/04/30 01:38:59.0768 4276Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/04/30 01:38:59.0940 4276Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
2011/04/30 01:39:00.0033 4276Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
2011/04/30 01:39:00.0189 4276WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
2011/04/30 01:39:00.0236 4276WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
2011/04/30 01:39:00.0470 4276WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
2011/04/30 01:39:00.0657 4276WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
2011/04/30 01:39:00.0798 4276ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
2011/04/30 01:39:00.0876 4276WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
2011/04/30 01:39:00.0969 4276WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
2011/04/30 01:39:01.0094 4276================================================================================
2011/04/30 01:39:01.0094 4276Scan finished
2011/04/30 01:39:01.0094 4276================================================================================
2011/04/30 01:39:17.0817 5444================================================================================
2011/04/30 01:39:17.0817 5444Scan started
2011/04/30 01:39:17.0817 5444Mode: Manual;
2011/04/30 01:39:17.0817 5444================================================================================
2011/04/30 01:39:18.0878 54441394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
2011/04/30 01:39:18.0940 5444ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
2011/04/30 01:39:19.0050 5444AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
2011/04/30 01:39:19.0206 5444adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
2011/04/30 01:39:19.0377 5444adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
2011/04/30 01:39:19.0518 5444adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
2011/04/30 01:39:19.0627 5444AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys
2011/04/30 01:39:19.0689 5444AFS (be913403ed7219894b30e362fd8d4313) C:\windows\system32\drivers\AFS.sys
2011/04/30 01:39:19.0892 5444AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys
2011/04/30 01:39:20.0017 5444agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
2011/04/30 01:39:20.0079 5444aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
2011/04/30 01:39:20.0282 5444aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
2011/04/30 01:39:20.0391 5444amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
2011/04/30 01:39:20.0469 5444amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
2011/04/30 01:39:20.0578 5444AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
2011/04/30 01:39:20.0656 5444AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
2011/04/30 01:39:20.0844 5444amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
2011/04/30 01:39:21.0031 5444amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
2011/04/30 01:39:21.0124 5444amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
2011/04/30 01:39:21.0187 5444AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
2011/04/30 01:39:21.0374 5444arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
2011/04/30 01:39:21.0514 5444arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
2011/04/30 01:39:21.0748 5444AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
2011/04/30 01:39:21.0873 5444atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
2011/04/30 01:39:22.0232 5444atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys
2011/04/30 01:39:22.0357 5444AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys
2011/04/30 01:39:22.0497 5444AVGIDSDriver (b93c0f409482d6c0e581caca51ae9c02) C:\windows\system32\DRIVERS\AVGIDSDriver.Sys
2011/04/30 01:39:22.0638 5444AVGIDSEH (13256fc72fa5b3f6d6e8c5957e579b7c) C:\windows\system32\DRIVERS\AVGIDSEH.Sys
2011/04/30 01:39:22.0731 5444AVGIDSFilter (fa0685cc51de5cfd804e7deaa6488e0e) C:\windows\system32\DRIVERS\AVGIDSFilter.Sys
2011/04/30 01:39:22.0840 5444AVGIDSShim (f788b51100d0f40ea176798cce954a1a) C:\windows\system32\DRIVERS\AVGIDSShim.Sys
2011/04/30 01:39:22.0996 5444Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\windows\system32\DRIVERS\avgldx86.sys
2011/04/30 01:39:23.0090 5444Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\windows\system32\DRIVERS\avgmfx86.sys
2011/04/30 01:39:23.0215 5444Avgrkx86 (ffbe8adeb1fd8640540bf6e4a137b3ef) C:\windows\system32\DRIVERS\avgrkx86.sys
2011/04/30 01:39:23.0355 5444Avgtdix (69e6adf5cbbdeb5f2b727c93937a5823) C:\windows\system32\DRIVERS\avgtdix.sys
2011/04/30 01:39:23.0464 5444b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
2011/04/30 01:39:23.0605 5444b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
2011/04/30 01:39:23.0667 5444Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
2011/04/30 01:39:23.0808 5444blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
2011/04/30 01:39:23.0901 5444bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys
2011/04/30 01:39:23.0964 5444BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
2011/04/30 01:39:24.0057 5444BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
2011/04/30 01:39:24.0135 5444Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
2011/04/30 01:39:24.0229 5444BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
2011/04/30 01:39:24.0291 5444BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
2011/04/30 01:39:24.0385 5444BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
2011/04/30 01:39:24.0447 5444BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
2011/04/30 01:39:24.0556 5444cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
2011/04/30 01:39:24.0619 5444cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
2011/04/30 01:39:24.0728 5444circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
2011/04/30 01:39:24.0775 5444CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
2011/04/30 01:39:24.0884 5444CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
2011/04/30 01:39:24.0978 5444cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
2011/04/30 01:39:25.0040 5444CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
2011/04/30 01:39:25.0102 5444Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
2011/04/30 01:39:25.0165 5444CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
2011/04/30 01:39:25.0243 5444crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
2011/04/30 01:39:25.0321 5444DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys
2011/04/30 01:39:25.0399 5444discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
2011/04/30 01:39:25.0461 5444Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
2011/04/30 01:39:25.0555 5444Dot4 (b5e479eb83707dd698f66953e922042c) C:\windows\system32\DRIVERS\Dot4.sys
2011/04/30 01:39:25.0648 5444Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\windows\system32\DRIVERS\Dot4Prt.sys
2011/04/30 01:39:25.0758 5444dot4usb (cf491ff38d62143203c065260567e2f7) C:\windows\system32\DRIVERS\dot4usb.sys
2011/04/30 01:39:25.0867 5444drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
2011/04/30 01:39:25.0914 5444DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\windows\System32\drivers\dxgkrnl.sys
2011/04/30 01:39:26.0054 5444ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
2011/04/30 01:39:26.0179 5444elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
2011/04/30 01:39:26.0241 5444epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\windows\system32\epmntdrv.sys
2011/04/30 01:39:26.0319 5444ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
2011/04/30 01:39:26.0413 5444EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\windows\system32\EuGdiDrv.sys
2011/04/30 01:39:26.0506 5444exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
2011/04/30 01:39:26.0569 5444fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
2011/04/30 01:39:26.0631 5444fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
2011/04/30 01:39:26.0725 5444FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
2011/04/30 01:39:26.0803 5444Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
2011/04/30 01:39:26.0850 5444flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
2011/04/30 01:39:26.0928 5444FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
2011/04/30 01:39:26.0990 5444FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
2011/04/30 01:39:27.0068 5444Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
2011/04/30 01:39:27.0130 5444fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys
2011/04/30 01:39:27.0193 5444gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
2011/04/30 01:39:27.0271 5444GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
2011/04/30 01:39:27.0333 5444hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
2011/04/30 01:39:27.0411 5444HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
2011/04/30 01:39:27.0489 5444HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
2011/04/30 01:39:27.0583 5444HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
2011/04/30 01:39:27.0676 5444HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
2011/04/30 01:39:27.0786 5444HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
2011/04/30 01:39:27.0879 5444HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
2011/04/30 01:39:28.0004 5444HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
2011/04/30 01:39:28.0098 5444HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
2011/04/30 01:39:28.0238 5444hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
2011/04/30 01:39:28.0363 5444i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
2011/04/30 01:39:28.0472 5444iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
2011/04/30 01:39:28.0581 5444iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
2011/04/30 01:39:28.0737 5444IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys
2011/04/30 01:39:28.0846 5444intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
2011/04/30 01:39:28.0956 5444intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
2011/04/30 01:39:29.0018 5444IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
2011/04/30 01:39:29.0096 5444IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
2011/04/30 01:39:29.0205 5444IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
2011/04/30 01:39:29.0299 5444IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
2011/04/30 01:39:29.0392 5444isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
2011/04/30 01:39:29.0439 5444iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
2011/04/30 01:39:29.0533 5444kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
2011/04/30 01:39:29.0626 5444kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
2011/04/30 01:39:29.0720 5444KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
2011/04/30 01:39:29.0767 5444KSecPkg (26c046977e85b95036453d7b88ba1820) C:\windows\system32\Drivers\ksecpkg.sys
2011/04/30 01:39:29.0860 5444Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2011/04/30 01:39:29.0923 5444Lbd (336abe8721cbc3110f1c6426da633417) C:\windows\system32\DRIVERS\Lbd.sys
2011/04/30 01:39:29.0985 5444lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
2011/04/30 01:39:30.0079 5444LPCFilter (6e3d3816749e107883eec5734ce44493) C:\windows\system32\DRIVERS\LPCFilter.sys
2011/04/30 01:39:30.0188 5444LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
2011/04/30 01:39:30.0297 5444LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
2011/04/30 01:39:30.0391 5444LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
2011/04/30 01:39:30.0500 5444LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
2011/04/30 01:39:30.0594 5444luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
2011/04/30 01:39:30.0687 5444megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
2011/04/30 01:39:30.0796 5444MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
2011/04/30 01:39:30.0890 5444Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
2011/04/30 01:39:30.0968 5444monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
2011/04/30 01:39:31.0077 5444mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
2011/04/30 01:39:31.0171 5444mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
2011/04/30 01:39:31.0264 5444mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
2011/04/30 01:39:31.0358 5444mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
2011/04/30 01:39:31.0452 5444mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
2011/04/30 01:39:31.0561 5444MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
2011/04/30 01:39:31.0654 5444mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\windows\system32\DRIVERS\mrxsmb.sys
2011/04/30 01:39:31.0764 5444mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\windows\system32\DRIVERS\mrxsmb10.sys
2011/04/30 01:39:31.0857 5444mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\windows\system32\DRIVERS\mrxsmb20.sys
2011/04/30 01:39:31.0951 5444msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
2011/04/30 01:39:32.0029 5444msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
2011/04/30 01:39:32.0138 5444Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
2011/04/30 01:39:32.0232 5444mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
2011/04/30 01:39:32.0278 5444msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
2011/04/30 01:39:32.0372 5444MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
2011/04/30 01:39:32.0466 5444MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
2011/04/30 01:39:32.0575 5444MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
2011/04/30 01:39:32.0653 5444MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
2011/04/30 01:39:32.0762 5444mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
2011/04/30 01:39:32.0856 5444MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
2011/04/30 01:39:32.0949 5444MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
2011/04/30 01:39:33.0012 5444Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
2011/04/30 01:39:33.0090 5444MxlW2k (d37a535bbe77a16c232969c6882b524b) C:\windows\system32\drivers\MxlW2k.sys
2011/04/30 01:39:33.0199 5444NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
2011/04/30 01:39:33.0308 5444NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
2011/04/30 01:39:33.0402 5444NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
2011/04/30 01:39:33.0495 5444NdisTapi (e4a8aec125a2e43a9e32afeea7Please try running ComboFix again.Wow, you certainly know your stuff!! the gadgets on my desktop are now displaying properly again and Combofix actually worked this time!! Thanks heaps Dave! Although Combofix did ask me to remove AVG in order to run, which I did. Just about to reinstall AVG now. Below is Combofix's log...


-----------------------------------------------------------------------------------------------------------------------------------------------

ComboFix 11-05-02.03 - Chris 03/05/2011 10:49:04.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.2942.1963 [GMT 10:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}
c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome.manifest
c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome\content\_cfg.js
c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\chrome\content\overlay.xul
c:\users\Chris\AppData\Local\{655B544A-9BE9-47BF-B585-F295511A8A73}\install.rdf
c:\users\Chris\AppData\Local\Temp\explorer.dat
c:\users\Chris\AppData\Local\Temp\wininit.dat
c:\users\Chris\AppData\Roaming\Adobe\plugs
c:\users\Chris\AppData\Roaming\Adobe\shed
c:\users\Chris\AppData\Roaming\Bitrix Security
c:\users\Chris\AppData\Roaming\Bitrix Security\bnnhjx_shrd
c:\users\Chris\AppData\Roaming\Bitrix Security\ddljzh
c:\users\Chris\AppData\Roaming\Bitrix Security\fg.txt
c:\users\Chris\AppData\Roaming\Bitrix Security\jje.txt
c:\users\Chris\AppData\Roaming\Bitrix Security\ljgh.txt
c:\users\Chris\AppData\Roaming\Bitrix Security\mcx.txt
c:\users\Chris\AppData\Roaming\Bitrix Security\mxd1.txt
c:\users\Chris\AppData\Roaming\Bitrix Security\qnf.txt
c:\users\Chris\AppData\Roaming\Xyevw
c:\users\Chris\AppData\Roaming\Xyevw\ydird.tui
C:\Windows Restore
c:\windows restore\Uninstall Windows Restore.lnk
c:\windows restore\Windows Restore.lnk
c:\windows\desktop
.
.
((((((((((((((((((((((((( Files Created from 2011-04-03 to 2011-05-03 )))))))))))))))))))))))))))))))
.
.
2011-05-03 00:54 . 2011-05-03 00:55--------d-----w-c:\users\Chris\AppData\Local\temp
2011-05-03 00:54 . 2011-05-03 00:54--------d-----w-c:\users\Default\AppData\Local\temp
2011-05-03 00:44 . 2011-05-03 00:45--------d-----w-C:\32788R22FWJFW
2011-04-29 10:51 . 2011-04-29 10:52--------d-----w-c:\program files\Common Files\Nero
2011-04-29 10:51 . 2011-04-29 10:51--------d-----w-c:\program files\Nero
2011-04-29 09:26 . 2011-04-29 09:26--------d-----w-c:\program files\Nero Wave Editor
2011-04-29 09:26 . 2011-04-29 09:26--------d-----w-c:\windows\Nero Wave Editor
2011-04-27 07:23 . 2011-04-27 07:23--------d-----w-c:\users\Chris\AppData\Roaming\AVG10
2011-04-27 04:31 . 2011-05-03 00:40--------d-----w-c:\programdata\AVG10
2011-04-26 12:12 . 2011-05-03 00:39--------d-----w-c:\programdata\MFAData
2011-04-24 13:54 . 2011-04-24 14:43--------d-----w-c:\program files\Toolbar Uninstaller
2011-04-23 16:49 . 2011-04-23 16:49--------d-----w-c:\program files\uTorrent
2011-04-22 23:26 . 2011-04-22 23:26--------d-----w-c:\program files\Bulk Rename Utility
2011-04-22 15:52 . 2011-04-23 16:48--------d-----w-c:\program files\BitTorrent
2011-04-22 15:51 . 2011-04-23 16:48--------d-----w-c:\users\Chris\AppData\Roaming\BitTorrent
2011-04-17 12:10 . 2011-04-17 12:10--------d-----w-c:\program files\TrendMicro
2011-04-17 11:59 . 2011-04-17 11:59--------d-----w-c:\program files\Common Files\Java
2011-04-17 11:59 . 2011-02-02 11:40472808----a-w-c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-17 11:59 . 2011-02-02 11:40472808----a-w-c:\windows\system32\deployJava1.dll
2011-04-13 04:10 . 2011-04-07 07:5916432----a-w-c:\windows\system32\lsdelete.exe
2011-04-13 03:18 . 2011-04-01 07:2264512----a-w-c:\windows\system32\drivers\Lbd.sys
2011-04-13 03:17 . 2011-04-13 03:1798392----a-w-c:\windows\system32\drivers\SBREDrv.sys
2011-04-13 03:17 . 2011-04-13 03:17--------d-----w-c:\users\Chris\AppData\Local\Sunbelt Software
2011-04-13 03:15 . 2011-04-13 03:15--------dc-h--w-c:\programdata\{6A395471-4AA3-4072-AE1B-9B69A97AD164}
2011-04-13 03:12 . 2011-04-13 03:16--------d-----w-c:\programdata\Lavasoft
2011-04-13 03:12 . 2011-04-13 03:12--------d-----w-c:\program files\Lavasoft
2011-04-13 03:08 . 2011-04-17 08:31--------d-----w-c:\programdata\Spybot - Search & Destroy
2011-04-13 03:08 . 2011-04-13 03:08--------d-----w-c:\program files\Spybot - Search & Destroy
2011-04-13 01:25 . 2011-04-13 01:32--------d-----w-c:\users\Chris\AppData\Roaming\GetRightToGo
2011-04-12 06:55 . 2011-04-12 06:55--------d-----w-C:\VundoFix Backups
2011-04-12 02:16 . 2008-12-08 02:5357344----a-w-c:\windows\system32\ff_vfw.dll
2011-04-12 02:16 . 2008-06-08 12:5860273----a-w-c:\windows\system32\pthreadGC2.dll
2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\ffdshow
2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\Haali
2011-04-12 02:16 . 2011-04-12 02:16--------d-----w-c:\program files\AviSynth 2.5
2011-04-12 02:15 . 2010-08-26 13:45147456----a-w-c:\windows\system32\stQTSource.ax
2011-04-12 02:15 . 2010-07-15 01:30290816----a-w-c:\windows\system32\stFLVSource.ax
2011-04-12 02:15 . 2011-04-12 02:16--------d-----w-c:\program files\Sothink Video Converter
2011-04-12 02:15 . 2009-08-16 23:541184984----a-w-c:\windows\system32\wvc1dmod.dll
2011-04-12 02:15 . 2009-08-16 23:54438272----a-w-c:\windows\system32\Mpeg2DecFilter.ax
2011-04-12 02:15 . 2009-08-16 23:54217088----a-w-c:\windows\system32\CoreFLACDecoder.ax
2011-04-12 02:15 . 2009-03-17 07:3870656----a-w-c:\windows\system32\RLAPEDec.ax
2011-04-12 02:12 . 2011-04-12 02:15--------d-----w-c:\program files\Common Files\SourceTec
2011-04-12 02:12 . 2011-04-12 02:12--------d-----w-c:\program files\SourceTec
2011-04-07 10:18 . 2011-04-12 05:32--------d-----w-c:\windows\PIF
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-12 02:15 . 2010-08-15 01:580----a-w-c:\users\Chris\AppData\Local\Xxepobesitefe.bin
2011-03-11 10:50 . 2010-06-21 10:4636734----a-w-c:\windows\system32\OggDSuninst.exe
2011-03-11 10:22 . 2011-03-11 10:22119350----a-w-c:\windows\File Renamer - Basic Uninstaller.exe
2011-03-01 09:31 . 2011-03-01 09:3177004----a-w-c:\windows\system32\drivers\AFS.SYS
2011-02-12 15:09 . 2011-02-12 15:09388096----a-r-c:\users\Chris\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-01-26 12:11 . 2011-03-08 14:17444283----a-w-c:\program files\Common Files\WinPcapNmap.exe
.
.
((((((((((((((((((((((((((((((((((((( REG Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TWebCamera"="%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun" [X]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-10 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 425984]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-07-14 8704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{F552DDE6-2090-4bf4-B924-6141E87789A5}"= "c:\program files\Greatis\RegRunSuite\RRShell.dll" [2004-11-01 368711]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GabPath
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPlusAgent]
2005-02-18 19:49225280----a-w-c:\program files\iriver\iriver plus\iAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 00:321479680----a-w-c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Regrun2]
2006-12-19 02:43350208----a-w-c:\progra~1\Greatis\REGRUN~1\WatchDog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2009-07-29 04:127625248------w-c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 04:49249064----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe
.
R0 AFS;AFS;

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 135664]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-05-11 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-05-11 8456]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 135664]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys

R3 PortlUSB;PortlUSB;c:\windows\system32\DRIVERS\H10USB.sys [2004-06-24 7552]
R3 RegGuard;RegGuard;c:\windows\system32\Drivers\regguard.sys [2010-08-15 25773]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-31 171520]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys

R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-01 64512]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-04-26 2146496]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704]
S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\RSelect\RSelSvc.exe [2009-07-07 62832]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and GENERAL Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-01 15232]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-23 24064]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-23 167936]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPServiceREG_MULTI_SZ HPSLPSVC
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-03 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-11-13 10:55]
.
2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 10:00]
.
2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-22 10:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\ceofca98.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=LMW2&o=16054&locale=en_US&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: PC Sync 2 Synchronisation Extension: [emailprotected] - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: HP Smart Web Printing: [emailprotected] - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: TVU Web Player: [emailprotected] - %profile%\extensions\[emailprotected]
FF - Ext: Sothink Web Video Downloader for Firefox: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08} - %profile%\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
FF - Ext: Conduit Engine : [emailprotected] - %profile%\extensions\[emailprotected]
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
FF - Ext: HP Smart Web Printing: [emailprotected] - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
MSConfigStartUp-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe
MSConfigStartUp-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
AddRemove-TOSHIBA Software Modem - c:\windows\agrsmdel
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3225168310-450358799-2518029026-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0619892F-D16A-973B-E705-9F49F072D162}*]
"lahilkapdgongndefaipeipf"=hex:65,62,64,62,62,6d,62,66,70,63,67,6a,62,6e,67,6b,
65,63,6f,6a,67,6f,65,6d,63,62,68,67,6d,6f,6a,68,6d,6e,67,6f,64,6a,6b,62,61,\
"haihofnpmgmhjfmc"=hex:63,62,6e,66,68,69,6c,6e,68,67,68,6e,64,6d,6b,61,61,6c,
6c,6f,61,6e,6c,66,6b,6b,6b,64,6d,62,70,66,6b,6b,6c,6f,6f,66,00,00
"haihofnpbfmnlepb"=hex:6f,61,66,69,65,67,64,68,62,66,6c,6e,63,62,6c,6c,6b,6d,
67,70,6d,65,64,6c,68,62,6c,67,61,61,00,66
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000009
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
COMPLETION time: 2011-05-03 10:56:22
ComboFix-quarantined-files.txt 2011-05-03 00:56
.
Pre-Run: 201,441,955,840 bytes free
POST-Run: 203,345,326,080 bytes free
.
- - End Of File - - 6E37FEA35733863D493B0D741ABB367EThat looks good. Don't despair. We're almost at the end.

P2P - I see you have P2P software installed on your machine (\uTorrent and BitTorrent). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
*************************************************
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    RegNull::
    [HKEY_USERS\S-1-5-21-3225168310-450358799-2518029026-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0619892F-D16A-973B-E705-9F49F072D162}*]
    "lahilkapdgongndefaipeipf"=hex:65,62,64,62,62,6d,62,66,70,63,67,6a,62,6e,67,6b,
    65,63,6f,6a,67,6f,65,6d,63,62,68,67,6d,6f,6a,68,6d,6e,67,6f,64,6a,6b,62,61,\
    "haihofnpmgmhjfmc"=hex:63,62,6e,66,68,69,6c,6e,68,67,68,6e,64,6d,6b,61,61,6c,
    6c,6f,61,6e,6c,66,6b,6b,6b,64,6d,62,70,66,6b,6b,6c,6f,6f,66,00,00
    "haihofnpbfmnlepb"=hex:6f,61,66,69,65,67,64,68,62,66,6c,6e,63,62,6c,6c,6b,6d,
    67,70,6d,65,64,6c,68,62,6c,67,61,61,00,66

    MBR::

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
*****************************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
253.

Solve : Major Virus Problem?

Answer»

Downloaded comodo.

1) I did not see any options to uncheck:
-"Install Comodo SafeSurf..",
-Make Comodo my default search provider"
-"Make Comodo Search my homepage" and
-uncheck any HopSurf and/or Ask.com options if you choose this one

-Is that normal?


2) I DID see these options:
-Comodo GeekBuddy (I choose to uncheck)
-Firewall only, Firewall Optimum, or Firewall Max (I choose Optimum)
-Comodo SecureDNS SERVER (I selected it)

-Did I make the right calls, if not, how to fix?
Thanks!I installed spyware blaster but did not do spybot search and destroy. After reading this site, I am novice with PC, and saw if I need to do HIJACK this it would interfere, and I just didn't WANT to make things more complicated. OK?


Also, if in the near future I get a new PC, I TAKE it no MATTER what I should]
1) Get CCleaner
2) Get SAS
3) Get MBAM
4) Get Comodo and disable any Windows or Apple firewall
5) Get spyware blaster

First thing when I get the new PC, right?

Thanks again!Quote

Also, if in the near future I get a new PC, I take it no matter what I should]
1) Get CCleaner
2) Get SAS
3) Get MBAM
4) Get Comodo and disable any Windows or Apple firewall
5) Get spyware blaster

First thing when I get the new PC, right?
You don't need CCleaner. You can do the same thing by doing a disk cleanup regularly.
SAS and MBAM are not active programs unless you buy them. You can have them on your computer and make it a habit to update them and run them on a regular basis.
A third-party firewall is a good idea and spywareblaster is also a good idea.
I will lock this thread. If you need it re-opened, please send me a pm.
254.

Solve : Re: My computer is sending out emails! Virus??

Answer» NEED some help PLEASE???

my hotmail account has STARTED to send out SPAM mail??
255.

Solve : Multiple Copies of explorer.exe?

Answer»

That's good. If there are no other issues, let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run UNINTERRUPTED until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**********************************************************
Use the Secunia Software INSPECTOR to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all CRITICAL updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Dave, I ran combofix /uninstall, but it did not remove the folders etc that I think it created. It actually added one c:\combofix. Here's a screenshot of the root of c:\: http://clip2net.com/clip/m80407/1306275960-clip-70kb.jpg. I don't think c:\boot(which has language folders and memtest.exe), c:\combofix,
c:\perflogs(empty except for admin sub folder), c:\programdata, c:\recovery(empty), and c:\virtualroot(empty) were there prior to this malware removal process. What should I do about these? I think I could delete the empty ones, but will wait until I hear from you. I noticed a new exe called nircmd.exe that's appeared that comodo firewall sandboxed. There is one folder missing that was on c:\ called c:\ooobox or something like that, that had combofix files in it.

skilz853Quote
I ran combofix /uninstall, but it did not remove the folders etc that I think it created. It actually added one c:\combofix.
I cleaned a computer this weekend in my home and the same thing happened when I tried to uninstall ComboFix. I ended up deleting it. I'm going to investigate the validity of that method of uninstalling ComboFix. This should remove it.

Download OTL to your desktop.
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are PROMPTED to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.Thanks Dave, I think that took care of it. I did have manually delete some folders. I found out that c:\boot is a windows folder for the inbuilt memtest. I went in properties and hid it.
I think all is well now.

Thanks again,
skilz853You're welcome. I will lock this thread. If you need it re-opened, please send me a pm or start a new thread.
256.

Solve : PC Performance and Stability Report?

Answer»

Do you have any idea where this sorta thing would have come from? This isn't the first time I've gotten it on my computer.Quote

I just noticed that I now have a shortcut to that Windows Vista Recovery thing on my desktop. Can i just delete it? or not just yet?
Your choice. If you don't want it, delete it. It's not something your going to use very often, if ever.
Quote
Do you have any idea where this sorta thing would have come from? This isn't the first time I've gotten it on my computer.
Probably from out-of-date programs. See here.

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* UNZIP SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.Results of screen317's Security Check version 0.99.11
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
ESET Online Scanner v3
Microsoft Security Essentials
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) SE Runtime Environment 6
Adobe Flash Player
Adobe Reader 7.0.8
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
``````````End of Log````````````
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.
******************************************************

Once the above is done we can do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a SPACE between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the CLEANING process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
****************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thanks so much for your help!!!!!!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
257.

Solve : "System Tool 2011" virus + Taskbar keeps swithching themes?

Answer»

Thanks for the fix Okay, the complete scan finished, however, there is no option to report incurable. Should I just save the report list and exit the program afterwards? Please try running the ESET scan again.Dr web Report list


Process in memory: C:\WINDOWS\system32\svchost.exe:744;;BackDoor.Tdss.565;Eradicated.;
f_0005c3;C:\Documents and Settings\My Computer\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache(2);Probably SCRIPT.Virus;Incurable.Moved.;
sma_common[1].js;C:\Documents and Settings\My Computer\Local Settings\Temporary Internet Files\Content.IE5\SLEFKDEB;Probably SCRIPT.Virus;Incurable.Moved.;
change.log.1;C:\System Volume Information\_restore{BABF27AF-98B1-46AD-8AEE-3507E0DEE2FA}\RP173;Modification of Trojan.DownLoad1.17823;Incurable.Moved.;
sma_common.js;I:\common\inc;Probably SCRIPT.Virus;;
sprt_common.js;I:\sprtcommon\inc;Probably SCRIPT.Virus;;
That looks good. If there are no other issues, let's cleanup. You may keep SAS and MBAM, if you wish. Update them and run them regularly.

Download OTL to your desktop.
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
**********************************************
To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
This will give you a new, clean Restore Point.
********************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make SURE you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
******************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
What are the programs that OTL is supposed to remove?
If they are not removed will it make my computer slow to start up?Quote
What are the programs that OTL is supposed to remove?
If they are not removed will it make my computer slow to start up?
They will not make your slow to start unless you have them running at startup. Here's a handy program to check to see what's running at startup.
!Killbox
*.run
_backupD
_OTL
_OTListIt
_OTM
_OTMoveIt
_OTS
_OTScanIt
404fix.exe
Avenger
avenger.exe
avenger.txt
avenger.zip
AWF.txt
BFU
bfu.zip
catchme
catchme.exe
cleanup.txt
ComboFix
ComboFix*.txt
combofix.exe
combo-fix.exe
Combo-Fix.sys
dds.com
dds.pif
dds.scr
Deckard
delete.bat
deljob
deljob.exe
dss.exe
dumphive.exe
erdnt\subs
Extras.txt
fdsv.exe
FindAWF.exe
fixwareout
fixwareout.exe
fsbl*.log
fsbl.exe
gmer
gmer.dll
gmer.exe
gmer.ini
gmer.log
gmer.sys
gmer_uninstall.cmd
grep.exe
haxfix.exe
haxfix.txt
iedfix.exe
killbox.exe
logit.txt
Lop SD
lopR.txt
LopSD.exe
moveex.exe
nircmd.exe
NoLop.exe
NoLop.txt
NoLopOLD.txt
OTL.exe
OTL.txt
OTListIt.txt
OTListIt2.exe
OTM.exe
OTMoveIt.exe
OTMoveIt2.exe
OTMoveIt3.exe
OTS.exe
OTS.txt
OTScanIt
OTScanIt.exe
OTScanIt2
OTScanIt2.exe
OTViewIt.exe
OTViewIt.txt
QooBox
rapport.txt
Rooter$
Rooter.exe
Rooter.txt
RSIT
RSIT.exe
Runscanner
Runscanner.exe
Runscanner.net
Runscanner.zip
Rustbfix
rustbfix.exe
SDFix
sdfix.exe
sed.exe
Silent Runners.vbs
SmitfraudFix
SmitfraudFix.exe
swreg.exe
Swsc.exe
Swxcacls.exe
SysInsite
tmp.reg
vacfix.exe
vcclsid.exe
VFind.exe
VundoFix Backups
VundoFix.exe
vundofix.txt
vundofix.vft
win32delfkil.exe
windelf.txt
WinPfind
winpfind.exe
WinPFind35u
WinPFind35u.exe
WinPFind3u
WinPFind3u.exe
WS2Fix.exe
zip.exe
StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the DISABLE box is checked.
Click CONTINUE.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
258.

Solve : Laptop infected...?

Answer»

It would appear that your computer is clean. Any other issues?Nicest words I have heard all week. Thank you so much.
Any recommendations in terms of how often to run the Avira AntiVirus, Malware and Spybot?Quote

Any recommendations in terms of how often to run the Avira AntiVirus, Malware and Spybot?
Your AV is active all the time. You shouldn't need to run any scans with it. You can update and run SAS and MBAM weekly to keep the bugs out. The same for Spybot. If you have SpywareBlaster, keep it up-to- date also.
Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a SPACE between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*******************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your WORK before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

GO to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing! Good luck from New Brunswick and have a good playoff run.
259.

Solve : Something blocking me from AV websites, have done required steps?

Answer»

Okay, i EASILY went to the Start>Run and did that.

I could NOT go to the ESET page on my desktop as whatever I have is obviously blocking me from that page. So I went to the ESET page from my laptop and put the .exe file on my SD card to then put it onto my desktop as I have done with other programs that I haven't been able to access from my desktop.

I cannot get ESET to run because it goes to update first and it says it can not get update is proxy configured? I do not know what to do now or how to get the ESET update from my laptop onto my desktop.


Ok. Let's try this one:

Run the BitDefender Online scanner

Agree to the license and then select SCAN. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

Once Bitdefender completes the scan:
Click-on the Detected Problems tab.
Then select Click here to export the scan report.

When the window comes up to save the report, change the Save as type: box to:
Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save.

This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later).
This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

Post the bdscan.txt file as an Attachment.
I cannot get to that page from my desktop. I went to it on my laptop but there was no file, that I could find, to download to put on my SD card to then transfer onto my desktop. Whatever I have is blocking me from these sites.
Please try this:

Please download TDSSKiller from here and save it to your Desktop.

  • Doubleclick TDSSKiller.exe to run the tool
  • Click the Start Scan button (If prompted with a "hidden service warning" do go ahead and delete it.)

  • After the scan has finished, click the Close button
  • Click the Report button and copy/paste the contents of it into your next reply
  • Note:It will also create a log in the C:\ directory.
260.

Solve : HJT made an evaluation?

Answer»

My PC can not access the internet. DIRECTX 9 was uninstalled "per se" and can not reinstall it. I can not access CD drive. Would LIKE your recommendations

[recovering disk space - old attachment deleted by admin]Quote from: antalves on March 02, 2011, 04:38:29 AM

DirectX 9 was uninstalled "per se"

DirectX 9 was uninstalled "by itself" ?? How did this happen?

Can you install it from here
http://directx.en.softonic.com/

I do not know how it happened. Just happened. I can not reinstall it, the message is that it is not compatible with XP!
Have you recently done a System restore?

Check the 'Important Notes' here
http://www.softwarepatch.com/windows/directx.html

Quote
DirectX is a crucial system component. It cannot be uninstalled without reinstalling your operating system (!) or performing a system restore/system recovery.

You can also use the guide.Every TIME I turn on my PC it's getting worse, slower. He must have been INFECTED by a dammed virus. I believe the solution is a complete reinstallation Do you still require help?No thanks. After hours of investigation, i had to reinstall everything. Too bad
261.

Solve : Is my PC infected??

Answer»

OK SuperDave that has been done. What do you suggest next?
Anyway, I'm no longer receiving the message that I mentioned at the beginning of this post. I've had no further PROBLEMS connecting to the internet. The only thing that's still odd is not being able to click once/twice to access files/programs etc. through the shortcuts on my desktop. Sometimes clicking perhaps 8/9 times will work. Also right clicking and then "OPEN" always works. I've tried 2 different PS/2 mice and one USB and still same problem. One other thing that I wanted to point out is a few of the logs( don't remember which ones now) that we're related to the apps. that you had me download and I saved to my desktop, were completely blank( looked like a blank page.) The only reason that I mention this is; while I was surfing the web looking for answers about not being able to open the shortcuts I came across a site somewhere (don't know if I could ever find it again)that said something to the effect that if you are having problems opening shortcuts and some of the icons on your desktop are blank it's probably a worm. Now perhaps this is total nonsense and I sure trust your knowledge and expertise on malware much,much, more that this, but just thought that I'd mention it. Sure appreciate all your help. naturegurlPlease try deleting one of those shortcuts and create a new one and see if it works.I think my PC might have spyware on it. How do I tell for sure? And how do I remove it?Quote from: SuperDave on February 24, 2011, 07:53:09 PM

Please try deleting one of those shortcuts and create a new one and see if it works.


Well SuperDave I had tried that several times the other day with no change. Thought that I'd give it another shot tonight and now it appears that the problem now includes more that the desktop. This is new. Most folders /files within Computer/Documents will not open properly now without a lot of coaxing. WOW !!Ok. Let's try this:

Please download SREng
  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that has an Error status click [Repair]
  • Refer to this image for an example:

  • In your case, it would be .EXE
  • Close SREng now.
.Quote from: SuperDave on February 25, 2011, 12:48:42 PM
Ok. Let's try this:

Please download SREng
  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that has an Error status click [Repair]
  • Refer to this image for an example:

  • In your case, it would be .EXE
  • Close SREng now.
.

Hi SuperDave I ran the app. it found one error. "VBS handle the VBS open method (whatever that is )" and I deleted it. Since my last post I have done the following; created a few new desktop icons, ran the app. that you just suggested and I'm now trying another USB mouse. Now perhaps it's just wishful thinking but some files/programs(not necessarily the new ones that I created) seem to now open a little easier.

I'm going to check with a colleague about this problem. In the meantime, please try this:

Do you have your OS CD/DVD?

If so,

1/ Click the Start button.

2/ From the Start Menu, Click All programs FOLLOWED by Accessories.

3/ In the Accessories menu, Right Click on the Command Prompt option.

4/ From the drop down menu that appears, Click on the Run as administrator option.

5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

7/ A message will appear stating that the system scan will begin.

8/ Be patient because the scan may take some time.

9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

11/ After the scan has COMPLETED, Close the command prompt window.
Quote from: SuperDave on February 25, 2011, 05:08:07 PM
I'm going to check with a colleague about this problem. In the meantime, please try this:

Do you have your OS CD/DVD?

If so,

1/ Click the Start button.

2/ From the Start Menu, Click All programs followed by Accessories.

3/ In the Accessories menu, Right Click on the Command Prompt option.

4/ From the drop down menu that appears, Click on the Run as administrator option.

5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

7/ A message will appear stating that the system scan will begin.

8/ Be patient because the scan may take some time.

9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

11/ After the scan has completed, Close the command prompt window.


Unfortunately SuperDave all that came with my system is two recovery disks. natregurlHi SuperDave . Well I found the problem (that I was having with opening programs/shortcuts etc.) was caused by (as embarrassing as it is) the mouse double-click speed. Besides everything ELSE I had looked at this several times over the past day or so and thought that it looked OK. All I did was slow it down ever so slightly and the problem appears cured. I certainly have no idea if it was changed,how it was changed or why it required slowing down?? Anyway, very sorry to have put you through this particular problem. So now that this has been overcome, as well as no more corrupted search provider messages, no hanging downloads, no further internet connection problems, is there any other things that you would have me check. My PC now seems to be running great now and I'm wondering if you think my PC is clean? Thanks so much.Quote
So now that this has been overcome, as well as no more corrupted search provider messages, no hanging downloads, no further internet connection problems, is there any other things that you would have me check. My PC now seems to be running great now and I'm wondering if you think my PC is clean? Thanks so much.

That is good news. I was thinking that it was not infection related. Judging by all the scans we ran, I would say that your computer is clean. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**********************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Well SuperDave, I followed your instructions re; last post, and I sincerely appreciate all of your help. I feel very fortunate that you were there to help me and I'm also very confident that all the other CH members that you have helped feel the way that I do.
Thank you very much and God Bless. naturegurlYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
262.

Solve : no windows update, browser redirects, no task bar or icons at startup?

Answer»

Dave, when I ran the Secunia Software Inspector it said that I needed to update my Internet Explorer and I should go to windows update to get a bunch of missing patches. But when I go to windows update it TELLS me there are no updates for my computer. What should I do? Here is the info from the scan:

This installation of Microsoft Internet Explorer 8.x is insecure and potentially exposes your system to security threats!

Your system does not have all security related patches from Microsoft installed. Please see list below for details about the missing patches.

Update Instructions:
Download via Microsoft Windows Update.

Missing KB Articles:
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB980195
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB982381
KB980195
KB980195
KB980195
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB980182
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB978207
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB976325
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB974455
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB972260
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB969897
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2416400
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2360131
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461
KB2183461

I have ran the software inspector several times from both IE and firefox. I was able to update all the software except fro the IE patches listed above, and also it keeps saying I need to update my firefox from version 3.5.10 to the latest 3.5.16. I have downloaded the upgrade several times, and when I check from in firefox it says I am RUNNING version 3.5.16. I also checked for updates from within firefox and it said no updates were available. Quote

when I go to windows update it tells me there are no updates for my computer. What should I do?
I would tend to agree with MicroSoft.

Quote
This installation of Microsoft Internet Explorer 8.x is insecure and potentially exposes your system to security threats!
I think IE9 is out now. I'll have to upgrade mine soon.

Quote
I have downloaded the upgrade several times, and when I check from in firefox it says I am running version 3.5.16. I also checked for updates from within firefox and it said no updates were available.
I wouldn't worry about Firefox too MUCH, if I were you. One day you'll open it and it will tell you to upgrade. My version is also 3.5.16 and I upgrade not too long ago.Ok. Followed all your instructions and suggestions. So far machine is running well. Thanks so much for all your help!!
263.

Solve : Annoying Google Redirect?

Answer»

Are you still getting the google re-directs?

UPDATE Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
*************************************************
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any SECURITY warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
No Google re-directs so far.
I installed the newest version of Java.
The ESET scanner did not find any threatsGood. Let's do some cleanup.
You can try this to fix the slow startup. How much time are talking about?

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.

****************************************************
To uninstall ComboFix

  • Click the Start button. Click RUN. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!I'm having trouble uninstalling ComboFix. I need to deactivate my antivirus, but my desktop(along with the taskbar and start button) is not showing up. It would usually show up in about three minutes, but recently its just stopped appearing.Quote
I'm having trouble uninstalling ComboFix. I need to deactivate my antivirus
You don't have to disable your AV to remove ComboFix.

Quote
but my desktop(along with the taskbar and start button) is not showing up. It would usually show up in about three minutes, but recently its just stopped appearing.
Did this just start to happen recently or has it been doing it all along?Ok I ran all the programs and uninstalled ComboFix.

Quote
Did this just start to happen recently or has it been doing it all along?
It has been happening all along.Quote
It has been happening all along.
I don't believe this is a malware issue. You should create a new thread in the proper software forum concerning this.
Can you give me a SCREENPRINT of this?
How to post screenshots or images
Thanks for the help so far SuperDave.

Notice that the Start MENU, desktop items, and taskbar are all gone.
Task Manager is the only way for me to open applications/programs



Uploaded with ImageShack.usI see. Let's try this.

  • Please download Unhide by Grinler from here and save it to your desktop.
  • Double click unhide.exe to run the tool.
  • It will take some time to go through all your files, so please be patient.
  • If this tool doesn´t fix the problem, please let me know.
nothing happens when I click on Run.Quote
nothing happens when I click on Run.
You're not supposed to click on Run. You're supposed to click on this: Double click unhide.exe to run the tool.
ok its been done, but there was no effect. I have been changing settings in msconfig, and the desktop will occasionally show up. However, it only shows up on the diagnostic setting. Maybe the problem is with the settings there.
264.

Solve : Trojan.Vundo and more?

Answer»

Ok. Please try uninstalling AVG using this REMOVAL tool.
AVG Antivirus Remover utilityI accidently closed ComboFix b/4 the log was finished so I re-ran it. Here is the log:

omboFix 11-05-25.03 - Rebecca Woods 05/26/2011 10:44:55.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1361 [GMT -5:00]
Running from: c:\documents and settings\Rebecca Woods\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\Rebecca Woods\g2mdlhlpx.exe
c:\documents and settings\Rebecca Woods\GoToAssistDownloadHelper.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\rnaph.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-04-26 to 2011-05-26 )))))))))))))))))))))))))))))))
.
.
2011-05-26 14:18 . 2011-05-09 18:466962000----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\mpengine.dll
2011-05-25 22:39 . 2011-05-25 22:39--------d-----w-C:\Pro
2011-05-21 19:49 . 2011-05-21 19:49--------d-----w-C:\_OTL
2011-05-21 12:06 . 2011-05-21 12:06388096----a-r-c:\documents and settings\Rebecca Woods\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-19 01:55 . 2011-05-19 01:55--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\Malwarebytes
2011-05-19 01:54 . 2010-12-20 23:0938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-19 01:54 . 2011-05-19 01:54--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-19 01:54 . 2010-12-20 23:0820952----a-w-c:\windows\system32\drivers\mbam.sys
2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\SUPERAntiSpyware.com
2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-05-18 22:12 . 2011-05-18 22:123063136----a-w-C:\ccsetup306.exe
2011-05-18 18:27 . 2011-05-18 19:16--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor
2011-05-18 18:27 . 2011-05-18 18:27--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\OnlineArmor
2011-05-18 18:26 . 2011-04-06 18:0239048----a-w-c:\windows\system32\drivers\oahlp32.sys
2011-05-18 18:26 . 2011-04-06 18:0129464----a-w-c:\windows\system32\drivers\OAnet.sys
2011-05-18 18:26 . 2011-04-06 18:0125192----a-w-c:\windows\system32\drivers\OAmon.sys
2011-05-18 18:26 . 2011-04-06 18:01205864----a-w-c:\windows\system32\drivers\OADriver.sys
2011-05-18 14:16 . 2011-05-18 18:11--------d-----w-c:\documents and settings\All Users\Application Data\iolo
2011-05-17 21:01 . 2011-05-17 21:01--------d--h--w-c:\windows\system32\GroupPolicy
2011-05-17 20:31 . 2010-10-19 20:51222080------w-c:\windows\system32\MpSigStub.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 10:07 . 2010-07-07 13:42472808----a-w-c:\windows\system32\deployJava1.dll
2011-04-14 07:40 . 2008-06-26 08:3073728----a-w-c:\windows\system32\javacpl.cpl
2011-03-07 05:33 . 2004-08-10 18:02692736---ha-w-c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-10 17:51420864---ha-w-c:\windows\system32\vbscript.dll
2011-03-03 14:47 . 2010-01-06 16:51398760---ha-r-c:\windows\system32\cpnprt2.cid
2011-03-03 13:21 . 2004-08-10 17:511857920---ha-w-c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-25 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 2183168]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 405504]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"eBook Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\eBook Library Launcher.exe" [2009-10-20 902504]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-17 98304]
"@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-04-06 2477032]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartUp This"="c:\program files\Laplink\PCmover\LaunchSt.exe" [2007-11-01 247088]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-21 13:4510536----a-w-c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:1364592----a-w-c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\real\\realplayer\\realplay.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"67:UDP"= 67:UDP:DHCP Discovery Service
.
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/18/2011 1:26 PM 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [5/18/2011 1:26 PM 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/18/2011 1:26 PM 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/18/2011 1:26 PM 29464]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 1:27 PM 1074568]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/29/2010 10:30 AM 10448]
R2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [5/18/2011 1:26 PM 4326472]
S1 MpKslf74c7e6c;MpKslf74c7e6c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys [?]
S2 gupdate1ca25d2787f1ffc;Google Update Service (gupdate1ca25d2787f1ffc);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104]
S2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [5/18/2011 1:26 PM 381512]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/12/2009 4:20 PM 401920]
S3 cpuz134;cpuz134;\??\c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/2/2010 3:46 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [8/3/2005 3:59 PM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [8/3/2005 3:59 PM 8960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-26 22:20]
.
2011-05-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21]
.
2011-05-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21]
.
2011-05-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]
.
2011-05-26 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]
.
2011-05-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-109568239-1760306711-3351161423-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
2011-05-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-109568239-1760306711-3351161423-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080626
Trusted Zone: intuit.com\ttlc
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-hpqSRMon - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-MS Word to Excel Import, Export & Convert Software_is1 - c:\program files\MS Word to Excel Import
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-26 11:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(592)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\System32\BCMLogon.dll
c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\MFC80.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
.
- - - - - - - > 'explorer.exe'(1936)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-05-26 11:09:22
ComboFix-quarantined-files.txt 2011-05-26 16:09
.
Pre-Run: 107,397,668,864 bytes free
Post-Run: 107,265,122,304 bytes free
.
- - End Of File - - 61AA2560A97042CCF7147EE508A838D8
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    DDS::
    Trusted Zone: intuit.com\ttlc

    SecCenter::
    17DDD097-36FF-435F-9E1B-52D74245D6BF

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
******************************************************
Download Security CHECK by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.ComboFix 11-05-26.05 - Rebecca Woods 05/27/2011 12:17:04.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1438 [GMT -5:00]
Running from: c:\documents and settings\Rebecca Woods\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((( Files Created from 2011-04-27 to 2011-05-27 )))))))))))))))))))))))))))))))
.
.
2011-05-27 17:05 . 2011-05-09 18:466962000----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-27 17:04 . 2011-05-09 18:466962000----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F37D01F6-A895-4DC3-B951-56B8F9E6E01D}\mpengine.dll
2011-05-27 12:32 . 2011-05-27 12:33--------d-----w-c:\windows\system32\MpEngineStore
2011-05-25 22:39 . 2011-05-25 22:39--------d-----w-C:\Pro
2011-05-21 19:49 . 2011-05-21 19:49--------d-----w-C:\_OTL
2011-05-21 12:06 . 2011-05-21 12:06388096----a-r-c:\documents and settings\Rebecca Woods\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-19 01:55 . 2011-05-19 01:55--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\Malwarebytes
2011-05-19 01:54 . 2010-12-20 23:0938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-19 01:54 . 2011-05-19 01:54--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-19 01:54 . 2010-12-20 23:0820952----a-w-c:\windows\system32\drivers\mbam.sys
2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\SUPERAntiSpyware.com
2011-05-18 22:45 . 2011-05-18 22:45--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-05-18 22:12 . 2011-05-18 22:123063136----a-w-C:\ccsetup306.exe
2011-05-18 18:27 . 2011-05-18 19:16--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor
2011-05-18 18:27 . 2011-05-18 18:27--------d-----w-c:\documents and settings\Rebecca Woods\Application Data\OnlineArmor
2011-05-18 18:26 . 2011-04-06 18:0239048----a-w-c:\windows\system32\drivers\oahlp32.sys
2011-05-18 18:26 . 2011-04-06 18:0129464----a-w-c:\windows\system32\drivers\OAnet.sys
2011-05-18 18:26 . 2011-04-06 18:0125192----a-w-c:\windows\system32\drivers\OAmon.sys
2011-05-18 18:26 . 2011-04-06 18:01205864----a-w-c:\windows\system32\drivers\OADriver.sys
2011-05-18 14:16 . 2011-05-18 18:11--------d-----w-c:\documents and settings\All Users\Application Data\iolo
2011-05-17 21:01 . 2011-05-17 21:01--------d--h--w-c:\windows\system32\GroupPolicy
2011-05-17 20:31 . 2010-10-19 20:51222080------w-c:\windows\system32\MpSigStub.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 10:07 . 2010-07-07 13:42472808----a-w-c:\windows\system32\deployJava1.dll
2011-04-14 07:40 . 2008-06-26 08:3073728----a-w-c:\windows\system32\javacpl.cpl
2011-03-07 05:33 . 2004-08-10 18:02692736---ha-w-c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-10 17:51420864---ha-w-c:\windows\system32\vbscript.dll
2011-03-03 14:47 . 2010-01-06 16:51398760---ha-r-c:\windows\system32\cpnprt2.cid
2011-03-03 13:21 . 2004-08-10 17:511857920---ha-w-c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-25 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 2183168]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 405504]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"eBook Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\eBook Library Launcher.exe" [2009-10-20 902504]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-17 98304]
"@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-04-06 2477032]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartUp This"="c:\program files\Laplink\PCmover\LaunchSt.exe" [2007-11-01 247088]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-21 13:4510536----a-w-c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:1364592----a-w-c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\real\\realplayer\\realplay.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"67:UDP"= 67:UDP:DHCP Discovery Service
.
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/18/2011 1:26 PM 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [5/18/2011 1:26 PM 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/18/2011 1:26 PM 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/18/2011 1:26 PM 29464]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 1:27 PM 1074568]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/29/2010 10:30 AM 10448]
S1 MpKslf74c7e6c;MpKslf74c7e6c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C9BD671-6650-4FAA-B6C1-5CF771BBD1E3}\MpKslf74c7e6c.sys [?]
S2 gupdate1ca25d2787f1ffc;Google Update Service (gupdate1ca25d2787f1ffc);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104]
S2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [5/18/2011 1:26 PM 381512]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [5/18/2011 1:26 PM 4326472]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/12/2009 4:20 PM 401920]
S3 cpuz134;cpuz134;\??\c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\REBECC~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/2/2010 3:46 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2009 5:21 PM 133104]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [8/3/2005 3:59 PM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [8/3/2005 3:59 PM 8960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-26 22:20]
.
2011-05-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21]
.
2011-05-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-25 22:21]
.
2011-05-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-109568239-1760306711-3351161423-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
2011-05-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-109568239-1760306711-3351161423-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080626
TCP: DhcpNameServer = 208.180.42.68 208.180.42.100
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-27 12:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(592)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\System32\BCMLogon.dll
c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\MFC80.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
.
- - - - - - - > 'explorer.exe'(2492)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-05-27 12:27:58
ComboFix-quarantined-files.txt 2011-05-27 17:27
ComboFix2.txt 2011-05-26 16:09
.
Pre-Run: 107,173,453,824 bytes free
Post-Run: 107,162,755,072 bytes free
.
- - End Of File - - BC2C36FF47868
i would still like to see the Security Check log.

SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel MODULES << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
Sorry! My computer froze and I forgot to go back and run that.

esults of screen317's Security Check version 0.99.12
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Online Armor 5.0
Microsoft Security Essentials
Antivirus out of date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 25
Adobe Flash Player
Adobe Reader 9.4.2
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Tall Emu Online Armor OAhlp.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe
``````````End of Log````````````
Thanks. Your MicroSoft Security Essentials is out-of-date. Please update it.

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and ENTER Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.As soon as I started to run the Sysprot program I got the lovely blue screen that said windows encountered a problem and was shutting down. Now my computer won't load past the desktop background.

RebeccaQuote
Now my computer won't load past the desktop background.

Once you get to the desktop, it's loaded. Do you mean you can't open anything?
Can you give me a screenshot.
How to post screenshots or images
No desktop icons, no start menu. Just the background nothing on it with the mouse arrow frozen.

RebeccaPlease see if you can re-boot in Safe Mode. If you can, please try System Restore to a date before you tried Sysprot. It looks like everything is restored. I updated MS Essentials and Adobe Reader.

Rebecca
265.

Solve : white smoke translator help!?

Answer»

BUMPHi susan. Something must have HAPPENED to DMJ. I'll try to get a message to him. Don't despair.Sorry, my ISP situation has been crazy.

ESET Online Scan

Please run a free online scan with the ESET Online Scanner

  • Tick the box next to YES, I accept the TERMS of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the OPTION Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use NOTEPAD to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and PASTE that log as a reply to this topic
266.

Solve : XP virus?

Answer»

I managed to find the original LOG. This is much easier now, as I can access the web on this laptop now and windows has stopped crashing.

Quote

2011/01/12 20:52:46.0158TDSS rootkit removing tool 2.4.13.0 Jan 12 2011 09:51:11
2011/01/12 20:52:46.0158================================================================================
2011/01/12 20:52:46.0158SystemInfo:
2011/01/12 20:52:46.0158
2011/01/12 20:52:46.0168OS Version: 5.1.2600 ServicePack: 3.0
2011/01/12 20:52:46.0168Product type: Workstation
2011/01/12 20:52:46.0168ComputerName: GARRY-8F7D7E432
2011/01/12 20:52:46.0168UserName: Owner
2011/01/12 20:52:46.0168Windows directory: C:\WINDOWS
2011/01/12 20:52:46.0168System windows directory: C:\WINDOWS
2011/01/12 20:52:46.0168Processor architecture: Intel x86
2011/01/12 20:52:46.0168Number of processors: 1
2011/01/12 20:52:46.0168Page size: 0x1000
2011/01/12 20:52:46.0168Boot type: Normal boot
2011/01/12 20:52:46.0168================================================================================
2011/01/12 20:52:48.0531Initialize success
2011/01/12 20:52:53.0028================================================================================
2011/01/12 20:52:53.0028Scan started
2011/01/12 20:52:53.0028Mode: Manual;
2011/01/12 20:52:53.0028================================================================================
2011/01/12 20:52:53.0549ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/01/12 20:52:53.0649ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/01/12 20:52:53.0799aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/01/12 20:52:53.0889AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/01/12 20:52:54.0380AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/01/12 20:52:54.0450atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/01/12 20:52:54.0560Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/01/12 20:52:54.0690audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/01/12 20:52:54.0830BCM43XX (30d20fc98bcfd52e1da778cf19b223d4) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
2011/01/12 20:52:54.0891bcm4sbxp (78123f44be9e4768852a3a017e02d637) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
2011/01/12 20:52:55.0151BCMModem (41347688046d49cde0f6d138a534f73d) C:\WINDOWS\system32\DRIVERS\BCMSM.sys
2011/01/12 20:52:55.0261Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/01/12 20:52:55.0371cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/01/12 20:52:55.0501Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/01/12 20:52:55.0622Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/01/12 20:52:55.0692Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/01/12 20:52:55.0792cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys
2011/01/12 20:52:56.0002CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/01/12 20:52:56.0142Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/01/12 20:52:56.0403Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/01/12 20:52:56.0543dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/01/12 20:52:56.0743dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/01/12 20:52:56.0813dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/01/12 20:52:56.0933DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/01/12 20:52:57.0074drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/01/12 20:52:57.0244Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/01/12 20:52:57.0344Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/01/12 20:52:57.0474Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/01/12 20:52:57.0574Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/01/12 20:52:57.0655FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/01/12 20:52:57.0735Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/01/12 20:52:57.0805Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/01/12 20:52:57.0955Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/01/12 20:52:58.0095HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/01/12 20:52:58.0305HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/01/12 20:52:58.0526hwdatacard (53f1160666435151b6fcf89d015fe620) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
2011/01/12 20:52:58.0736i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/01/12 20:52:58.0916ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2011/01/12 20:52:59.0127Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/01/12 20:52:59.0287IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/01/12 20:52:59.0357intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/01/12 20:52:59.0407Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/01/12 20:52:59.0517IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/01/12 20:52:59.0617IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/01/12 20:52:59.0748IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/01/12 20:52:59.0868IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/01/12 20:52:59.0958IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/01/12 20:53:00.0028isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/01/12 20:53:00.0128Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/01/12 20:53:00.0278kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/01/12 20:53:00.0889KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/01/12 20:53:01.0230mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/01/12 20:53:01.0740Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/01/12 20:53:02.0291Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/01/12 20:53:02.0762MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/01/12 20:53:03.0703MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/01/12 20:53:04.0865MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/01/12 20:53:05.0255MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/01/12 20:53:05.0666Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/01/12 20:53:05.0846MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/01/12 20:53:06.0007MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/01/12 20:53:06.0117MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/01/12 20:53:06.0217mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/01/12 20:53:06.0257Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/01/12 20:53:06.0377NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/01/12 20:53:06.0467NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/01/12 20:53:06.0577Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/01/12 20:53:06.0627NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/01/12 20:53:06.0718NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/01/12 20:53:06.0798NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/01/12 20:53:06.0868NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/01/12 20:53:07.0128Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/01/12 20:53:07.0278Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/01/12 20:53:07.0429Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/01/12 20:53:07.0499NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/01/12 20:53:07.0569NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/01/12 20:53:07.0659OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
2011/01/12 20:53:07.0759Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
2011/01/12 20:53:07.0839PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/01/12 20:53:07.0929ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/01/12 20:53:08.0160PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/01/12 20:53:08.0680PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys
2011/01/12 20:53:08.0760Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/01/12 20:53:09.0151PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/01/12 20:53:09.0281PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/01/12 20:53:09.0341Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/01/12 20:53:09.0472PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/01/12 20:53:09.0742RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/01/12 20:53:09.0862Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/01/12 20:53:09.0922RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/01/12 20:53:10.0002Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/01/12 20:53:10.0072Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/01/12 20:53:10.0183RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/01/12 20:53:10.0293RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/01/12 20:53:10.0393redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/01/12 20:53:10.0643SbieDrv (97f0e3f18ab10314318a2b9a3949b331) C:\Program Files\Sandboxie\SbieDrv.sys
2011/01/12 20:53:10.0904Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/01/12 20:53:11.0054Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
2011/01/12 20:53:11.0264Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/01/12 20:53:11.0434splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/01/12 20:53:11.0575sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
2011/01/12 20:53:11.0575Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/01/12 20:53:11.0605sptd - detected Locked file (1)
2011/01/12 20:53:11.0675sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/01/12 20:53:11.0775Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/01/12 20:53:11.0925STAC97 (5813d453ef8ce49d607c255cf128aceb) C:\WINDOWS\system32\drivers\stac97.sys
2011/01/12 20:53:12.0095swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/01/12 20:53:12.0165swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/01/12 20:53:12.0406sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/01/12 20:53:12.0616SysProtDrv.sys (7d5b6655442dbcf5e3b86a134ab90584) C:\Documents and Settings\Owner\Desktop\SysProt\SysProt\SysProtDrv.sys
2011/01/12 20:53:12.0796Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/01/12 20:53:13.0057TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/01/12 20:53:13.0157TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/01/12 20:53:13.0267TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/01/12 20:53:13.0447TSWLAN (61b5cae97b96dee31d8b24fb800364b3) C:\WINDOWS\system32\drivers\TsWlan.sys
2011/01/12 20:53:13.0507Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/01/12 20:53:13.0668Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/01/12 20:53:13.0818usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/01/12 20:53:13.0888usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/01/12 20:53:13.0968usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/01/12 20:53:14.0078usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/01/12 20:53:14.0198usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/01/12 20:53:14.0288USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/01/12 20:53:14.0349usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/01/12 20:53:14.0529VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/01/12 20:53:14.0659VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/01/12 20:53:14.0909Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/01/12 20:53:15.0019wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/01/12 20:53:15.0280WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/01/12 20:53:15.0420WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/01/12 20:53:15.0500WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/01/12 20:53:15.0640\HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/01/12 20:53:15.0690================================================================================
2011/01/12 20:53:15.0690Scan finished
2011/01/12 20:53:15.0690================================================================================
2011/01/12 20:53:15.0731Detected object count: 2
2011/01/12 20:53:38.0213Locked file(sptd) - User select action: Skip
2011/01/12 20:53:38.0223\HardDisk0 - will be cured after reboot
2011/01/12 20:53:38.0223Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2011/01/12 20:53:54.0977Deinitialize success


That's great. Now let's run another scan, just to make sure.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop USING a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
There was an issue HALF way through the scan. I was working on my Vista laptop and turned to my right to look at the XP (this) laptop and I was at about 45mins in and the laptop started a restart. No idea why as I was not watching the screen.
I could then no longer connect to the internet. I logged off and logged back on and everything was fine. I restarted the scan and these are the results.


Quote
C:\WINDOWS\Temp\tpqf.tmp\setup.exeWin32/TrojanDownloader.Agent.QME trojancleaned by deleting - quarantined
These computers are strange devices. If there are no other issues, let's do some cleanup. You may keep SAS and MBAM, if you wish. Update them and run them regularly. All the others can be uninstalled/deleted

To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
This will give you a new, clean Restore POINT.
******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*********************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Thank you for the help. I'm already a member of WOT as they have given both my websites a clean bill of health. Although I'm shutting geek-shack down in about 10mins. Your a star and thank you so much for spending your free time to help me. It is much appreciated.
267.

Solve : Trojan downloader/dropper/virus(es)?

Answer»

So Windows Security Essentials has been detecting trojan viruses lately, which I have been removing/quarantining as appropriate and then following up with a MBAM scan and removing whatever is shown there. Last night, however, a virus Trojan:DOS/Alureon.A was detected and can't be deleted. I also noticed that a number of programs have been installed without my permission, namely SweetIM for Messenger 3.4, SweetIM Toobal for Internet Explorer 4.1, Whitesmoke (which seems to be a big problem), and Street-Ads Browser Enhancer, none of which I am able to uninstall. I also seem to have a Google redirect virus, but only when I am using Astrill (VPN) which I use as I am in China currently.

I have already run CCleaner, SUPERAntivirus and MBAM, but the link for HJT brings up nothing but random characters for me.

If necessary, I guess I would be willing to have a new hard drive installed (if this would remedy the problem) or reformat the current one, but I have no recovery disks. However, if it is possible to get rid of the problem without doing this, I would prefer to do it that way. However, to my (untrained) eye, it looks pretty severe, hence me looking here for help. Thanks in advance.



Here is the SUPERAntivirus LOG

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/05/2011 at 01:13 PM

Application Version : 4.53.1000

Core Rules Database Version : 7202
Trace Rules Database Version: 5014

Scan type : Complete Scan
Total Scan Time : 00:57:29

Memory items scanned : 378
Memory threats detected : 1
Registry items scanned : 7734
Registry threats detected : 56
File items scanned : 81773
File threats detected : 1133

Trojan.Downloader-SVCHost/Fake
C:\WINDOWS\WINUPDATERSTD\SVCHOST.EXE
C:\WINDOWS\WINUPDATERSTD\SVCHOST.EXE
[Speaker] C:\WINDOWS\WINUPDATERSTD\SVCHOST.EXE

Worm.SYSHost
[SysRestore] C:\WINDOWS\..\SBRB\SYSHOST.EXE
C:\WINDOWS\..\SBRB\SYSHOST.EXE

Rogue.Agent/Gen
HKLM\Software\Classes\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}#AppID
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\InprocServer32
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\InprocServer32#ThreadingModel
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\ProgID
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\Programmable
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\TypeLib
HKCR\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF}\VersionIndependentProgID
HKCR\chkavwqhhst.chkavwqhhst.1.0
HKCR\chkavwqhhst.chkavwqhhst.1.0\CLSID
HKCR\chkavwqhhst.chkavwqhhst
HKCR\chkavwqhhst.chkavwqhhst\CLSID
HKCR\chkavwqhhst.chkavwqhhst\CurVer
HKCR\TypeLib\{18B5BB0D-DC38-4611-B16C-2A6A82FECAE5}
C:\WINDOWS\$XNTUNINSTALL643$\WKTLY.DLL
HKLM\Software\Classes\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}#AppID
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\InprocServer32
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\InprocServer32#ThreadingModel
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\ProgID
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\Programmable
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\TypeLib
HKCR\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}\VersionIndependentProgID
HKCR\adfavwqhpr.adfavwqhpr.1.0
HKCR\adfavwqhpr.adfavwqhpr.1.0\CLSID
HKCR\adfavwqhpr.adfavwqhpr
HKCR\adfavwqhpr.adfavwqhpr\CLSID
HKCR\adfavwqhpr.adfavwqhpr\CurVer
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKU\S-1-5-21-3945443218-3704102702-969017525-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4}

Trojan.Agent/Gen-Nullo[Short]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKCR\CLSID\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKCR\CLSID\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKCR\CLSID\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}\InprocServer32
HKCR\CLSID\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}\InprocServer32#ThreadingModel
HKCR\CLSID\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}\ProgID
HKCR\Mqublrsv
HKCR\Mqublrsv\CLSID
C:\WINDOWS\SYSTEM32\LWWHZYYW.DLL
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKU\S-1-5-21-3945443218-3704102702-969017525-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD4CBA5A-14F6-88A6-0037-59505B26C86C}
HKLM\System\ControlSet001\Services\otwxoqqw
HKLM\System\ControlSet001\Enum\Root\LEGACY_otwxoqqw
HKLM\System\ControlSet002\Services\otwxoqqw
HKLM\System\ControlSet002\Enum\Root\LEGACY_otwxoqqw
HKLM\System\CurrentControlSet\Services\otwxoqqw
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_otwxoqqw

Malware.Trace
HKU\.DEFAULT\Software\5GUTNY6MFK
HKU\S-1-5-18\Software\5GUTNY6MFK

PUP.Whitesmoke
C:\Program Files\WHITESMOKE\buy.ico
C:\Program Files\WHITESMOKE\ComVistaElevator.dll
C:\Program Files\WHITESMOKE\FloatButtonWhiteApps.txt
C:\Program Files\WHITESMOKE\FuncServer_WDC_x64.exe
C:\Program Files\WHITESMOKE\HookDllOE.dll
C:\Program Files\WHITESMOKE\HookDllOE64.dll
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\blank.gif
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\checkerboard.gif
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\helix.gif
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\iepngfix.htc
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\iepngfix.html
C:\Program Files\WHITESMOKE\html\english\common\iepngfix\opacity.png
C:\Program Files\WHITESMOKE\html\english\common\iepngfix
C:\Program Files\WHITESMOKE\html\english\common\js\common.js
C:\Program Files\WHITESMOKE\html\english\common\js\pngfix.js
C:\Program Files\WHITESMOKE\html\english\common\js\prototype.js
C:\Program Files\WHITESMOKE\html\english\common\js\xmlhttp.js
C:\Program Files\WHITESMOKE\html\english\common\js
C:\Program Files\WHITESMOKE\html\english\common
C:\Program Files\WHITESMOKE\html\english\dictClientDic\dictionary.html
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\ajax-loader.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\corner_bottom_left.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\corner_bottom_right.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\corner_top_left.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\corner_top_right.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\down_arrow.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\input_bg.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\input_bg_old.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\leftSide.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\leftSide2.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\left_input.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\loading_dictionary.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\rightSide.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\right_input.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background\search_strip_bg3.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Background
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\down_arrow.png
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\go_over.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\go_press.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\go_up.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\humanTranslation_press.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\humanTranslation_roll.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\humanTranslation_up.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\moreLang_press.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\moreLang_roll.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons\moreLang_up.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\Buttons
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img\spacer.gif
C:\Program Files\WHITESMOKE\html\english\dictClientDic\img
C:\Program Files\WHITESMOKE\html\english\dictClientDic\index.html
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\common.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\Contextmenu.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\dictInterface.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\jquery-1.4.2.min.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\jquery.combobox.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\jquery.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\prototype.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\transInterface.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js\xmlhttp.js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\js
C:\Program Files\WHITESMOKE\html\english\dictClientDic\style\combobox.css
C:\Program Files\WHITESMOKE\html\english\dictClientDic\style\Contextmenu.css
C:\Program Files\WHITESMOKE\html\english\dictClientDic\style\dictionary.css
C:\Program Files\WHITESMOKE\html\english\dictClientDic\style
C:\Program Files\WHITESMOKE\html\english\dictClientDic\translator.html
C:\Program Files\WHITESMOKE\html\english\dictClientDic
C:\Program Files\WHITESMOKE\html\english\floatingButton\blue-Q-rollover.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton\blue-rollover.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton\blue-X-rollover.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton\blue.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton\index.html
C:\Program Files\WHITESMOKE\html\english\floatingButton\red&blue.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton\Thumbs.db
C:\Program Files\WHITESMOKE\html\english\floatingButton
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\img\Background\howto_bg.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\img\Background
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\img\spacer.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\img\Thumbs.db
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\img
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\index.html
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\blank.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\checkerboard.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\helix.gif
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\iepngfix.htc
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\iepngfix.html
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix\opacity.png
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\iepngfix
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js\index.js
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\js
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\style\style.css
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto\style
C:\Program Files\WHITESMOKE\html\english\floatingButton_howto
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\ajax-loader.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\base_fade_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\blue.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\blue_bg_.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\blue_dark_bg.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\blue_dark_bg_.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\blue_top_bg_.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\bottom_grey_strip.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\buttons_tray_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\buttons_tray_px.p_goldng
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_bar_re_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_bar_re_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_bar_re_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_bottom_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\caption_strip_right_corner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\cascade.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\collapse.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_bl2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_br2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_dot.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_menu_bg.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_submenu.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_submenu_dis.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_sub_menu_bg.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_tl2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\context_tr2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\Copy of notice_right_top_bg.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\down_arrow.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\dpreloader.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_footer_left.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_footer_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_footer_right.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_header_left.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_header_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_header_right.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\edit_sidefade.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\feather.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\green.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\inputline_fade_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\input_bg.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\leftBottom3.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\leftSide.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\leftSide2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\leftSide3.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\left_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\logo.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\logo.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\logo2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\main_background.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\main_background_11.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\main_background_old.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\notice_checkbox_checked.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\notice_checkbox_unchecked.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\red.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\red2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\resize_gripper.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\result_area_top_bg.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\rightBottom.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\rightSide.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\rightSide2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\rightSide2_11.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\right_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\spacer.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\spacer_.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\strike_blue.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\strike_green.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\strike_green2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\strike_purple.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\strike_red.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_apply_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_apply_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_apply_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_check_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_check_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_check_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_left_corner.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\summaryline_right_corner.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\ticket.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\topButtonsLeft.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\topButtonsLeft_from_home.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\topButtonsLeft__.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\topButtonsRight.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\topRightBorder.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\top_grey_strip.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background\wslogo.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Background
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\blue.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\bottom_right_corner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\buttons_tray_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_bar_re_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_bar_re_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_bar_re_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_bottom_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\caption_strip_right_corner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\get-full.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\get-full3.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\green.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\help_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\help_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\help_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\left_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\logo.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\logo.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\logo2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\main_background.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_dictionary_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_dictionary_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_dictionary_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_dictionary_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_templates_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_templates_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_templates_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_templates_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_toolkit_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_toolkit_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_toolkit_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_toolkit_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_translator_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_translator_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_translator_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_translator_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_tutorials_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_tutorials_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_tutorials_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_tutorials_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_writer_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_writer_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_writer_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\menuline_writer_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\red.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\red2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\right_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\sitting_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\sitting_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\sitting_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\smallclosebutton.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\store_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\store_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\store_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_apply_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_apply_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_apply_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_check_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_check_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_check_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\summaryline_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\x.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\x.jpg
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\x_hover.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\x_hover_old.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons\x_old.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\Buttons
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\blue.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\bottom_right_corner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\buttons_tray_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_close_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_close_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_close_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_max_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_max_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_max_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_re_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_re_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bar_re_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_bottom_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\caption_px_11.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\green.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\leftCaptionCorner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\leftCaptionCorner2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\left_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\logo.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\logo3.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\logologo2_11.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\logo_1.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\main_background.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_dictionary_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_dictionary_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_dictionary_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_dictionary_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_templates_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_templates_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_templates_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_templates_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_toolkit_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_toolkit_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_toolkit_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_toolkit_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_translator_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_translator_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_translator_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_translator_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_tutorials_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_tutorials_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_tutorials_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_tutorials_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_writer_down.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_writer_on.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_writer_roll.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\menuline_writer_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\red.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\red2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\rightCaptionCorner.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\rightCaptionCorner.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\rightCaptionCorner2.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\rightCaptionCorner3.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\rightCaptionCorner3_11.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\right_input.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\store_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\store_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\store_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_apply_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_apply_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_apply_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_check_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_check_roll.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_check_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar\summaryline_px.png
C:\Program Files\WHITESMOKE\html\english\gui\img\captionbar
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\addto_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\addto_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\addto_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\definition_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\definition_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\definition_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\enrichment_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\enrichment_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\enrichment_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\explanation_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\explanation_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\explanation_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\grammarexpclosebutton.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\howto_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\howto_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\howto_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\search_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\search_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\search_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\thesaurus_disabled.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\thesaurus_hover.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar\thesaurus_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\grammar
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\closedy2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\content-review4.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\dot.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\down-content.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\grade1.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\grade2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\grade3.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\grade4.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\grade5.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\li-content.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\opencq8.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\report.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\score1.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\score2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\score3.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\score4.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\score5.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\shadow.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\shadow2.png
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\shdow.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section\shdow_good.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\review-section
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\button_no_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\button_no_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\button_yes_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\button_yes_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\caption_bar_close_over.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\ico_analyze.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\ico_complete.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\ico_connection.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\ico_expired.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\loading_window.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\loading_window.swf
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\myWelcome.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_bg.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_bg_bottom.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_bg_gold.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_bg_old.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_bg_top.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_captionbar_press.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_captionbar_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_getitnow_press.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_getitnow_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_ok_press.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_ok_press.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_ok_up.gif
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_ok_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\screen_ok_up_11.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeClose_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeClose_over.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeClose_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeGo_down.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeGo_over.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens\welcomeGo_up.png
C:\Program Files\WHITESMOKE\html\english\gui\img\screens
C:\Program Files\WHITESMOKE\html\english\gui\img\spacer.gif
C:\Program Files\WHITESMOKE\html\english\gui\img
C:\Program Files\WHITESMOKE\html\english\gui\index.html
C:\Program Files\WHITESMOKE\html\english\gui\js\appInterface.js
C:\Program Files\WHITESMOKE\html\english\gui\js\builder.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\common.js
C:\Program Files\WHITESMOKE\html\english\gui\js\Contextmenu.js
C:\Program Files\WHITESMOKE\html\english\gui\js\controls.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\dictionaryContextMenu.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\dragdrop.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\effects.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\enrichmentContextMenu.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\enrichmentsContextMenu.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\final.js
C:\Program Files\WHITESMOKE\html\english\gui\js\gmonitor.js
C:\Program Files\WHITESMOKE\html\english\gui\js\grammarCache.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\grammarContextMenu.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\blank.gif
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\checkerboard.gif
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\helix.gif
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\iepngfix.htc
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\iepngfix.html
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix\opacity.png
C:\Program Files\WHITESMOKE\html\english\gui\js\iepngfix
C:\Program Files\WHITESMOKE\html\english\gui\js\iframeTest.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jqModal.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jquery-1.2.6.pack.NotUSED.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jquery-1.3.2.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jquery-1.3.2.min.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jquery.ba-throttle-debounce.js
C:\Program Files\WHITESMOKE\html\english\gui\js\jquery.jeegoocontext.min.js
C:\Program Files\WHITESMOKE\html\english\gui\js\monitor.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\builder.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\controls.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\dragdrop.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\effects.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\prototype.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\slider.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion\sound.js
C:\Program Files\WHITESMOKE\html\english\gui\js\NonPackedVersion
C:\Program Files\WHITESMOKE\html\english\gui\js\prototype.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\scriptaculous.js
C:\Program Files\WHITESMOKE\html\english\gui\js\slider.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\sound.pack.js
C:\Program Files\WHITESMOKE\html\english\gui\js\spellingContextMenu.class.js
C:\Program Files\WHITESMOKE\html\english\gui\js\summary.js
C:\Program Files\WHITESMOKE\html\english\gui\js\supersleight.js
C:\Program Files\WHITESMOKE\html\english\gui\js\switchcontent.js
C:\Program Files\WHITESMOKE\html\english\gui\js\tooltip.js
C:\Program Files\WHITESMOKE\html\english\gui\js\unittest.js
C:\Program Files\WHITESMOKE\html\english\gui\js\ws_content_manager.js
C:\Program Files\WHITESMOKE\html\english\gui\js\ws_functions.js
C:\Program Files\WHITESMOKE\html\english\gui\js\ws_links.js
C:\Program Files\WHITESMOKE\html\english\gui\js\x.gif
C:\Program Files\WHITESMOKE\html\english\gui\js\xmlhttp.js
C:\Program Files\WHITESMOKE\html\english\gui\js\ypSlideOutMenus.js
C:\Program Files\WHITESMOKE\html\english\gui\js\ypSlideOutMenusContext.js
C:\Program Files\WHITESMOKE\html\english\gui\js
C:\Program Files\WHITESMOKE\html\english\gui\style\combobox.css
C:\Program Files\WHITESMOKE\html\english\gui\style\Contextmenu.css
C:\Program Files\WHITESMOKE\html\english\gui\style\dictionary.css
C:\Program Files\WHITESMOKE\html\english\gui\style\enrichment.css
C:\Program Files\WHITESMOKE\html\english\gui\style\enrichments.css
C:\Program Files\WHITESMOKE\html\english\gui\style\grammar.css
C:\Program Files\WHITESMOKE\html\english\gui\style\iframeTest.css
C:\Program Files\WHITESMOKE\html\english\gui\style\indexnew.css
C:\Program Files\WHITESMOKE\html\english\gui\style\jeegoo.css
C:\Program Files\WHITESMOKE\html\english\gui\style\jqModal.css
C:\Program Files\WHITESMOKE\html\english\gui\style\screens.css
C:\Program Files\WHITESMOKE\html\english\gui\style\spelling.css
C:\Program Files\WHITESMOKE\html\english\gui\style
C:\Program Files\WHITESMOKE\html\english\gui
C:\Program Files\WHITESMOKE\html\english\registration\img\banner.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\banner.png
C:\Program Files\WHITESMOKE\html\english\registration\img\captionbar\caption_bar_close_down.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\captionbar\caption_bar_close_up.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\captionbar\caption_bar_close_up_over.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\captionbar
C:\Program Files\WHITESMOKE\html\english\registration\img\continue_button_click.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\continue_button_over.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\continue_button_up.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\down.gif
C:\Program Files\WHITESMOKE\html\english\registration\img\down.png
C:\Program Files\WHITESMOKE\html\english\registration\img\f2.gif
C:\Program Files\WHITESMOKE\html\english\registration\img
C:\Program Files\WHITESMOKE\html\english\registration\index.html
C:\Program Files\WHITESMOKE\html\english\registration\js\regInterface.js
C:\Program Files\WHITESMOKE\html\english\registration\js
C:\Program Files\WHITESMOKE\html\english\registration\style\registration.css
C:\Program Files\WHITESMOKE\html\english\registration\style
C:\Program Files\WHITESMOKE\html\english\registration
C:\Program Files\WHITESMOKE\html\english\settings\css\index.css
C:\Program Files\WHITESMOKE\html\english\settings\css
C:\Program Files\WHITESMOKE\html\english\settings\img\Background\logo.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Background\main_bg.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Background
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\cancel_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\cancel_down.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\cancel_over.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\cancel_up.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\save_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\save_down.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\save_over.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\save_up.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_connection_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_connection_off.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_connection_on.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_content_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_content_off.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_content_on.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_general_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_general_off.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_general_on.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_info_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_info_off.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_info_on.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_shortcut_disabled.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_shortcut_off.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons\tab_shortcut_on.png
C:\Program Files\WHITESMOKE\html\english\settings\img\Buttons
C:\Program Files\WHITESMOKE\html\english\settings\img\captionbar\caption_bar_close_down.gif
C:\Program Files\WHITESMOKE\html\english\settings\img\captionbar\caption_bar_close_over.gif
C:\Program Files\WHITESMOKE\html\english\settings\img\captionbar\caption_bar_close_up.gif
C:\Program Files\WHITESMOKE\html\english\settings\img\captionbar
C:\Program Files\WHITESMOKE\html\english\settings\img
C:\Program Files\WHITESMOKE\html\english\settings\index.html
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\blank.gif
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\checkerboard.gif
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\helix.gif
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\iepngfix.htc
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\iepngfix.html
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix\opacity.png
C:\Program Files\WHITESMOKE\html\english\settings\js\iepngfix
C:\Program Files\WHITESMOKE\html\english\settings\js\settingsInterface.js
C:\Program Files\WHITESMOKE\html\english\settings\js
C:\Program Files\WHITESMOKE\html\english\settings
C:\Program Files\WHITESMOKE\html\english\templates\dtree.css
C:\Program Files\WHITESMOKE\html\english\templates\dtree.js
C:\Program Files\WHITESMOKE\html\english\templates\General\Apologies\ApologyInnappropriateBehavior.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Apologies\ApologyUnjustBehavior.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Apologies
C:\Program Files\WHITESMOKE\html\english\templates\General\Community Work\ResignationFromVoluntaryPosition.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Community Work
C:\Program Files\WHITESMOKE\html\english\templates\General\Condolences\LetterOfCondolence.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Condolences
C:\Program Files\WHITESMOKE\html\english\templates\General\Cover Letters\CoverLetter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Cover Letters\GrantCoverSheet.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Cover Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Family\FamilyNewsUpdate.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Family
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\AgreementToCompromiseDebt.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\BankError.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\DebtValidation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\InvestigationOfBillingInquiry.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\LetterOfCreditGeneral.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\LetterOfCreditIrrevocable.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\LetterOfCreditRevolving.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\LetterOfDispute.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\RemovalOfInadequateInformation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\ReplyToApplicationForCredit.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\RequestForIncreaseOfCreditLimit.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\ReturningUnsignedCheck.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance\UnauthorizedCreditInquiry.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Finance
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\AChristmasWish.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ArrivalOfChristmas.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\BlessingsAtChristmas.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ChristmasGreetings.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ChristmasGreetingsMessage.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ChristmasGreetingsToASpouse.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ChristmasGreetingsToWorkers.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\ChristmasWishes.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\HappyChristmasGreeting.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\InTheStillOfTheNightChristmasGreeting.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\JoyousOccasion.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\LovePeaceAndJoy.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\MerryChristmasAndHappyNewYear.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas\MerryChristmasToFamily.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Christmas
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Graduation\CongratulationsOnYourGraduation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Graduation\CongratulationsToTheGraduate.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Graduation\YouHaveGraduated.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings\Graduation
C:\Program Files\WHITESMOKE\html\english\templates\General\Greetings
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\EmployeePerformanceReviewAndPlanningSessions.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\EmploymentApplications.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\HealthRelatedIssues.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\NewEmployeeOrientation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\TerminationOfEmployment.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual\TuitionReimbursementPolicy.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Manual
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\EmploymentReferenceLetter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\JobReferenceLetter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\LetterOfReference.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\ReferenceLetterByAcquaintance.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\RequestForEmployeeReferenceLetter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters\VerificationOfEmploymentLetter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employee Reference Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Letter Requesting Pay Raise.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Refusal of Resquest For Raise.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request for Leave of Absence.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request for Letter of Reference.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request for Meeting Regarding Pay Raise.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request for Paid or Unpaid Leave.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request For Salary Increase.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests\Request to Schedule an Interview.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Employment Requests
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Acknowledgment of Job Application.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Confirmation of Job Dismissal.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Final Warning Before Dismissal.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Job Rejection Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Job Rejection Letter2.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection\Rejection of Job Offer.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Dismissal and Rejection
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\Employment Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\Introduction of New Employee.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\Letter for Assistant Professor.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\LetterForTenureTrackAssociateProfessor.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\Offer of Employment.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters\Request for Employment Test.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Employment Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Job Acceptance\Accept or Decline Job Offer.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Job Acceptance\Job Acceptance Letter 2.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Job Acceptance\Job Acceptance Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Job Acceptance\Job Offer Acceptance.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Job Acceptance
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Thank You Letters\Thank You Letter After Interview.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Thank You Letters\Thank You to Applicant for Testing.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees\Thank You Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Hiring Employees
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Resignation Letters\Acceptance of Employee's Resignation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Resignation Letters\Employee Termination Notice.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Resignation Letters\Job Resignation Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination\Resignation Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Hiring and Termination
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Personnel Office\Notice of Decision to Reprimand.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Personnel Office
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Cover Letter Auditor Development Program.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Job Application Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Job Search Cover Letter - Disabled Citizens.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Job Search Cover Letter - Software Employment.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Law Internship Cover Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Resume Cover Letter.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters\Resume Cover Letter2.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Job Search Cover Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Letters of Recommendation\Letter of Recommendation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Letters of Recommendation
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Accounting Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Administrative Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Banking Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Customer Service Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Database and Application Developer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\End User Trainer and Instructional Designer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Engineering Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Freelance Marcom Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\General CV Format.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Graphic Designer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Healthcare Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Internship Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Java Developer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Management Resume 2.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Management Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Marketing Administrator Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Marketing Director Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\HumanIt seems my post was too long, here's the rest of it:


C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Marketing Manager Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Medical Essay Residency Experience.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Medical Resume - Physician.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Medical Resume Partnership in General Practice.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\PowerPoint Designer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Product Delivery Engineer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Sales Representative Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Software QA Engineer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Technical Publication Manager Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Technical Writer.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Web Developer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes\Web Maintainer Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters\Resumes
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources\Resumes and Cover Letters
C:\Program Files\WHITESMOKE\html\english\templates\General\Human Resources
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Advertising\Advertising Commitment Form.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Advertising\Art Advertising Flyer.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Advertising\Request for Advertising Rate.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Advertising\Subscriber Letter News Service.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Advertising
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Legal\Assignment of Literary Property.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Legal
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Comments to Author Regarding Book.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Introduction of Novel.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Letter of Interest to Magazine.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Letter of Recommendation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Magazine Review.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions\Promotional Letter Antique Shop.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Promotions
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Resumes\Actor Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary\Resumes
C:\Program Files\WHITESMOKE\html\english\templates\General\Literary
C:\Program Files\WHITESMOKE\html\english\templates\General\Personal Matters\Career Change.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Personal Matters\Letter to a Friend Regarding Change of Job.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Personal Matters\Sale of Automobile or Other Motor Vehicle.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Personal Matters\Upset Regarding Loss of Job.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Personal Matters
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Admissions Essays\Admissions Essay for Entrance to Theater Institute.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Admissions Essays\Essay - Describe Events.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Admissions Essays\Graduate School Literary Essay.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Admissions Essays
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Careers\Career Letter for Accounting Position.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Careers\Career Letter in Journalism.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Careers
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Personal Correspondence\Compliment Student on Graduation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Personal Correspondence\Congratulations to High School Graduate.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Personal Correspondence\Personal Letter of Recommendation.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Personal Correspondence\Request for Financial Assistance from Parents.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Personal Correspondence
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes\Resume for After-School Job.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes\Student Resume Automotive Service Industry.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes\Student Resume Forestry.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes\Student Resume Wildlife.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes\Student Resume.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\Resumes
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\University Correspondence\Appreciation of Scholarship.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\University Correspondence\Request for Reference.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\University Correspondence\Request for University Application Material.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Students\University Correspondence
C:\Program Files\WHITESMOKE\html\english\templates\General\Students
C:\Program Files\WHITESMOKE\html\english\templates\General\Thank You\Letter Thanking Coworker for Support.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Thank You\Message of Thanks.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Thank You\Thank You Staff for Emotional Support.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Thank You
C:\Program Files\WHITESMOKE\html\english\templates\General\Well Wishes\Letter of Congratulations.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Well Wishes\Welcome New Tenants.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Well Wishes\Wishes for Speedy Recovery.html
C:\Program Files\WHITESMOKE\html\english\templates\General\Well Wishes
C:\Program Files\WHITESMOKE\html\english\templates\General
C:\Program Files\WHITESMOKE\html\english\templates\images\jspDrag.gif
C:\Program Files\WHITESMOKE\html\english\templates\images\jspVerticalBar.gif
C:\Program Files\WHITESMOKE\html\english\templates\images
C:\Program Files\WHITESMOKE\html\english\templates\img\apply_over.png
C:\Program Files\WHITESMOKE\html\english\templates\img\apply_press.png
C:\Program Files\WHITESMOKE\html\english\templates\img\apply_up.png
C:\Program Files\WHITESMOKE\html\english\templates\img\atart_arrow.jpg
C:\Program Files\WHITESMOKE\html\english\templates\img\base.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\borders.png
C:\Program Files\WHITESMOKE\html\english\templates\img\borders2.png
C:\Program Files\WHITESMOKE\html\english\templates\img\borders3.png
C:\Program Files\WHITESMOKE\html\english\templates\img\borders_good.png
C:\Program Files\WHITESMOKE\html\english\templates\img\bullet.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\cd.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\close.png
C:\Program Files\WHITESMOKE\html\english\templates\img\close2.png
C:\Program Files\WHITESMOKE\html\english\templates\img\dirClose.png
C:\Program Files\WHITESMOKE\html\english\templates\img\dirOpen.png
C:\Program Files\WHITESMOKE\html\english\templates\img\empty - Copy.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\empty.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\empty2.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\folder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\folderopen.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\globe.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\base.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\cd.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\empty.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\folder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\folderopen.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\globe.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\imgfolder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\join.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\joinbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\line.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\minusbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\musicfolder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\nolines_minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\nolines_plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\page.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\plusbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\question.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img\trash.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\img
C:\Program Files\WHITESMOKE\html\english\templates\img\imgfolder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\join.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\joinbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\jspDrag.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\jspVerticalBar.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\line.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\minusbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\musicfolder.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\myEmpty.png
C:\Program Files\WHITESMOKE\html\english\templates\img\neg_bullet.png
C:\Program Files\WHITESMOKE\html\english\templates\img\nolines_minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\nolines_plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\open.png
C:\Program Files\WHITESMOKE\html\english\templates\img\open2 - Copy.png
C:\Program Files\WHITESMOKE\html\english\templates\img\open2.png
C:\Program Files\WHITESMOKE\html\english\templates\img\p7t_minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\p7t_plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\page.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\plusbottom.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\plus_bullet.png
C:\Program Files\WHITESMOKE\html\english\templates\img\question.gif
C:\Program Files\WHITESMOKE\html\english\templates\img\top_close.png
C:\Program Files\WHITESMOKE\html\english\templates\img\top_open.png
C:\Program Files\WHITESMOKE\html\english\templates\img\trash.gif
C:\Program Files\WHITESMOKE\html\english\templates\img
C:\Program Files\WHITESMOKE\html\english\templates\index.html
C:\Program Files\WHITESMOKE\html\english\templates\js\jquery-1.4.2.min.js
C:\Program Files\WHITESMOKE\html\english\templates\js\jquery.jscrollpane.min.js
C:\Program Files\WHITESMOKE\html\english\templates\js\jquery.mousewheel.js
C:\Program Files\WHITESMOKE\html\english\templates\js\switchcontent.js
C:\Program Files\WHITESMOKE\html\english\templates\js\templatesInterface.js
C:\Program Files\WHITESMOKE\html\english\templates\js
C:\Program Files\WHITESMOKE\html\english\templates\menu.htm
C:\Program Files\WHITESMOKE\html\english\templates\objects\ebook_js.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\flashobject.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\mcl.css
C:\Program Files\WHITESMOKE\html\english\templates\objects\navigation.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\p7tm\p7tmbasic.css
C:\Program Files\WHITESMOKE\html\english\templates\objects\p7tm\p7tmscripts.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\p7tm\p7t_minus.gif
C:\Program Files\WHITESMOKE\html\english\templates\objects\p7tm\p7t_plus.gif
C:\Program Files\WHITESMOKE\html\english\templates\objects\p7tm
C:\Program Files\WHITESMOKE\html\english\templates\objects\parseURL.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\utils.js
C:\Program Files\WHITESMOKE\html\english\templates\objects\wm_cookies.js
C:\Program Files\WHITESMOKE\html\english\templates\objects
C:\Program Files\WHITESMOKE\html\english\templates\start.html
C:\Program Files\WHITESMOKE\html\english\templates\style\jquery.jscrollpane.css
C:\Program Files\WHITESMOKE\html\english\templates\style\style.css
C:\Program Files\WHITESMOKE\html\english\templates\style\templates.css
C:\Program Files\WHITESMOKE\html\english\templates\style
C:\Program Files\WHITESMOKE\html\english\templates
C:\Program Files\WHITESMOKE\html\english\userGuide\css\jquery.jscrollpane.css
C:\Program Files\WHITESMOKE\html\english\userGuide\css\style - Copy.css
C:\Program Files\WHITESMOKE\html\english\userGuide\css\style.css
C:\Program Files\WHITESMOKE\html\english\userGuide\css
C:\Program Files\WHITESMOKE\html\english\userGuide\faq.html
C:\Program Files\WHITESMOKE\html\english\userGuide\images\arr.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\arr2.gif
C:\Program Files\WHITESMOKE\html\english\userGuide\images\bg - Copy.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\bg-good.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\bg.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\boxBlackFix.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\buttons.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\ConfiguringWhiteSmoke.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\correctionssuggestions.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\dictionaryTab.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\faq.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\i.gif
C:\Program Files\WHITESMOKE\html\english\userGuide\images\I.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\jspDrag.gif
C:\Program Files\WHITESMOKE\html\english\userGuide\images\jspVerticalBar.gif
C:\Program Files\WHITESMOKE\html\english\userGuide\images\nav.jpg
C:\Program Files\WHITESMOKE\html\english\userGuide\images\otk.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\t.gif
C:\Program Files\WHITESMOKE\html\english\userGuide\images\TheRight-clickMenu.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\TheTemplatesTab.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\translatorTab.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\WhiteSmokeEmailCheck.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\WhiteSmokeOverview.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images\WriterTab.png
C:\Program Files\WHITESMOKE\html\english\userGuide\images
C:\Program Files\WHITESMOKE\html\english\userGuide\js\jquery-1.4.2.min.js
C:\Program Files\WHITESMOKE\html\english\userGuide\js\jquery.jscrollpane.min.js
C:\Program Files\WHITESMOKE\html\english\userGuide\js\jquery.min.js
C:\Program Files\WHITESMOKE\html\english\userGuide\js\jquery.mousewheel.js
C:\Program Files\WHITESMOKE\html\english\userGuide\js\userGuide.js
C:\Program Files\WHITESMOKE\html\english\userGuide\js
C:\Program Files\WHITESMOKE\html\english\userGuide\troubleshooting.html
C:\Program Files\WHITESMOKE\html\english\userGuide\userGuide.html
C:\Program Files\WHITESMOKE\html\english\userGuide
C:\Program Files\WHITESMOKE\html\english
C:\Program Files\WHITESMOKE\html
C:\Program Files\WHITESMOKE\Microsoft.VC80.CRT.manifest
C:\Program Files\WHITESMOKE\msvcp80.dll
C:\Program Files\WHITESMOKE\msvcr80.dll
C:\Program Files\WHITESMOKE\NotifierWhiteApps.txt
C:\Program Files\WHITESMOKE\osmax.ocx
C:\Program Files\WHITESMOKE\osmax64.ocx
C:\Program Files\WHITESMOKE\secman.dll
C:\Program Files\WHITESMOKE\secman64.dll
C:\Program Files\WHITESMOKE\settings.ini
C:\Program Files\WHITESMOKE\TCCons.dll
C:\Program Files\WHITESMOKE\TCCons_x64.dll
C:\Program Files\WHITESMOKE\Uninst.exe
C:\Program Files\WHITESMOKE\WCapture.dll
C:\Program Files\WHITESMOKE\WCaptureX.dll
C:\Program Files\WHITESMOKE\WCaptureX_x64.dll
C:\Program Files\WHITESMOKE\WCapture_x64.dll
C:\Program Files\WHITESMOKE\WCustom.dll
C:\Program Files\WHITESMOKE\WCustom_x64.dll
C:\Program Files\WHITESMOKE\WhiteSmokeRegistration.exe
C:\Program Files\WHITESMOKE\WHook.dll
C:\Program Files\WHITESMOKE\WHook_x64.dll
C:\Program Files\WHITESMOKE\Writer.ico
C:\Program Files\WHITESMOKE\WSDictHookDll.dll
C:\Program Files\WHITESMOKE\WSEngine.dll
C:\Program Files\WHITESMOKE\WSEnrichment.exe
C:\Program Files\WHITESMOKE\WSLogger.exe
C:\Program Files\WHITESMOKE\WSMouseHook.dll
C:\Program Files\WHITESMOKE\WSTray64.exe
C:\Program Files\WHITESMOKE

Trojan.Dropper/SVCHost-Fake
C:\SBRB\SVCHOST.EXE

Adware.Tracking Cookie
.eyewonder.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
in.getclicky.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.riverisland.122.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediav.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adxpose.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
user.lucidmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mmstat.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.msnportal.112.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.yieldmanager.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
fidelity.rotator.hadj7.adjuggler.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.googleads.g.doubleclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ext-us.bestofmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ice.112.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
dc.tremormedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.myroitracking.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lucidmedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fuckyeahchesthair.tumblr.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
trekmedia.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.*adult URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fuckyeahchesthair.tumblr.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dmtracker.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstbeacon.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstbeacon.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cracked.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediabrandsww.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
server.iad.liveperson.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
delivery.trafficjunky.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
fidelity.rotator.hadj7.adjuggler.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.sublimemedia.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.jscount.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.jscount.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
*Blocked Russian URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
*Blocked Russian URL* [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
eas.apm.emediate.eu [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
eas.apm.emediate.eu [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
publishers.w00tmedia.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.nike.112.2o7.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
fr.sitestat.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
fr.sitestat.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
bmuk.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
bmuk.burstnet.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adviva.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.sublimemedia.net [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
C:\Users\1\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt





And the MBAM log

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6773

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/5/2011 1:33:43 PM
mbam-log-2011-06-05 (13-33-43).txt

Scan type: Quick scan
Objects scanned: 149488
Time elapsed: 2 minute(s), 42 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
c:\Windows\winupdaterstd\svchost.exe (Backdoor.Agent) -> 3220 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Context\Context-Ads (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0554F458-BC72-486D-9AAE-F5D719A933EF} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\chkavwqhhst.chkavwqhhst.1.0 (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\chkavwqhhst.chkavwqhhst (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adfavwqhpr.adfavwqhpr.1.0 (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adfavwqhpr.adfavwqhpr (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF4A603B-2231-4ABA-AEFF-A1F02D9CBCE4} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$XNTUninstall643$ (Adware.AdRotator) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Speaker (Backdoor.Agent) -> Value: Speaker -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bipro (Trojan.Agent.Gen) -> Value: bipro -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)
HELLO and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
******************************************************
Is this a business computer?
I am required to give you this information.
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

I would counsel you to disconnect this PC from the Internet immediately.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall?

We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

Should you have any questions, please feel FREE to ask.

Please let us know what you have decided to do in your next post
It isn't a business computer. I would like to try and repair for now, I think. Since I am currently abroad and can't really reformat myself. I will definitely consider reformatting when I return home, but until then I need to use my computer. I wouldn't need to use it for banking or anything serious, just for university work mainly. For future reference, installing a new hard drive would FIX the problem, right?Quote

For future reference, installing a new hard drive would fix the problem, right?
Yes but you will need to install your OS and, from what I understand, the disk(s) are at home.

Download DDS from HERE or HERE and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.
***************************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
268.

Solve : Malware after bad link from infected friend?

Answer»

Ok. I'm satisfied. How's your computer running? Any other issues?No - other than facebook sometimes (rare) logging me out on its own, but I guess that's a facebook issue.Ok. Let's do some cleanup.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*************************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
*********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and SCROLL down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ACTIVEX programs to run on your computer. Also stop certain cookies from being ADDED to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. GUIDE: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
I would like to sincerely thank you in helping me deal with this infection!Quote from: Harres on January 16, 2011, 06:11:53 PM
I would like to sincerely thank you in helping me deal with this infection!
You're welcome. Tell your friends about us here at CH. I will lock this thread. If you need it opened for any reason, pm me.
269.

Solve : Requesting help to clean PC?

Answer»

It says "no action taken". Please run it again and clean the infections. Let's do some cleanup.

Download OTL to your desktop.

To REMOVE all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it MANUALLY.

************************************************

To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When TURNING off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
This will give you a new, clean Restore Point.

**********************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a COMPLETE cleaning.
********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Hi Dave,

I'll try your instruction...viruses keep me annoying...hopes it will work and Thanks for advance...
These instructions were created for this user and may do more harm to your computer than good. If you're having problems, start your own thread and you will get help.Thank you so much Dave for all your time, effort and expertise. You are an absolute star You're welcome. I will lock this thread. If the original poster needs it re-opened, please pm me.
270.

Solve : Infected with win 7 security 2011?

Answer»

This appears to be a problem with your accounts and not malware. One more scan, if you don't mind.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the START button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
C:\Qoobox\Quarantine\C\Users\Huy\AppData\Roaming\803F13E0404D4D065A16E363334CEE12\enemies-names.txt.virWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Users\Huy\AppData\Roaming\803F13E0404D4D065A16E363334CEE12\local.ini.virWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined




I still can't browse the internet. Maybe the the virus change some settings and they were not restored when the virus was removed.Quote
I still can't browse the internet. Maybe the the virus change some settings and they were not restored when the virus was removed.
Mini-toolbox took care of that PLUS most of tools we used were download from the internet. We should do some cleanup and then you should start a new thread in this forum.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
***********************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these RELIABLE vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before IMMUNIZING. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Okay I will post on a New thread about my browser issue.

thanks for all your help Dave!You're welcome. This thread will be locked. If you need it re-opened, please send me a pm.
271.

Solve : Background process almost brings computer to a halt?

Answer»

Could you please try to run ESET again?Would it be OK for me to stop the process wuauclt.exe when it runs, as this seems to be the process that brings the computer almost to a halt - or would that do more harm than good?

ESET ran and said there were no threats.ESET log:

ESETSmartInsta[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=43fa88dd6e114e4a953ecf35227219d2
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-04-16 09:11:44
# local_time=2011-04-16 10:11:44 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 6058035 6058035 0 0
# compatibility_mode=3584 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 2352769 2352769 0 0
# compatibility_mode=9217 16777214 100 70 4357047 25685842 0 0
# scanned=152208
# found=0
# cleaned=0
# scan_time=6543Good. How's your computer running?A spurious process is still running each day. It appears to be wuauclt.exe.Quote

A spurious process is still running each day. It appears to be wuauclt.exe.
Are you getting a warning about this file?

Wuauclt.exe is the AutoUpdate Client of Windows Update and is used to check for available updates (for the various versions of the MS Windows platform) from Microsoft Update. The wuauclt.exe file is included in the Task Manager’s list of active PROCESSES when it is waiting for a response or an action to be performed by the user.
When the spurious process runs, it is sometimes accompanied by a warning message produced by (I think) Norton AV, saying "Win32 Services high memory usage".Please download SystemLook from one of the links below and save it to your DESKTOP.

Link # 1
Link # 2

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click SystemLook.exe to run it.

Copy the contents of the following codebox into the main textfield.
Code: [Select]:filefind
wuauclt.exe
Click the Look button to start the scan.

Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
SystemLook log:-
*********************************************************************************
SystemLook 04.09.10 by jpshortstuff
Log created at 10:21 on 04/06/2011 by Administrator
Administrator - Elevation successful

========== filefind ==========

Searching for "wuauclt.exe"
C:\WINDOWS\ERDNT\cache\wuauclt.exe--a---- 53472 bytes[11:39 18/02/2011][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD
C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe------- 111104 bytes[20:18 18/09/2008][00:12 14/04/2008] ED7262E52C31CF1625B65039102BC16C
C:\WINDOWS\system32\wuauclt.exe--a---- 53472 bytes[08:00 04/08/2004][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD
C:\WINDOWS\system32\dllcache\wuauclt.exe--a---- 53472 bytes[08:00 04/08/2004][18:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD

-= EOF =-
*************************************************************************

In the course of clicking on the Link in your post to find out how to temporarily disable my AV software, I noticed information on that website about how to fix corruptions of SVCHOST; so I bought that software (Paretologic PC Health Advisor) and ran it. It lets you do a scan without paying but I had to pay for the software to run the fix. ANYWAY, as one of the messages I was getting referred to high memory usage by SVCHOST, I thought this might fix the problem. In fact, it does seem to have gone quite a long way to fixing it, as SVCHOST now runs quickly and hardly slows the PC down while it's running. There is still one outstanding problem, which gives a 'Generic host process for Win 32 Services - high memory usage' message, which I think is the wuauclt.exe - but this seems to only occur only once every few days. So I think there were 2 problems, one of which has now been fixed and the other of which only happens every so often, rather than every day. I think we might be able to put up with this, unless you have a simple solution to it. If you think we have gone as far as is sensible with this, I would like to thank you for your efforts in dealing with this. Your involvement is appreciated.Quote
In fact, it does seem to have gone quite a long way to fixing it, as SVCHOST now runs quickly and hardly slows the PC down while it's running. There is still one outstanding problem, which gives a 'Generic host process for Win 32 Services - high memory usage' message, which I think is the wuauclt.exe - but this seems to only occur only once every few days. So I think there were 2 problems, one of which has now been fixed and the other of which only happens every so often, rather than every day. I think we might be able to put up with this, unless you have a simple solution to it. If you think we have gone as far as is sensible with this, I would like to thank you for your efforts in dealing with this. Your involvement is appreciated.

I don't feel that this is a malware issue. Very little showed up in all the scans we've run on this computer. You could start a new thread in the appropriate software forum, if you wish.
We should do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start SEARCH, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
****************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
******************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from ONLINE scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!OK - done that. Thanks for your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm or start a new thread.
272.

Solve : know I have a virus, don't know anything else about it.?

Answer»

thanks. I think I am almost back up and running. Now that I've "freshened up" my laptop with a full format, I may go off and do the same THING to my old XP desktop that has a very full hard drive.

With spyware PROGRAMS like you listed, do I have them all on and active? do they run in the background or do I need to get back into the habit of just running them weekly?
I have Windows Defender on and running. Is there a way to settle User Account CONTROL down so it isn't popping up every time I make a change?Quote

With spyware programs like you listed, do I have them all on and active? do they run in the background or do I need to get back into the habit of just running them weekly?
MBAM has a free trial period of continous scanning. Once that expires, you will probably have to buy the new version. Or, you can keep MBAM and SAS on your computer, update them and run regularyly.
Quote
Is there a way to settle User Account Control down so it isn't popping up every time I make a change?
You can DISABLE it.
273.

Solve : I keep sending everyone in my email address book emails.?

Answer»

Quote

Is it a serious problem that I get this warning on alot of sites I have to log into?
No. That's just there for your protection. It means it might be a dubious website.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the CLEANING process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
********************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the BOX next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't KNOW what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thank you SuperDave for your help. Sorry the "thank you" came so late as once the computer starting working good again I was off and running.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
274.

Solve : Log analyze (malware removal help)?

Answer»

That looks good. If there are no other issues, it's time for some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(NOTE: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* DEPENDING on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
***********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block OUTGOING connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
I greatly thank you for the support you gave me, I will now know how to keep my PC clean in futur.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
275.

Solve : PC Running Very Slow/Freezing?

Answer»

So I take it I should UNCHECK "Remove Found Threats" and just scan and post log?no found threats...can't find log ?

Now what?Quote from: bluecountry on June 27, 2011, 12:14:38 AM

no found threats...can't find log ?

Now what?
How's your computer running? Any other issues?It's BETTER than before, though it has it's moments.
Is there anything I can do, run, to double check and make sure it checks out?
Thanks Dave.Quote
Is there anything I can do, run, to double check and make sure it checks out?
Thanks Dave.
From all the scans we've run I would say that it's clean. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
**************************************************
If this doesn't remove ComboFix, please let me know

Clean out your temporary internet files and temp files.

DOWNLOAD TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and SCROLL down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from ONLINE scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1) There is no FINAL scan we can do, just to be sure, before book closing?

2) tried combofix uninstall, said windows could not find it. I think I might have already deleted, anyway to confirm?Quote
There is no final scan we can do, just to be sure, before book closing?
ESET was the final scan.
Quote
tried combofix uninstall, said windows could not find it. I think I might have already deleted, anyway to confirm?
I didn't think it would work because ComboFix was installed in the wrong location. Please try this:

Download OTC by OldTimer and save it to your desktop.

Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
**************************************************
To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.I have done everything but secunia.

I was in firefox with secunia and tried it three times, all of which caused the browser to crash.

I then tried it with IE, and it caused this message to be displayed continously until I ctrl-alt-dlt it to shut off.

Quote
Microsoft C++ Runtime Library
Runtime Error!

Program: C:\Program files\ internet explorer\iexplore.exe

R6025
-pure virtual function cell

So is there still something wrong with my PC?
What should I do?Quote
was in firefox with secunia and tried it three times, all of which caused the browser to crash.

I then tried it with IE, and it caused this message to be displayed continously until I ctrl-alt-dlt it to shut off.

That's ok. Secunia acts up sometimes. Just make sure that you have all your updates, especially Windows and Java updates.So it otherwise should be all set and good?Quote from: bluecountry on July 02, 2011, 11:32:00 AM
So it otherwise should be all set and good?
Yes. I will lock this thread. If you need it re-opened, please send me a pm.
276.

Solve : Requesting Help with Malware Removal?

Answer»

Okay, just finished the ESET scan. I accidentally hit Finish before exporting, but fortunately found the log in the Program Files location you mentioned, so thanks for that.

I'm suddenly getting a lot of "Potentially Unwanted Program Blocked" messages from McAfee regarding "TOOL-NirCmd" from OTL, should I allow that program?

Following is the log, and again, thank you.

ESET Log:

[emailprotected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=7158f6dc72e4014abce3de1c6ba92476
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-07-12 10:44:01
# local_time=2011-07-12 03:44:01 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 268006 268006 0 0
# compatibility_mode=5121 16777213 100 75 939170 10873495 0 0
# compatibility_mode=5892 16776573 100 100 0 147108361 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=164046
# found=0
# cleaned=0
# scan_time=9807
Quote

I'm suddenly getting a lot of "Potentially Unwanted Program Blocked" messages from McAfee regarding "Tool-NirCmd" from OTL, should I allow that program?
That looks good. If there are no other issues, we can do some cleanup which will fix that OTL warning.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, PLEASE delete it manually.
*************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all PROGRAMS when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet EXPLORER to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the LATEST Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Great, I've done all of this. Once again, thank you so much, Dave!You're welcome. I will lock this thread. If you need it reopened, please send me a pm.
277.

Solve : Troubling Virus?

Answer»

I forgot to mention that the Security check indicates that you have Panda Antivirus Pro 2012 and Norton 360 running at the same time on your computer. One of these AV's will have to be disabled/uninstalled.
*********************************************
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not INTERFERE with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    File::
    C:\found.005
    C:\found.004
    C:\found.003
    C:\found.002
    C:\found.001

    DirLook::
    C:\40d9b26e2a8b3f767a
    C:\ef60c58cdd1f56bf95401cfaf20940ef

    Firefox::
    Trusted Zone: internet
    Trusted Zone: mcafee.com

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
*********************************************************
Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and links posted for each one)

* Copy the file path in the below Code box:

Code: [Select]c:\windows\system32\x64
c:\windows\system32\igxpun.exe
c:\windows\system32\Drivers\utkwnty5.sys
* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning ENGINES.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
Sorry it took so long to get back to you I've had more problems with my laptop.

I checked the files with jotti and found out that I only have 1 of the files......c:\windows\system32\igxpun.exe
the others do not exist on my computer.

ComboFix 11-07-15.01 - Feutz 07/15/2011 11:58:26.3.2 - x86 NETWORK
Running from: c:\users\Feutz\Desktop\ComboFix.exe
Command switches used :: c:\users\Feutz\Desktop\CFScript.txt
.
FILE ::
"C:\found.001"
"C:\found.002"
"C:\found.003"
"C:\found.004"
"C:\found.005"
.
.
((((((((((((((((((((((((( Files Created from 2011-06-15 to 2011-07-15 )))))))))))))))))))))))))))))))
.
.
2011-07-15 19:12 . 2011-07-15 19:15--------d-----w-c:\users\Feutz\AppData\Local\temp
2011-07-15 19:12 . 2011-07-15 19:12--------d-----w-c:\users\Robin\AppData\Local\temp
2011-07-15 19:12 . 2011-07-15 19:12--------d-----w-c:\users\Default\AppData\Local\temp
2011-07-15 16:44 . 2011-07-15 16:44--------d-----w-C:\found.007
2011-07-15 16:35 . 2011-07-15 16:35--------d-----w-c:\users\Robin\AppData\Local\Panda Security
2011-07-15 16:35 . 2011-07-15 16:35--------d-----w-c:\users\Robin\AppData\Roaming\SUPERAntiSpyware.com
2011-07-15 05:18 . 2011-07-15 05:18--------d-----w-C:\found.006
2011-07-15 04:41 . 2011-07-15 04:55--------d-----w-c:\windows\$regcmp$
2011-07-12 12:51 . 2011-07-12 12:51404640----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 06:42 . 2011-06-20 15:577074640----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2AE3AC5-D19D-420D-820B-E39A120A10E8}\mpengine.dll
2011-07-09 22:14 . 2011-07-10 17:49--------d-----w-c:\users\Feutz\AppData\Local\Conduit
2011-07-09 16:37 . 2011-07-09 16:37--------d-----w-C:\found.005
2011-07-09 16:30 . 2011-07-09 16:30--------d-----w-C:\40d9b26e2a8b3f767a
2011-07-09 03:07 . 2011-07-15 01:58183180----a-w-c:\windows\system32\drivers\APPFCONT.DAT
2011-07-09 03:07 . 2010-09-09 23:23193864----a-w-c:\windows\system32\drivers\idsflt.sys
2011-07-09 03:07 . 2009-09-25 21:5446856----a-w-c:\windows\system32\drivers\wnmflt.sys
2011-07-09 03:07 . 2009-09-25 21:5453256----a-w-c:\windows\system32\drivers\dsaflt.sys
2011-07-09 03:06 . 2011-01-31 23:4183528----a-w-c:\windows\system32\drivers\APPFLT.SYS
2011-07-09 03:06 . 2009-09-25 21:5422024----a-w-c:\windows\system32\drivers\fnetmon.sys
2011-07-09 03:06 . 2009-09-25 21:54159112----a-w-c:\windows\system32\drivers\NETFLTDI.SYS
2011-07-07 10:00 . 2011-07-07 10:00--------d-----w-C:\ef60c58cdd1f56bf95401cfaf20940ef
2011-07-07 00:18 . 2011-07-07 00:18--------d-----w-C:\78584a5e440f81cc72
2011-07-05 10:00 . 2011-07-05 10:00--------d-----w-C:\760eb5305c2b3efcab91dcc17084bd
2011-07-04 23:18 . 2011-07-04 23:18--------d-----w-C:\found.004
2011-07-04 22:45 . 2011-07-04 22:45--------d-----w-c:\windows\system32\x64
2011-07-04 22:45 . 2008-02-12 03:13920088----a-w-c:\windows\system32\igxpun.exe
2011-07-03 18:51 . 2011-07-03 18:51--------d-----w-c:\users\Feutz\AppData\Local\Panda Security
2011-07-03 18:45 . 2010-06-23 01:1326696----a-w-c:\windows\system32\drivers\pavboot.sys
2011-07-03 18:45 . 2007-03-16 02:3854832----a-w-c:\windows\system32\pavcpl.cpl
2011-07-03 18:45 . 2003-10-23 01:23446464----a-w-c:\windows\system32\HHActiveX.dll
2011-07-03 18:45 . 2010-06-22 00:02193344----a-w-c:\windows\system32\TpUtil.dll
2011-07-03 18:45 . 2010-06-22 00:01520000----a-w-c:\windows\system32\PavSHook.dll
2011-07-03 18:45 . 2010-06-22 00:0187360----a-w-c:\windows\system32\PavLspHook.dll
2011-07-03 18:45 . 2010-06-22 00:0155616----a-w-c:\windows\system32\pavipc.dll
2011-07-03 18:45 . 2007-02-08 17:53107568----a-w-c:\windows\system32\SYSTOOLS.DLL
2011-07-03 18:44 . 2011-07-03 18:45--------d-----w-c:\program files\Panda Security
2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\windows\system32\PAV
2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\users\Feutz\AppData\Roaming\Panda Security
2011-07-03 18:44 . 2011-07-03 18:44--------d-----w-c:\programdata\Panda Security
2011-07-03 18:44 . 2010-09-01 18:09201032----a-w-c:\windows\system32\drivers\neti1644.sys
2011-07-03 18:44 . 2010-05-21 20:5054344----a-w-c:\windows\system32\drivers\amm8660.sys
2011-07-03 18:44 . 2010-03-24 19:5555552----a-w-c:\windows\system32\avldr.dll
2011-07-01 20:05 . 2011-07-01 20:05388096----a-r-c:\users\Feutz\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\users\Feutz\AppData\Roaming\SUPERAntiSpyware.com
2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\programdata\SUPERAntiSpyware.com
2011-07-01 01:28 . 2011-07-01 01:28--------d-----w-c:\program files\SUPERAntiSpyware
2011-06-30 13:03 . 2011-06-30 13:03--------d-----w-C:\d6aaef27f533ca95ed452bdd47deb9
2011-06-30 04:59 . 2011-06-30 04:59--------d-----w-C:\60dd7279dace78af16
2011-06-29 14:05 . 2011-06-29 14:05--------d-----w-C:\6bd801315f181fe169cd3798
2011-06-29 13:14 . 2011-06-29 13:14--------d-----w-C:\058d8e97ce6d35b88fe00fef6563
2011-06-29 00:42 . 2011-06-29 00:43--------d-----w-C:\SMCLPAV
2011-06-28 12:54 . 2005-04-04 06:02753664----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-06-28 12:54 . 2005-04-04 06:0269714----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-06-28 12:54 . 2005-04-04 06:01274432----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-06-28 12:54 . 2005-04-04 06:00184320----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-06-28 12:54 . 2005-04-04 05:595632----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-06-28 12:54 . 2011-06-28 12:54200836----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-06-28 12:54 . 2011-06-28 12:54331908----a-w-c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-06-26 17:25 . 2011-07-05 05:12--------d-----w-c:\users\Feutz\AppData\Roaming\QuickScan
2011-06-26 17:22 . 2011-06-26 17:22--------d-----w-c:\users\Feutz\AppData\Local\Mozilla
2011-06-26 14:44 . 2011-06-26 14:44--------d-----w-C:\a8b79eb2bb60353fc6
2011-06-25 16:25 . 2011-06-25 16:32--------d-----w-c:\users\Feutz\AppData\Local\ElevatedDiagnostics
2011-06-20 17:40 . 2011-06-20 17:40472808----a-w-c:\windows\system32\deployJava1.dll
2011-06-19 20:15 . 2011-06-19 20:15--------d-----w-c:\program files\BeerSmith2
2011-06-19 16:28 . 2011-06-19 16:28--------d-----w-C:\5cee7e0f1b01fbec51c15a1462
2011-06-19 14:16 . 2011-06-20 17:41--------d-----w-c:\program files\Common Files\Java
2011-06-19 14:16 . 2011-06-19 14:16--------d-----w-C:\4756e36812682c0f88ddac0bd9665fb6
2011-06-19 13:54 . 2011-06-19 13:54--------d-----w-C:\found.003
2011-06-19 01:08 . 2011-06-19 01:08--------d-----w-C:\found.002
2011-06-17 01:28 . 2011-06-17 01:28--------d-----w-C:\found.001
2011-06-17 00:52 . 2011-04-14 14:5975264----a-w-c:\windows\system32\drivers\dfsc.sys
2011-06-17 00:52 . 2011-04-21 13:58273408----a-w-c:\windows\system32\drivers\afd.sys
2011-06-17 00:52 . 2011-04-29 13:25146432----a-w-c:\windows\system32\drivers\srv2.sys
2011-06-17 00:52 . 2011-04-29 13:25102400----a-w-c:\windows\system32\drivers\srvnet.sys
2011-06-17 00:37 . 2011-06-17 00:37--------d-----w-c:\users\Robin\AppData\Roaming\AVG10
2011-06-16 02:54 . 2011-06-16 02:59--------d-----w-c:\users\Feutz\AppData\Roaming\AVG
2011-06-16 02:08 . 2010-12-20 16:35563712----a-w-c:\windows\system32\oleaut32.dll
2011-06-16 02:08 . 2011-05-02 17:16739328----a-w-c:\windows\system32\inetcomm.dll
2011-06-16 02:08 . 2011-04-29 13:24214016----a-w-c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 02:08 . 2011-04-29 13:2479872----a-w-c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 02:08 . 2011-04-29 13:24106496----a-w-c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 02:08 . 2011-05-02 12:022409784----a-w-c:\program files\Windows Mail\OESpamFilter.dat
2011-06-16 01:03 . 2011-06-16 01:03--------d-----w-C:\$AVG
2011-06-16 00:29 . 2011-06-16 00:29--------d--h--w-c:\programdata\Common Files
2011-06-16 00:27 . 2011-06-30 00:21--------d-----w-c:\programdata\AVG10
2011-06-16 00:16 . 2011-07-01 00:28--------d-----w-c:\program files\AVG
2011-06-16 00:11 . 2011-06-30 00:21--------d-----w-c:\programdata\MFAData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-02 12:52 . 2011-06-02 12:52161792----a-w-c:\windows\system32\msls31.dll
2011-06-02 12:52 . 2011-06-02 12:521126912----a-w-c:\windows\system32\wininet.dll
2011-06-02 12:52 . 2011-06-02 12:5286528----a-w-c:\windows\system32\iesysprep.dll
2011-06-02 12:52 . 2011-06-02 12:5276800----a-w-c:\windows\system32\SetIEInstalledDate.exe
2011-06-02 12:52 . 2011-06-02 12:5274752----a-w-c:\windows\system32\RegisterIEPKEYs.exe
2011-06-02 12:52 . 2011-06-02 12:5263488----a-w-c:\windows\system32\tdc.ocx
2011-06-02 12:52 . 2011-06-02 12:5248640----a-w-c:\windows\system32\mshtmler.dll
2011-06-02 12:52 . 2011-06-02 12:52367104----a-w-c:\windows\system32\html.iec
2011-06-02 12:52 . 2011-06-02 12:5274752----a-w-c:\windows\system32\iesetup.dll
2011-06-02 12:52 . 2011-06-02 12:5223552----a-w-c:\windows\system32\licmgr10.dll
2011-06-02 12:52 . 2011-06-02 12:52152064----a-w-c:\windows\system32\wextract.exe
2011-06-02 12:52 . 2011-06-02 12:52150528----a-w-c:\windows\system32\iexpress.exe
2011-06-02 12:52 . 2011-06-02 12:521427456----a-w-c:\windows\system32\inetcpl.cpl
2011-06-02 12:52 . 2011-06-02 12:52420864----a-w-c:\windows\system32\vbscript.dll
2011-06-02 12:52 . 2011-06-02 12:5235840----a-w-c:\windows\system32\imgutil.dll
2011-06-02 12:52 . 2011-06-02 12:522382848----a-w-c:\windows\system32\mshtml.tlb
2011-06-02 12:52 . 2011-06-02 12:521797632----a-w-c:\windows\system32\jscript9.dll
2011-06-02 12:52 . 2011-06-02 12:52142848----a-w-c:\windows\system32\ieUnatt.exe
2011-06-02 12:52 . 2011-06-02 12:5211776----a-w-c:\windows\system32\mshta.exe
2011-06-02 12:52 . 2011-06-02 12:52101888----a-w-c:\windows\system32\admparse.dll
2011-06-02 12:52 . 2011-06-02 12:52110592----a-w-c:\windows\system32\IEAdvpack.dll
2011-05-29 16:11 . 2011-03-30 00:0339984----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-25 02:14 . 2010-06-27 01:40222080------w-c:\windows\system32\MpSigStub.exe
2011-04-14 16:26 . 2011-06-26 17:22142296----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\40d9b26e2a8b3f767a ----
.
2011-07-09 16:30 . 2011-07-09 16:300---ha-w-c:\40d9b26e2a8b3f767a\$shtdwn$.req
2011-03-25 16:08 . 2011-03-25 16:0836514----a-w-c:\40d9b26e2a8b3f767a\1044\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837222----a-w-c:\40d9b26e2a8b3f767a\1045\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836738----a-w-c:\40d9b26e2a8b3f767a\1046\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837656----a-w-c:\40d9b26e2a8b3f767a\1049\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836020----a-w-c:\40d9b26e2a8b3f767a\1053\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836274----a-w-c:\40d9b26e2a8b3f767a\1055\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0827922----a-w-c:\40d9b26e2a8b3f767a\2052\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837404----a-w-c:\40d9b26e2a8b3f767a\2070\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837314----a-w-c:\40d9b26e2a8b3f767a\3082\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0827950----a-w-c:\40d9b26e2a8b3f767a\1028\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836822----a-w-c:\40d9b26e2a8b3f767a\1029\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836050----a-w-c:\40d9b26e2a8b3f767a\1030\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0838050----a-w-c:\40d9b26e2a8b3f767a\1031\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0838958----a-w-c:\40d9b26e2a8b3f767a\1032\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836030----a-w-c:\40d9b26e2a8b3f767a\1035\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837832----a-w-c:\40d9b26e2a8b3f767a\1036\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0832912----a-w-c:\40d9b26e2a8b3f767a\1037\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837822----a-w-c:\40d9b26e2a8b3f767a\1038\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0837192----a-w-c:\40d9b26e2a8b3f767a\1040\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0831108----a-w-c:\40d9b26e2a8b3f767a\1041\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0830194----a-w-c:\40d9b26e2a8b3f767a\1042\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0836962----a-w-c:\40d9b26e2a8b3f767a\1043\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0827950----a-w-c:\40d9b26e2a8b3f767a\3076\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0834086----a-w-c:\40d9b26e2a8b3f767a\1025\LocalizedData.xml
2011-03-25 16:08 . 2011-03-25 16:0865160----a-w-c:\40d9b26e2a8b3f767a\ParameterInfo.xml
2011-03-25 16:03 . 2011-03-25 16:035079552----a-w-c:\40d9b26e2a8b3f767a\NDP40-KB2478663.msp
2011-03-25 15:34 . 2011-03-25 15:343628----a-w-c:\40d9b26e2a8b3f767a\header.bmp
2011-03-25 15:34 . 2011-03-25 15:34196662----a-w-c:\40d9b26e2a8b3f767a\SplashScreen.bmp
2011-03-25 15:34 . 2011-03-25 15:3413606----a-w-c:\40d9b26e2a8b3f767a\Strings.xml
2011-03-25 15:34 . 2011-03-25 15:3436180----a-w-c:\40d9b26e2a8b3f767a\UiInfo.xml
2011-03-25 15:34 . 2011-03-25 15:34104072----a-w-c:\40d9b26e2a8b3f767a\watermark.bmp
2011-03-25 15:34 . 2011-03-25 15:34123035----a-w-c:\40d9b26e2a8b3f767a\1025\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34128333----a-w-c:\40d9b26e2a8b3f767a\1028\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34101146----a-w-c:\40d9b26e2a8b3f767a\1029\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34109464----a-w-c:\40d9b26e2a8b3f767a\1030\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:3491719----a-w-c:\40d9b26e2a8b3f767a\1031\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34102048----a-w-c:\40d9b26e2a8b3f767a\1032\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34138595----a-w-c:\40d9b26e2a8b3f767a\1033\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34111176----a-w-c:\40d9b26e2a8b3f767a\1035\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34133172----a-w-c:\40d9b26e2a8b3f767a\1036\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34125351----a-w-c:\40d9b26e2a8b3f767a\1037\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34110879----a-w-c:\40d9b26e2a8b3f767a\1038\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34124974----a-w-c:\40d9b26e2a8b3f767a\1040\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34111958----a-w-c:\40d9b26e2a8b3f767a\1041\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:3435285----a-w-c:\40d9b26e2a8b3f767a\1043\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:3436083----a-w-c:\40d9b26e2a8b3f767a\1044\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34126541----a-w-c:\40d9b26e2a8b3f767a\1045\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34109574----a-w-c:\40d9b26e2a8b3f767a\1046\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:3449319----a-w-c:\40d9b26e2a8b3f767a\1049\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34125073----a-w-c:\40d9b26e2a8b3f767a\1053\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34112947----a-w-c:\40d9b26e2a8b3f767a\1055\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34110754----a-w-c:\40d9b26e2a8b3f767a\2052\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34125196----a-w-c:\40d9b26e2a8b3f767a\2070\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:342060----a-w-c:\40d9b26e2a8b3f767a\3076\eula.rtf
2011-03-25 15:34 . 2011-03-25 15:34108174----a-w-c:\40d9b26e2a8b3f767a\3082\eula.rtf
2011-03-23 20:12 . 2011-03-23 20:1235802----a-w-c:\40d9b26e2a8b3f767a\1033\LocalizedData.xml
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\2070\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\3082\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\2052\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1049\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1053\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1055\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1045\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1046\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4814680----a-w-c:\40d9b26e2a8b3f767a\1042\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818776----a-w-c:\40d9b26e2a8b3f767a\1043\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817240----a-w-c:\40d9b26e2a8b3f767a\1044\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1038\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1040\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4815192----a-w-c:\40d9b26e2a8b3f767a\1041\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1036\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4816216----a-w-c:\40d9b26e2a8b3f767a\1037\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818776----a-w-c:\40d9b26e2a8b3f767a\1032\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4816728----a-w-c:\40d9b26e2a8b3f767a\1033\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1035\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4818264----a-w-c:\40d9b26e2a8b3f767a\1031\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1030\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\1028\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4817752----a-w-c:\40d9b26e2a8b3f767a\1029\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:4813656----a-w-c:\40d9b26e2a8b3f767a\3076\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:48295248----a-w-c:\40d9b26e2a8b3f767a\SetupUi.dll
2011-03-22 18:48 . 2011-03-22 18:4816728----a-w-c:\40d9b26e2a8b3f767a\1025\SetupResources.dll
2011-03-22 18:48 . 2011-03-22 18:48809304----a-w-c:\40d9b26e2a8b3f767a\SetupEngine.dll
2011-03-22 18:48 . 2011-03-22 18:4878152----a-w-c:\40d9b26e2a8b3f767a\Setup.exe
2011-03-22 18:35 . 2011-03-22 18:3516118----a-w-c:\40d9b26e2a8b3f767a\DHtmlHeader.html
2011-03-22 18:35 . 2011-03-22 18:3530120----a-w-c:\40d9b26e2a8b3f767a\SetupUi.xsd
2011-03-22 18:35 . 2011-03-22 18:35144416----a-w-c:\40d9b26e2a8b3f767a\sqmapi.dll
2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\Print.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate1.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate2.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate3.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate4.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate5.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate6.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate7.ico
2011-03-22 18:31 . 2011-03-22 18:31894----a-w-c:\40d9b26e2a8b3f767a\Graphics\Rotate8.ico
2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\Save.ico
2011-03-22 18:31 . 2011-03-22 18:3136710----a-w-c:\40d9b26e2a8b3f767a\Graphics\Setup.ico
2011-03-22 18:31 . 2011-03-22 18:3110134----a-w-c:\40d9b26e2a8b3f767a\Graphics\stop.ico
2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\SysReqMet.ico
2011-03-22 18:31 . 2011-03-22 18:311150----a-w-c:\40d9b26e2a8b3f767a\Graphics\SysReqNotMet.ico
2011-03-22 18:31 . 2011-03-22 18:3110134----a-w-c:\40d9b26e2a8b3f767a\Graphics\warn.ico
.
---- Directory of C:\ef60c58cdd1f56bf95401cfaf20940ef ----
.
2011-07-07 10:00 . 2011-07-07 10:00788---ha-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\$shtdwn$.req
2011-04-13 19:05 . 2011-04-13 19:0537404----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537314----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536962----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536514----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537222----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536738----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536020----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536274----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0527922----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0538958----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536030----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537832----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0532912----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537822----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0537192----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0531108----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0530194----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0534086----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0527950----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536822----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0536050----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0538050----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:0527950----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\LocalizedData.xml
2011-04-13 19:05 . 2011-04-13 19:053628----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\header.bmp
2011-04-13 19:05 . 2011-04-13 19:0567018----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\ParameterInfo.xml
2011-04-13 19:05 . 2011-04-13 19:05196662----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SplashScreen.bmp
2011-04-13 19:05 . 2011-04-13 19:0513606----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Strings.xml
2011-04-13 19:05 . 2011-04-13 19:0536180----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\UiInfo.xml
2011-04-13 19:05 . 2011-04-13 19:05104072----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\watermark.bmp
2011-04-13 19:05 . 2011-04-13 19:05123035----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05128333----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05101146----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05109464----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:0591719----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05102048----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05138595----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05111176----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05133172----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05125351----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05110879----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05124974----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05111958----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05149503----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:0535285----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:0536083----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05126541----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05109574----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:0549319----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05125073----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05112947----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05110754----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05125196----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:052060----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\eula.rtf
2011-04-13 19:05 . 2011-04-13 19:05108174----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\eula.rtf
2011-04-13 18:37 . 2011-04-13 18:3719201024----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\NDP40-KB2518870.msp
2011-04-13 13:12 . 2011-04-13 13:1235802----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\LocalizedData.xml
2011-04-12 21:38 . 2011-04-12 21:3815192----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1041\SetupResources.dll
2011-04-12 21:22 . 2011-04-12 21:2216728----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1025\SetupResources.dll
2011-04-12 21:08 . 2011-04-12 21:0813656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2052\SetupResources.dll
2011-04-12 20:50 . 2011-04-12 20:5013656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1028\SetupResources.dll
2011-04-12 20:50 . 2011-04-12 20:5013656----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3076\SetupResources.dll
2011-04-12 20:36 . 2011-04-12 20:3617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1029\SetupResources.dll
2011-04-12 20:16 . 2011-04-12 20:1617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1030\SetupResources.dll
2011-04-12 20:01 . 2011-04-12 20:0118264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1031\SetupResources.dll
2011-04-12 19:42 . 2011-04-12 19:4218776----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1032\SetupResources.dll
2011-04-12 19:24 . 2011-04-12 19:2418264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\3082\SetupResources.dll
2011-04-12 19:08 . 2011-04-12 19:0817752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1035\SetupResources.dll
2011-04-12 18:51 . 2011-04-12 18:5118264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1036\SetupResources.dll
2011-04-12 18:36 . 2011-04-12 18:3616216----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1037\SetupResources.dll
2011-04-12 18:20 . 2011-04-12 18:2018264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1038\SetupResources.dll
2011-04-12 18:06 . 2011-04-12 18:0617752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1040\SetupResources.dll
2011-04-12 17:49 . 2011-04-12 17:4914680----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1042\SetupResources.dll
2011-04-12 17:31 . 2011-04-12 17:3118776----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1043\SetupResources.dll
2011-04-12 17:17 . 2011-04-12 17:1717240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1044\SetupResources.dll
2011-04-12 17:03 . 2011-04-12 17:0317752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1045\SetupResources.dll
2011-04-12 16:43 . 2011-04-12 16:4317752----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1046\SetupResources.dll
2011-04-12 16:23 . 2011-04-12 16:2318264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\2070\SetupResources.dll
2011-04-12 16:00 . 2011-04-12 16:0018264----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1049\SetupResources.dll
2011-04-12 15:44 . 2011-04-12 15:4417240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1053\SetupResources.dll
2011-04-12 15:23 . 2011-04-12 15:2316728----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1033\SetupResources.dll
2011-04-12 15:23 . 2011-04-12 15:2317240----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\1055\SetupResources.dll
2011-04-12 15:23 . 2011-04-12 15:23809304----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupEngine.dll
2011-04-12 15:23 . 2011-04-12 15:23295248----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupUi.dll
2011-04-12 15:23 . 2011-04-12 15:2378152----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Setup.exe
2011-04-12 15:16 . 2011-04-12 15:1616118----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\DHtmlHeader.html
2011-04-12 15:16 . 2011-04-12 15:1630120----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\SetupUi.xsd
2011-04-12 15:16 . 2011-04-12 15:16144416----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\sqmapi.dll
2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Print.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate1.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate2.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate3.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate4.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate5.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate6.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate7.ico
2011-04-12 13:11 . 2011-04-12 13:11894----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Rotate8.ico
2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Save.ico
2011-04-12 13:11 . 2011-04-12 13:1136710----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\Setup.ico
2011-04-12 13:11 . 2011-04-12 13:1110134----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\stop.ico
2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\SysReqMet.ico
2011-04-12 13:11 . 2011-04-12 13:111150----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\SysReqNotMet.ico
2011-04-12 13:11 . 2011-04-12 13:1110134----a-w-c:\ef60c58cdd1f56bf95401cfaf20940ef\Graphics\warn.ico
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-07-04 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows MEDIA Player\WMPNSCFG.exe" [2008-01-21 202240]
"Registry Repair Wizard Scheduler"="c:\program files\SmartPCTools\Registry Repair Wizard\RCHelper.exe" [2011-04-26 1540480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-26 413696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE" [2011-04-13 1000768]
"SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe" [2011-02-02 70464]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2010-03-24 19:5555552----a-w-c:\windows\System32\avldr.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Feutz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Feutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-01 15:32421160----a-w-c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-10 12:15421888----a-w-c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-11-21 01:151826816----a-w-c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2008-01-30 00:38583048----a-w-c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-02-06 23:25202256----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-08-24 09:38247144----a-w-c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Persistence"=c:\windows\system32\igfxpers.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R0 30587362;30587362 Boot Guard Driver;c:\windows\system32\DRIVERS\30587362.sys

R1 30587361;30587361;c:\windows\system32\DRIVERS\30587361.sys

R1 setup_9.0.0.722_17.06.2011_02-59drv;setup_9.0.0.722_17.06.2011_02-59drv;c:\windows\system32\DRIVERS\3058736.sys

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys

R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys

R3 utkwnty5;AVZ Kernel Driver;c:\windows\system32\Drivers\utkwnty5.sys

S0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot.sys [2010-06-23 26696]
S1 APPFLT;App FILTER Plugin;c:\windows\system32\Drivers\APPFLT.SYS [2011-01-31 83528]
S1 DSAFLT;DSA Filter Plugin;c:\windows\system32\Drivers\DSAFLT.SYS [2009-09-25 53256]
S1 FNETMON;NetMon Filter Plugin;c:\windows\system32\Drivers\fnetmon.SYS [2009-09-25 22024]
S1 IDSFLT;Ids Filter Plugin;c:\windows\system32\Drivers\IDSFLT.SYS [2010-09-09 193864]
S1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\Drivers\NETFLTDI.SYS [2009-09-25 21:54 159112]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm8660.sys [2010-05-21 54344]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2012\PskSvc.exe [2010-08-16 28992]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-08-24 92008]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys

S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 NETIMFLT01060044;PANDA NDIS IM Filter Miniport v1.6.0.44;c:\windows\system32\DRIVERS\neti1644.sys [2010-09-01 201032]
S3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys

S3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys

.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Feutz\AppData\Roaming\Mozilla\Firefox\Profiles\6ut3ou0q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4017210073-3623525190-2501994021-1000\Software\SecuROM\License information*]
"datasecu"=hex:c4,80,29,ed,05,d0,45,d9,29,7e,6a,37,9e,64,ce,c2,e9,37,98,c4,c1,
7a,60,54,48,c8,de,53,bb,04,84,f3,48,bf,48,d0,5c,7b,fb,b9,8f,53,3c,c9,29,d9,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\07\06\09\16\10\02?"
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\TPSrv.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\AVENGINE.EXE
c:\toshiba\IVP\ISM\pinger.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\Firewall\PSHOST.EXE
c:\program files\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\vssvc.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wermgr.exe
.
**************************************************************************
.
Completion time: 2011-07-15 12:35:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-15 19:35
ComboFix2.txt 2011-07-10 16:39
.
Pre-Run: 64,561,160,192 bytes free
Post-Run: 64,469,340,160 bytes free
.
- - End Of File - - 85ABDEECE7410EEEB37B7FDE0D3D8A5DQuote
Sorry it took so long to get back to you I've had more problems with my laptop
What sort of problems?

Quote
I checked the files with jotti and found out that I only have 1 of the files......c:\windows\system32\igxpun.exe
And what did Jotti report about this file?

*********************************************************
Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.
Registry Repair Wizard
There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry.

For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

Further reading: XP Fixes Myth #1: Registry Cleaners
**********************************************************
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::
    DDS::
    Trusted Zone: internet
    Trusted Zone: mcafee.com

    File::
    C:\found.007
    C:\found.006
    C:\found.005
    C:\found.004
    C:\found.003
    C:\found.002
    C:\found.001

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
*******************************************************
I need these files checked. Please show me the results by including the link in your reply.

Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and links posted for each one)

* Copy the file path in the below Code box:

Code: [Select]c:\windows\system32\DRIVERS\30587361.sys
c:\windows\system32\DRIVERS\3058736.sys
* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
278.

Solve : sound and video jittery- suspected malware???

Answer»

Thank you for the Link Dave, I had the laptop apart last week (that was fun!!) and cleaned the fan there wasn't a lot of dust in there tho which surprised me. I am gona have to ask the COMPANY who re-installed for a disc.
thanks for all your work on this matter.Hi Dave I have been TRYING to reinstall windows but it gets to the point of formatting the hard drive and shuts down?? also the disc I have is not suitable for the sfc /scannow as it says it is a different disc. am at a loss here as to what to do?
It WOULD appear that there could be something defective with your harddrive or some other some other component of your COMPUTER. Please try running a diagnostic on your harddrive.

Run hard drive diagnostics: tacktech.com
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For TOSHIBA hard drives, see here:

Note : If you do not know how to set your computer to boot from CD follow the steps here

279.

Solve : Malware Issues - PE_Perfect pecompact TR/SPy.Keylogger.qme?

Answer»

That looks great. Just one more scan.

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program REQUESTS permission from dig.exe to access the Internet, allow it to do so.
Results of screen317's Security Check version 0.99.18
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
ESET Online Scanner v3
Microsoft Security Essentials
WMI entry may not exist for antivirus; attempting AUTOMATIC update.
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

MVPS Hosts File
Malwarebytes' Anti-Malware
Wise Disk Cleaner 5.93
Wise Registry Cleaner 5.9.4
Java(TM) 6 Update 26
Flash Player Out of Date!
Adobe Flash Player 10.0.45.2
Adobe Reader X (10.1.0)
Mozilla Firefox (X86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````
thank you Dave. I have 2 more machines showing same types of problems. Can I run their logs with you to look at and resolve. Thank you again for your help!The Security Check shows two Anti-Virus programs on your computer; Avira AntiVir Personal and Microsoft Security Essentials
If more that one AV program is active on a computer it can cause conflicts.

Quote

thank you Dave. I have 2 more machines showing same types of problems. Can I run their logs with you to look at and resolve. Thank you again for your help!
You should start a new thread for each computer otherwise, it's too confusing.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
******************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, SPYWARE, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest IMMUNIZATIONS always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
280.

Solve : unregistered files?

Answer»

Hi there
Yes I used the removal tool and I've just finished doing the other housekeeping you suggested in an earlier message (28 July). Take your point about programs re-installing though I did wonder if I buy McAfee online and it recognises that the program's been removed (which it did) and I still have 240 days of my subscription left it wilol try to re-install - I guess I should ask McAfee that question huh?

Anyway, after a clean cold start yesterday and today, once I got into cleaning and so on the first reboot (after running TFC) I did brought up the same old messages. I've still to do the OTL so we'll see what that pushes out.

Thanks

Alexokay, done the OTL scan and the reports as follows - OTL.Txt first:

OTL logfile created on: 07/08/2011 14:53:35 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.36 Mb Total Physical Memory | 409.29 Mb Available Physical Memory | 39.99% Memory free
2.31 Gb Paging File | 1.64 Gb Available in Paging File | 70.84% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.71 Gb Total Space | 89.63 Gb Free Space | 49.60% Space Free | Partition Type: NTFS
Drive D: | 5.58 Gb Total Space | 0.55 Gb Free Space | 9.84% Space Free | Partition Type: FAT32
Drive E: | 3.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-C94F920E24 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcupdate.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe ()
PRC - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe (Cyberlink)
PRC - C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll (Microsoft Corporation)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) -- File not found
SRV - (AppMgmt) -- File not found
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (a2AntiMalware) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (UMVPFSrv) -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (MSK80Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (MOBKbackup) -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (CLSched) CyberLink Task Scheduler (CTS) -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe ()
SRV - (CLCapSvc) CyberLink Background Capture Service (CBCS) -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe ()
SRV - (CyberLink Media Library Service) -- C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe (Cyberlink)
SRV - (EPSONStatusAgent2) -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (a2acc) -- C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys (Emsi Software GmbH)
DRV - (MREMP50) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (LVUVC) Logitech Webcam Pro 9000(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) -- C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) -- C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (LUsbFilt) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) -- C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (MOBKFilter) -- C:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (NWADI) -- C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort) -- C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) -- C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) -- C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (alcaudsl) -- C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) -- C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON)
DRV - (RTPP2K) -- C:\WINDOWS\system32\drivers\rtpp2k.sys (Shuttle Technology.)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/cs/*http://uk.docs.yahoo.com/info/bt_side.html

IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginen ame: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enable d: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/webhp?hl=en&source=hp&btnG=Google+Search"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [emailprotected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {73e1e35c-27c2-44c5-90fa-cf9da6cbfec3}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {b9452a5b-916c-404f-8479-850185ae13bc}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/12 09:55:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/08/04 14:45:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/22 15:57:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/16 10:35:12 | 000,000,000 | ---D | M]

[2009/10/31 14:05:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Extensions
[2009/03/06 00:37:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Extensions\[emailprotected]
[2011/08/05 10:49:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions
[2011/08/05 10:49:36 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/06/22 17:28:16 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\searchplugins\askcom.xml
[2010/10/01 22:31:36 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\searchplugins\bing.xml
[2010/10/01 22:12:25 | 000,005,471 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\searchplugins\googlecom-in-english.xml
[2011/07/21 22:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/27 15:54:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/02 14:55:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 21:03:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/27 11:37:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/27 10:32:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/21 22:50:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\HP_OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\JVO1QB88.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/07/21 22:50:11 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/27 10:51:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/06/22 15:57:46 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2011/07/21 22:50:09 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/08/24 11:08:35 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/07/26 12:53:07 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110803101551.dll (McAfee, Inc.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Download ENERGY Toolbar) - {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Download Energy Toolbar) - {AD708C09-D51B-45B3-9D28-4EBA2681FEBF} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [ftutil2] C:\WINDOWS\System32\ftutil2.dll (Promise Technology, Inc.)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [EPSON PX820FWD Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGXE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled [2011/07/16 10:31:49 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: CONNECTION Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199112852312 (MUWebControl Class)
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} http://secure2.comned.com/signuptemplates/securelogin-devel.cab (SecureLogin class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://uk.games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/06 00:32:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2005/02/25 18:24:46 | 000,000,051 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/07 14:49:16 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/08/07 11:29:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/08/07 11:17:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/08/05 10:47:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/08/05 10:43:46 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/08/05 10:43:29 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/08/05 10:43:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/05 10:34:58 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/08/05 10:22:26 | 081,496,432 | ---- | C] (Apple Inc.) -- C:\Program Files\iTunesSetup.exe
[2011/08/05 10:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/08/05 10:17:20 | 037,806,960 | ---- | C] (Apple Inc.) -- C:\Program Files\SafariSetup.exe
[2011/08/05 10:12:57 | 000,909,600 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u26-windows-i586-iftw.exe
[2011/08/05 10:11:42 | 003,124,384 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files\install_flash_player_ax.exe
[2011/08/05 09:13:47 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Program Files\TFC.exe
[2011/08/04 20:01:09 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/08/04 09:37:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/08/03 10:17:53 | 000,000,000 | ---D | C] -- C:\Program Files\McAfeeMOBK
[2011/08/03 10:17:39 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Online Backup
[2011/08/03 10:17:38 | 000,054,776 | ---- | C] (Mozy, Inc.) -- C:\WINDOWS\System32\drivers\MOBK.sys
[2011/08/03 10:17:31 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Online Backup
[2011/08/03 10:15:50 | 000,009,344 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeclnk.sys
[2011/08/03 10:15:46 | 000,089,368 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2011/08/03 10:00:22 | 000,085,984 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys
[2011/08/03 10:00:22 | 000,083,688 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfendisk.sys
[2011/08/03 10:00:21 | 000,337,912 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfefirek.sys
[2011/08/03 10:00:21 | 000,179,248 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/08/03 10:00:21 | 000,059,288 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/08/03 10:00:21 | 000,057,432 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\cfwids.sys
[2011/08/03 10:00:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mcafee
[2011/08/03 10:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2011/08/03 09:59:32 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2011/08/03 09:58:24 | 000,148,520 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\mfevtps.exe
[2011/08/02 11:00:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/07/26 23:50:49 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/07/26 23:50:11 | 002,322,184 | ---- | C] (ESET) -- C:\Documents and Settings\HP_Owner\Desktop\esetsmartinstaller_enu.exe
[2011/07/26 14:32:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\SysProt
[2011/07/26 14:23:55 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/07/26 12:50:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/07/25 14:47:38 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\HP_Owner\PrivacIE
[2011/07/25 13:53:37 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\HP_Owner\IETldCache
[2011/07/25 13:49:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011/07/25 13:44:57 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/07/25 13:38:41 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/07/25 09:51:51 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/07/25 09:45:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/07/22 00:53:23 | 000,000,000 | ---D | C] -- C:\Program Files\Dial-a-fix-v0.60.0.24
[2011/07/21 22:58:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Start Menu\Programs\HiJackThis
[2011/07/21 22:58:39 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/07/21 22:50:27 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/07/21 22:50:27 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/07/21 22:50:27 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/07/21 22:50:27 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2011/07/21 15:53:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HP_Owner\Recent
[2011/07/12 15:52:05 | 000,008,192 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\E_DCINST.DLL
[2011/07/12 15:51:58 | 000,093,696 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FLBGXE.DLL
[2011/07/12 15:51:58 | 000,063,488 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FD4BGXE.DLL
[2011/07/12 15:46:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\UDL
[2011/07/12 15:39:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\Epson
[2011/07/12 15:38:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Epson Software
[2011/07/12 15:38:38 | 000,000,000 | ---D | C] -- C:\Program Files\Epson Software
[2011/07/12 15:38:15 | 000,475,410 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\ensppmon.dll
[2011/07/12 15:38:15 | 000,458,129 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\ensppui.dll
[2011/07/12 15:38:15 | 000,249,344 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\enspres.dll
[2011/07/12 15:38:14 | 000,475,410 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\enppmon.dll
[2011/07/12 15:38:14 | 000,458,129 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\enppui.dll
[2011/07/12 15:38:14 | 000,249,344 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\enpres.dll
[2011/07/12 15:38:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\InstallShield
[2011/07/12 15:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet
[2011/07/12 15:34:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2011/07/12 15:34:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\EPSON
[2011/07/12 15:34:11 | 000,342,016 | ---- | C] (Seiko Epson Corporation) -- C:\WINDOWS\System32\eswiaud.dll
[2011/07/12 15:34:11 | 000,132,560 | ---- | C] (Seiko Epson Corporation) -- C:\WINDOWS\System32\esdevapp.exe
[2011/07/12 15:34:11 | 000,012,800 | ---- | C] (Seiko Epson Corporation) -- C:\WINDOWS\System32\escdev.dll
[2011/07/12 11:20:54 | 000,178,536 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\dnssdX.dll
[2011/07/12 11:20:54 | 000,083,816 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\dns-sd.exe
[2011/07/12 11:20:54 | 000,073,064 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\dnssd.dll
[2010/08/11 10:14:24 | 003,887,480 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Program Files\procexp.exe
[2010/02/20 23:05:43 | 000,559,992 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Program Files\autorunsc.exe
[2009/11/24 14:22:22 | 018,665,720 | ---- | C] (Lime Wire LLC) -- C:\Program Files\LimeWireWin.exe
[2009/07/07 13:05:47 | 000,401,484 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcrtd.dll
[2009/03/12 16:43:33 | 001,971,378 | ---- | C] (LIGHTNING UK!) -- C:\Program Files\SetupImgBurn_2.4.2.0.exe
[2009/02/22 22:35:19 | 003,171,208 | ---- | C] (Piriform Ltd) -- C:\Program Files\ccsetup216.exe
[2009/02/21 14:50:17 | 018,638,688 | ---- | C] (PC Tools ) -- C:\Program Files\sdsetup.exe
[2009/01/03 21:33:47 | 006,832,928 | ---- | C] (ESTsoft Corp. ) -- C:\Program Files\alzip.exe
[2009/01/03 18:33:23 | 008,973,608 | ---- | C] (M.Dev Software ) -- C:\Program Files\zg603sui.exe
[2008/12/09 16:01:50 | 004,399,029 | ---- | C] (Joseph Leung ) -- C:\Program Files\quickzip.exe
[2008/07/09 12:27:25 | 000,820,380 | ---- | C] ( ) -- C:\Program Files\audacity-win-1.2.6.exe
[1 C:\Documents and Settings\HP_Owner\Desktop\*.tmp files -> C:\Documents and Settings\HP_Owner\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\HP_Owner\*.tmp files -> C:\Documents and Settings\HP_Owner\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/07 14:49:17 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/08/07 14:22:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/07 12:19:48 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1157552183-2752306718-432289623-1008.job
[2011/08/07 12:19:47 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1157552183-2752306718-432289623-1008.job
[2011/08/07 11:47:53 | 000,000,188 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2011/08/07 11:29:06 | 000,001,606 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/08/07 11:12:43 | 000,186,910 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/08/07 11:12:41 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/07 11:12:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/07 11:12:31 | 1073,139,712 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/07 11:12:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/08/06 10:23:48 | 000,001,824 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/08/05 10:47:11 | 000,001,553 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/05 10:33:09 | 000,092,776 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/08/05 10:29:01 | 081,496,432 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunesSetup.exe
[2011/08/05 10:28:24 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/08/05 10:28:24 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/08/05 10:21:31 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/05 10:20:11 | 037,806,960 | ---- | M] (Apple Inc.) -- C:\Program Files\SafariSetup.exe
[2011/08/05 10:12:58 | 000,909,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u26-windows-i586-iftw.exe
[2011/08/05 10:12:04 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/05 10:11:43 | 003,124,384 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\install_flash_player_ax.exe
[2011/08/05 09:13:48 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Program Files\TFC.exe
[2011/07/27 03:03:10 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/07/26 23:50:12 | 002,322,184 | ---- | M] (ESET) -- C:\Documents and Settings\HP_Owner\Desktop\esetsmartinstaller_enu.exe
[2011/07/26 12:53:07 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/25 14:47:12 | 000,000,678 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to iexplore.lnk
[2011/07/25 09:51:59 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/07/22 17:21:08 | 000,002,397 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\PagePlus 11 (2).lnk
[2011/07/22 01:00:46 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/07/22 01:00:46 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/07/22 00:53:42 | 000,000,765 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to Dial-a-fix-v0.60.0.24.lnk
[2011/07/21 23:01:00 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to sniper.exe.lnk
[2011/07/21 22:59:30 | 000,000,544 | ---- | M] () -- C:\WINDOWS\zipgenius.xml
[2011/07/21 22:50:07 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/07/21 22:50:07 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/07/21 22:50:06 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/07/21 22:50:06 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2011/07/21 22:50:05 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2011/07/21 15:44:39 | 000,000,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/07/14 10:02:10 | 000,405,512 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 19:30:11 | 000,000,000 | ---- | M] () -- C:\WINDOWS\EEventManager.INI
[2011/07/12 15:46:56 | 000,001,819 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Epson Easy Photo Print.lnk
[2011/07/12 15:44:14 | 000,000,306 | ---- | M] () -- C:\WINDOWS\setup.iss
[2011/07/12 15:40:04 | 000,000,559 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Print CD.lnk
[2011/07/12 15:36:09 | 000,001,910 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EPSON PX820FWD Series Network Guide.lnk
[2011/07/12 15:35:50 | 000,001,910 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EPSON PX820FWD Series Manual.lnk
[2011/07/12 15:34:13 | 000,000,676 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EPSON Scan.lnk
[2011/07/12 11:20:54 | 000,178,536 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\dnssdX.dll
[2011/07/12 11:20:54 | 000,083,816 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\dns-sd.exe
[2011/07/12 11:20:54 | 000,073,064 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\dnssd.dll
[1 C:\Documents and Settings\HP_Owner\Desktop\*.tmp files -> C:\Documents and Settings\HP_Owner\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\HP_Owner\*.tmp files -> C:\Documents and Settings\HP_Owner\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/05 10:47:11 | 000,001,553 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/05 10:33:09 | 000,092,776 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/08/05 10:28:24 | 000,002,193 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
[2011/08/05 10:28:24 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/08/05 10:21:31 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/03 10:18:43 | 000,001,606 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/07/30 10:17:53 | 000,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/30 10:17:52 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/25 14:47:12 | 000,000,678 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to iexplore.lnk
[2011/07/25 13:47:14 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/07/22 00:53:42 | 000,000,765 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to Dial-a-fix-v0.60.0.24.lnk
[2011/07/21 23:00:59 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Shortcut to sniper.exe.lnk
[2011/07/13 19:30:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2011/07/12 15:46:56 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Epson Easy Photo Print.lnk
[2011/07/12 15:44:05 | 000,000,306 | ---- | C] () -- C:\WINDOWS\setup.iss
[2011/07/12 15:40:04 | 000,000,559 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Print CD.lnk
[2011/07/12 15:36:09 | 000,001,910 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EPSON PX820FWD Series Network Guide.lnk
[2011/07/12 15:35:50 | 000,001,910 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EPSON PX820FWD Series Manual.lnk
[2011/07/12 15:34:13 | 000,000,676 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EPSON Scan.lnk
[2011/06/30 12:45:50 | 000,223,176 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/06/25 10:01:22 | 000,333,018 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/04/25 16:17:14 | 000,014,848 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/22 23:58:22 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2010/10/19 16:51:50 | 014,709,760 | ---- | C] () -- C:\Program Files\ClassActionKillers.msi
[2010/10/01 17:16:03 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Uzagefu.dat
[2010/10/01 17:16:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Jdebecusuramu.bin
[2010/08/11 10:14:24 | 000,072,268 | ---- | C] () -- C:\Program Files\procexp.chm
[2010/05/14 22:56:06 | 010,877,272 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2010/05/14 22:56:06 | 000,102,744 | ---- | C] () -- C:\WINDOWS\System32\LogiDPPApp.exe
[2010/05/14 22:55:58 | 000,331,608 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2010/05/07 18:43:30 | 000,025,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2010/02/08 07:33:04 | 000,359,320 | ---- | C] () -- C:\WINDOWS\System32\vfprintpthelper.dll
[2009/10/01 11:07:58 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\setup_ldm.iss
[2009/09/30 12:27:14 | 005,486,113 | ---- | C] () -- C:\Program Files\DarkWave-Studio-2.4.exe
[2009/08/31 14:00:22 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\WBCustomizer.dll
[2009/08/31 14:00:21 | 000,185,344 | ---- | C] () -- C:\WINDOWS\System32\MemWarp.dll
[2009/08/25 15:22:36 | 015,436,399 | ---- | C] () -- C:\Program Files\F1_v1.3.zip
[2009/08/25 15:16:29 | 091,959,937 | ---- | C] () -- C:\Program Files\Avert Fate.zip
[2009/07/10 01:19:49 | 347,928,562 | ---- | C] () -- C:\Program Files\sauerbraten_2009_05_04_trooper_edition_win32_setup.exe
[2009/07/07 13:05:47 | 000,172,032 | ---- | C] () -- C:\Program Files\libpng13.dll
[2009/07/07 13:05:46 | 000,045,056 | ---- | C] () -- C:\Program Files\Launcher.exe
[2009/05/13 12:13:24 | 001,271,001 | ---- | C] () -- C:\Program Files\Lame-Front-End.zip
[2009/04/12 20:22:29 | 006,237,728 | ---- | C] () -- C:\Program Files\SUPERAntiSpyware.exe
[2009/03/20 13:20:38 | 000,000,573 | ---- | C] () -- C:\Program Files\xp_system32opens.vbs
[2009/02/10 20:20:54 | 000,748,688 | ---- | C] () -- C:\Program Files\cpukil305.zip
[2009/01/30 19:13:44 | 001,053,744 | ---- | C] () -- C:\Program Files\revosetup.exe
[2009/01/23 20:51:09 | 000,189,810 | ---- | C] () -- C:\Program Files\libmp3lame-win-3.98.2.zip
[2009/01/03 18:40:29 | 000,939,698 | ---- | C] () -- C:\Program Files\7z464.exe
[2008/12/14 20:56:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\galaxy.ini
[2008/12/12 18:31:59 | 000,000,471 | ---- | C] () -- C:\Program Files\FILE_ID.DIZ
[2008/12/09 20:25:45 | 000,007,804 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/12/09 19:52:39 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2008/12/09 16:03:51 | 000,001,143 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\QuickZip45.ini
[2008/12/03 18:45:24 | 020,768,389 | ---- | C] () -- C:\Program Files\DN3DInst.zip
[2008/07/06 16:17:05 | 000,000,591 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2008/07/02 12:04:10 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/05/17 01:31:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/17 01:31:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/05/17 01:31:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/05/17 01:31:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/05/17 01:31:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/05/17 01:31:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/05/17 01:31:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/05/17 01:31:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/05/17 01:31:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/05/14 17:17:55 | 000,000,223 | ---- | C] () -- C:\WINDOWS\HP PrecisionScan Pro.INI
[2008/04/01 17:34:30 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2008/03/21 21:01:18 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/03/21 19:31:27 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2008/03/21 18:56:14 | 000,005,607 | R--- | C] () -- C:\WINDOWS\System32\stci.dll
[2008/03/21 17:54:34 | 000,116,736 | ---- | C] () -- C:\WINDOWS\Uninstall_Livebox.EXE
[2008/01/30 22:39:58 | 000,005,495 | ---- | C] () -- C:\Program Files\0x0409.ini
[2007/12/31 15:45:05 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/05/11 16:12:54 | 000,027,872 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/04/27 10:43:58 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2006/06/05 20:14:40 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/05 19:53:15 | 000,028,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006/06/05 19:49:40 | 000,013,561 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006/06/05 19:49:33 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006/06/05 19:45:45 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2006/06/05 19:42:54 | 000,000,102 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/06/05 19:38:07 | 000,080,417 | ---- | C] () -- C:\WINDOWS\HPHins08.dat
[2006/06/05 19:38:07 | 000,004,011 | ---- | C] () -- C:\WINDOWS\hphmdl08.dat
[2006/06/05 19:36:57 | 000,090,686 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2006/06/05 19:36:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpimdl01.dat
[2006/06/05 19:27:20 | 000,095,822 | ---- | C] () -- C:\WINDOWS\hpqins69.dat
[2006/06/05 19:26:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/06/05 19:23:26 | 000,121,994 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/06/05 19:08:43 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/06/05 19:05:18 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2006/06/05 19:05:18 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2006/06/05 19:04:54 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2006/03/18 01:23:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/12/06 00:49:08 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/12/06 00:36:34 | 000,506,376 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/12/06 00:36:34 | 000,088,978 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/12/06 00:34:46 | 000,405,512 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/12/06 00:31:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/06 00:30:02 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 12:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/06/24 20:10:06 | 000,000,567 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 23:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 23:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/07/06 22:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2000/09/14 03:03:00 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[2000/08/11 07:00:00 | 000,030,208 | ---- | C] () -- C:\WINDOWS\System32\EPIPPJ50.DLL
[2000/04/14 17:50:02 | 000,343,040 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[1998/06/11 13:08:06 | 000,095,232 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
[1996/04/03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/08/04 09:37:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/07/12 15:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2009/10/24 16:16:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HighAndes
[2011/05/16 00:57:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/04/01 18:01:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/03/21 02:21:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/06/25 19:20:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonEU
[2008/11/12 20:41:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2008/07/20 11:03:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\O2CM-CE
[2008/02/02 17:06:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spearit
[2011/05/24 13:39:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/12 15:46:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2008/05/15 01:44:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uniblue
[2011/08/05 10:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/13 14:29:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/05/12 15:22:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2009/06/19 00:02:16 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2011/03/21 02:21:27 | 000,000,288 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3DFE6FE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
And the Extras.Txt as follows:

OTL Extras logfile created on: 07/08/2011 14:53:35 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.36 Mb Total Physical Memory | 409.29 Mb Available Physical Memory | 39.99% Memory free
2.31 Gb Paging File | 1.64 Gb Available in Paging File | 70.84% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.71 Gb Total Space | 89.63 Gb Free Space | 49.60% Space Free | Partition Type: NTFS
Drive D: | 5.58 Gb Total Space | 0.55 Gb Free Space | 9.84% Space Free | Partition Type: FAT32
Drive E: | 3.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-C94F920E24 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Vid\Vid.exe" = C:\Program Files\Logitech\Vid\Vid.exe:*:Enabled:Logitech Vid HD -- (Logitech Inc.)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe" = C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application -- (SEIKO EPSON CORPORATION)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host -- (McAfee, Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0B884C9B-5D85-4461-88EE-826E1BB33008}" = Serif PagePlus 11
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}" = TrayApp
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{190D0C6E-C8A7-4019-8FB5-FD041EC1F2D2}" = Mobile Broadband Drivers
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1E1F1E70-14D8-4380-8652-BD1A895A7D65}" = Status
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = PowerCinema
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26
"{27C467F8-F8EF-4f68-BD72-D63632B2096C}" = McAfee Online Backup
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{310C1558-F6B5-4889-98B0-7471966BA7F2}" = Epson Easy Photo Print 2
"{31263605-FC84-4787-B847-BA445B147E24}" = ScannerCopy
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352F5013-07DC-446D-8DB6-38F339086C60}" = LightScribe 1.4.84.1
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{370187B9-6964-38D0-851F-6C4898B0C2B1}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{37AC7F94-2C0C-3DFF-8039-4B6AB79150D0}" = Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools
"{39556553-8C77-4C5E-8F30-4083274948A2}" = Application Verifier
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3CF99DC3-38FD-46E6-A6B4-9C70074E020C}" = DocumentViewer
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3FADAA19-E595-44CA-A072-58B6B0851768}" = Norton Security Scan
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{44A91B04-3D0C-47F9-B644-7F682869AFF3}" = MobileMe Control Panel
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{492E1D84-D7BF-4FA2-A26A-30AFC89EF547}" = Tiger Woods PGA TOUR 2003
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB5EAF2-E5D8-4A2B-864B-D72B37A9DD51}" = PCmover
"{4B509F1E-BEA7-3D0E-BE94-3BBF85E8D698}" = Microsoft Windows SDK .NET Framework Tools (30514)
"{4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}" = SolutionCenter
"{4F30BC2B-5441-3149-91D7-FAA2332E2F5F}" = Microsoft Windows SDK for Windows 7 Headers and Libraries (30514)
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5CFD7508-7774-48FE-8280-7A3C0AE71755}" = Internet Services
"{5D61626A-BD55-4e42-82EE-4AE89D8FD050}" = HP Photosmart Cameras 6.0
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{699C970F-1E17-3CD8-A2EA-87AB9EDEDFF4}" = Microsoft Windows SDK for Windows 7 Samples (30514)
"{6A118C80-B382-41c0-8907-CDD0BF5EFE6E}" = CameraDrivers
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{729DF902-05F9-4C00-9E6D-411119824E5F}" = hpiCamDrvQFolder
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AFFE35D-047A-3D27-B204-1CD849933C02}" = Microsoft Windows SDK for Windows 7 Common Utilities (30514)
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{85C977FB-2A5B-3223-8AC5-828558EAF7D9}" = Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514)
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8F1A20DC-251D-47B0-91B7-DCA2523EE6C9}" = McAfee Virtual Technician
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{928D2FB1-291A-362B-89A4-7075A9D904A4}" = Microsoft Windows SDK for Windows 7 (7.1)
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A9C11FA-AE85-3B48-86BE-5FA83D0384B3}" = Microsoft Windows SDK Intellisense and Reference Assemblies (30514)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{ABBA0799-F982-414C-9A8B-17EB03D39677}" = trakAxPC
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.5
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B2395631-54D5-481E-B9A8-74B269546F40}" = Visual C++ CRT 8.0
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B7072091-4582-396F-87E2-412C85AC7095}" = Microsoft Windows SDK MSHelp (30514)
"{B9DD2DE0-27BE-4e6b-AAD8-0D960ABF87FD}" = CameraUserGuides
"{BF4E9ED0-EF26-4A4C-A123-6A6A1ABEE411}" = DocProc
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C617EC41-9E21-3915-AA7E-F156B74F7D07}" = Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514)
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{C98E8D9D-21DE-4F87-A9B7-142BB89840FC}" = Toolbox
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD1067C8-1AA1-4503-BCAD-EA1EE5427DC7}" = MAGIX Video easy SE
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFF4500E-C5D6-695D-A027-B3D4DDED2CC3}" = McAfee Online Backup
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D09605BE-5587-4B0C-86C8-69B5092CB80F}" = Debugging Tools for Windows (x86)
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = SpeedTouch USB Software
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DEBB2986-15B0-4D28-95FA-5C966A396589}" = HPProductAssistant
"{E4197D6B-F046-33E7-ABDE-51FF373FDC76}" = Windows SDK IntellisenseNFX
"{E5A1DE9A-A21C-43A1-B06D-5146BAF62033}" = PanoStandAlone
"{E7F9E526-2324-437B-A609-E8C5309465CB}" = Microsoft Windows Performance Toolkit
"{EA4FA30B-7321-4428-90E9-28B088EC8DC9}" = Runtime 8.0 Libraries
"{EC2715CE-C182-483C-84CC-81D7D914CF14}" = WebReg
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1" = ZipGenius 6 (6.0.3.1150)
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask MAKER
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"7-Zip" = 7-Zip 4.64
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"ALUpdate_is1" = ALTools Update
"ALZip_is1" = ALZip
"ATI Display Driver" = ATI Display Driver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"BT Broadband Desktop Help" = BT Broadband Desktop Help
"BT Wireless Connection Manager" = BT Wireless Connection Manager
"BT Yahoo! Applications" = BT Yahoo! Applications
"BTHomeHub" = BTHomeHub
"CCleaner" = CCleaner
"CleanMem1.3.0" = CleanMem
"Combat Arms EU" = Combat Arms EU
"conduitEngine" = Conduit Engine
"Cube" = Cube
"Download_Energy Toolbar" = Download_Energy Toolbar
"Emsisoft Anti-Malware_is1" = Emsisoft Anti-Malware 5.1
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON PX820FWD Series" = EPSON PX820FWD Series Printer Uninstall
"EPSON PX820FWD Series Manual" = EPSON PX820FWD Series Manual
"EPSON PX820FWD Series Network Guide" = EPSON PX820FWD Series Network Guide
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"ffdshow_is1" = ffdshow [rev 1900] [2008-03-15]
"Google Chrome" = Google Chrome
"HP Document Viewer" = HP Document Viewer 6.1
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photo Printing Software" = HP Photo Printing Software
"HP Solution Center & Imaging Support Tools" = HP Solution Center and Imaging Support Tools 6.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{5CFD7508-7774-48FE-8280-7A3C0AE71755}" = Internet Services
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Jardinains 2!_is1" = Jardinains 2!
"LMMS 0.4.5" = Linux MultiMedia Studio (LMMS)
"MAGIX_MSI_Video_easy_SE" = MAGIX Video easy SE
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Mozilla Firefox 5.0 (x86 en-GB)" = Mozilla Firefox 5.0 (x86 en-GB)
"MSC" = McAfee Internet Security
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 12.0" = RealPlayer
"Recordpad" = RecordPad Sound Recorder
"Revo Uninstaller" = Revo Uninstaller 1.92
"SDKSetup_7.1.7600.0.30514" = Microsoft Windows SDK for Windows 7 (7.1)
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.1
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.10
"WavePad" = WavePad Sound Editor
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Ziepod_is1" = Ziepod version 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 05/08/2011 04:44:16 | Computer Name = YOUR-C94F920E24 | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 05/08/2011 04:44:16 | Computer Name = YOUR-C94F920E24 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 05/08/2011 12:51:15 | Computer Name = YOUR-C94F920E24 | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 05/08/2011 12:51:15 | Computer Name = YOUR-C94F920E24 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 05/08/2011 12:51:54 | Computer Name = YOUR-C94F920E24 | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007041f.

Error - 06/08/2011 04:56:47 | Computer Name = YOUR-C94F920E24 | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 06/08/2011 04:56:47 | Computer Name = YOUR-C94F920E24 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 06/08/2011 20:18:07 | Computer Name = YOUR-C94F920E24 | Source = Application Error | ID = 1000
Description = Faulting application gta_sa.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x6567696c.

Error - 07/08/2011 06:12:57 | Computer Name = YOUR-C94F920E24 | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 07/08/2011 06:12:57 | Computer Name = YOUR-C94F920E24 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ System Events ]
Error - 30/06/2011 07:02:06 | Computer Name = YOUR-C94F920E24 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 30/06/2011 07:02:06 | Computer Name = YOUR-C94F920E24 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 30/06/2011 07:02:43 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10010
Description = The server {4EB61BAC-A3B6-4760-9581-655041EF4D69} did not register
with DCOM within the required timeout.

Error - 30/06/2011 07:04:57 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10010
Description = The server {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A} did not register
with DCOM within the required timeout.

Error - 30/06/2011 07:17:06 | Computer Name = YOUR-C94F920E24 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 30 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 30/06/2011 07:17:06 | Computer Name = YOUR-C94F920E24 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 30 minutes. NtpClient has no source of accurate
time.

Error - 12/07/2011 05:18:02 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10010
Description = The server {4EB61BAC-A3B6-4760-9581-655041EF4D69} did not register
with DCOM within the required timeout.

Error - 17/07/2011 03:31:08 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10010
Description = The server {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C} did not register
with DCOM within the required timeout.

Error - 03/08/2011 11:38:06 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10010
Description = The server {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C} did not register
with DCOM within the required timeout.

Error - 05/08/2011 12:51:54 | Computer Name = YOUR-C94F920E24 | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service VSS with arguments
"" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}


< End of report >
AVENGER

  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
  • Click the Execute button.
  • You will be asked No script has been entered. Do you want to execute a rootkit scan only?.
  • Click Yes.
  • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
  • Please post this log in your next reply.
This doesn't look very dramatic:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Completed script processing.

*******************
Please do this in the following order. Please download, install and activate MicroSoft Security Essentials from the link below. Then remove McAfee using the tool below and see if you're still getting the error message.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
Microsoft Security Essentials for Windows XP

Download the McAfee Consumer Product Removal Tool to your Desktop.

Using McAfee Consumer Product Removal tool:

* Double click the MCPR.exe
* A Command Line window will be displayed, and then close automatically.
* Wait for a second Command Line window to be displayed.

Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.

* After the second window appears, the program will begin the cleanup.
* Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
* Press Y on the keyboard.
* Wait for the computer to restart.
* All McAfee products are now removed from your computer.
Done and the reboot produced no repeat of the FP message.
Too much to do today to stop and start but expect a cold start to have the same result. As I think you have too, I've come to the conclusion the problem has resided somewhere in McAfee. We shall see!

Thanks again.

AlexSince last job I've been getting explorer.exe using up between 40-50% of CPU all the time - I'm sure this isn't normal. Any thoughts and suggestions to fix?Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
Click on View > Select Colunms.
In addition to already pre-selected options, make sure, the Command Line is selected, and press OK.
Go File>Save As, and save the report as Procexp.txt.
Attach the file to your next reply.I already run process explorer - it's more user friendly and detailed than Task Manager. However, as with many diagnostic type tools, I never get round to fully utilising the features available. So I'm glad to have this passed on - thanks.

Here's the data:

ProcessPIDCPUPrivate BytesWorking SetDescriptionCompany NameCommand Line
System Idle Process047.690 K28 K
Interruptsn/a0 K0 KHardware Interrupts
DPCsn/a0 K0 KDeferred Procedure Calls
System40 K140 K
smss.exe444204 K116 KWindows NT Session ManagerMicrosoft Corporation\SystemRoot\System32\smss.exe
csrss.exe5081,860 K2,756 KClient Server Runtime ProcessMicrosoft CorporationC:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
winlogon.exe5326,656 K2,604 KWindows NT Logon APPLICATIONMICROSOFT Corporationwinlogon.exe
services.exe5760.771,932 K2,244 KServices and Controller appMicrosoft CorporationC:\WINDOWS\system32\services.exe
a2service.exe74815,736 K440 KEmsisoft Anti-Malware ServiceEmsi Software GmbH"C:\Program Files\Emsisoft Anti-Malware\a2service.exe"
svchost.exe8363,228 K1,828 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k DcomLaunch
hpgs2wnf.exe1912964 K440 Khpgs2wnf ModuleC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe -Embedding
svchost.exe9322,000 K2,284 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k rpcss
MsMpEng.exe972170,924 K48,428 KAntimalware Service ExecutableMicrosoft Corporation"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
svchost.exe100819,816 K25,812 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe10802,100 K2,168 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k NetworkService
svchost.exe11643,400 K1,212 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService
spoolsv.exe12764,508 K1,960 KSpooler SubSystem AppMicrosoft CorporationC:\WINDOWS\system32\spoolsv.exe
UMVPFSrv.exe13081,616 K140 KLogitech User mode UMVPF serviceLogitech Inc."C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe"
svchost.exe5121,400 K784 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService
SASCORE.EXE868732 K212 KCore ServiceSUPERAntiSpyware.com"C:\Program Files\SUPERAntiSpyware\SASCORE.EXE"
mDNSResponder.exe1436984 K1,064 KBonjour ServiceApple Inc."C:\Program Files\Bonjour\mDNSResponder.exe"
CLCapSvc.exe14485,944 K848 KCLCapSvc Module"C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe"
CLMLServer.exe15088,664 K1,080 KNT CLMLServerCyberlink"C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe"
SAgent2.exe15801,764 K484 KEPSON Printer Status AgentSEIKO EPSON CORPORATION"C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe"
jqs.exe17688,816 K1,380 KJava(TM) Quick Starter ServiceSun Microsystems, Inc."C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
LSSrvc.exe1596632 K140 KHewlett-Packard Company"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
McciCMService.exe22642,036 K1,432 Kmcci+McciCMServiceAlcatel-Lucent"C:\Program Files\Common Files\Motive\McciCMService.exe"
MDM.EXE2284964 K476 KMachine Debug ManagerMicrosoft Corporation"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
nvsvc32.exe23362,680 K2,472 KNVIDIA Driver Helper Service, Version 175.19NVIDIA CorporationC:\WINDOWS\system32\nvsvc32.exe
HPZIPM12.EXE2352556 K276 KPML DriverHPC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
svchost.exe24162,756 K2,644 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k imgsvc
CLSched.exe25041,460 K880 KCLSched Module"C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe"
dialdictate.exe254027,956 K404 KDial DictateNCH Software"C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe" -service
iPodService.exe30802,472 K1,504 KiPodService Module (32-bit)Apple Inc."C:\Program Files\iPod\bin\iPodService.exe"
alg.exe33521,188 K240 KApplication Layer Gateway ServiceMicrosoft CorporationC:\WINDOWS\System32\alg.exe
lsass.exe5884,080 K1,416 KLSA Shell (Export Version)Microsoft CorporationC:\WINDOWS\system32\lsass.exe
explorer.exe162850.0053,632 K32,584 KWindows ExplorerMicrosoft CorporationC:\WINDOWS\Explorer.EXE
hpgs2wnd.exe1800936 K444 Khpgs2wndHewlett-Packard"C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
BTHelpNotifier.exe18121.542,240 K2,584 Kmcci+McciTrayAppAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
BTHelpBrowser.exe676010,112 K18,904 Kmcci+McciBrowserAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" /APPKEY=btbb /URL=file:///C:/Program Files/BT Broadband Desktop Help/btbb/OCB/d153fd8a-965a-4485-845b-effd12a9f06f/Tasks.html
BTHelpBrowser.exe68528,840 K16,004 Kmcci+McciBrowserAlcatel-Lucent"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" -AppKey=btbb -url=https://pbttbc.bt.motive.com/portal/smptasks.jsp?taskid=1
FUFAXSTM.exe18367,792 K1,188 KFAX Status MonitorSEIKO EPSON CORPORATION"C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe"
EEventManager.exe18443,416 K1,004 KEEventManager ApplicationSEIKO EPSON CORPORATION"C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
jusched.exe1864856 K200 KJava(TM) 2 Platform Standard Edition binarySun Microsystems, Inc."C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe"
realsched.exe19001,540 K232 KRealNetworks SchedulerRealNetworks, Inc."C:\program files\real\realplayer\update\realsched.exe" -osboot
dialdictate.exe200429,028 K1,520 KDial DictateNCH Software"C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe" -logon
msseces.exe1524,880 K2,976 KMicrosoft Security Client User InterfaceMicrosoft Corporation"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
SUPERANTISPYWARE.EXE38431,668 K796 KSUPERAntiSpyware ApplicationSUPERAntiSpyware.com"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
ctfmon.exe4001,188 K2,172 KCTF LoaderMicrosoft Corporation"C:\WINDOWS\system32\ctfmon.exe"
procexp.exe148411,660 K13,144 KSysinternals Process ExplorerSysinternals - www.sysinternals.com"C:\Program Files\procexp.exe"
firefox.exe664889,488 K102,004 KFirefoxMozilla Corporation"C:\Program Files\Mozilla Firefox\firefox.exe"
kbd.exe40163,704 K1,784 KKBD EXEHewlett-Packard CompanyC:\HP\KBD\KBD.EXE
hpsysdrv.exe992880 K760 KhpsysdrvHewlett-Packard Companyc:\windows\system\hpsysdrv.exe
No messages today on cold start and CPU usage has regularised to average 93% free so, subject to repetitions, looking like a fix. I presume you'd recommend I don't re-install McAfee then? Also, should I get a separate firewall or will MSE manage that too?

AlexQuote
I presume you'd recommend I don't re-install McAfee then? Also, should I get a separate firewall or will MSE manage that too?
I'm not a big fan of McAfee. The Windows Firewall in XP is not much good because it only blocks incoming. Outgoing is the most harmful. I really depends on how much security you want on your pc. If you're doing financial dealings then I would recomment a third-party firewall.See suggestions below.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*********************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
Good luck!Thanks for your help Dave - HOPE it's been as intriguing for you as it has been frustrating for me. I'll get on with finding a firewall and doing the cleanup.

Regards

AlexYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
281.

Solve : cannot use internet on infected computer?

Answer»

The default gateway is missing on that computer. That's what I'm trying to repair. Please try this:

Go Start>Run (Start search in Vista and 7), type in:
cmd
Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

At Command Prompt, type in:
netsh int ip reset reset.log
Hit Enter.
Type in:
netsh winsock reset catalog
Hit Enter.

Restart computer.That didn't work either Edited. should I post about this in the networking section???Quote

should I post about this in the networking section???
You may just as well post it there. I've reached the bottom of my bag of tricks.
If you can succeed in getting connected to the net, please run the ESET scan.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the RESULTS pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and FILES, hides System files and folders, and resets System Restore.
**************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have SAVED all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft WINDOWS Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
282.

Solve : adobe flash misbehaving?

Answer»

yes i have them. TOOK a while to dig up but i have themok i ended up just doing a complete format of my HARD drive and REINSTALLED windows. everythings working fine now. thanks for your patience superdave!Quote from: kamikaze33 on September 05, 2011, 05:30:50 PM

ok i ended up just doing a complete format of my hard drive and reinstalled windows. everythings working fine now. thanks for your patience superdave!
When I asked for you OS disk I was going to ask you to do a system File CHECK to see if any files were absent or corrupted not a complete re-format. However, now you have a new computer. I will lock this thread. If you need it reopened, PLEASE send me a pm
283.

Solve : computer running slow and locks up intermittently?

Answer»

I swear I attached it.
Lets try this again.
T.

[regaining space - attachment deleted by admin]I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new WINDOW.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
PUSH the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
ok. I ran ESET and attached the log file.
My god, every different program you have me use seems to find more things. Am I that infected? WOW
As always, THANK you for your time and help.
T.

[regaining space - attachment deleted by admin]I would say your computer is now clean. If there are no other issues, let's do some cleanup.

To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and FOLLOW the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
**************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will CLOSE all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Thank you for all your help.
Still running fairly slow but it is a night and day difference from the way it was prior to your assistance.
I have implimented all the programs and done all the cleanup that you suggested as well as was recommended in the links you provided.
I feel like my computer is well protected now.
Thanks again.

T.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
284.

Solve : Need help with Malware removal.?

Answer»

That sounds good. I will LOCK this thread. If you need it re-opened, PLEASE SEND me a pm.

285.

Solve : Stubborn Malware!?

Answer»

OK, removed a ton of programs, now have 19 GB free, and 19% free space....
MB log included.....
OTL log-

========== OTL ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.28.0 log created on 09162011_184108

Kas log, wow, that scan took over 13 hours, hope it helped.....

Status: Deleted (events: 5)
2011-09-17 07:09DeletedTrojan program Trojan.Win32.Chifrax.aC:\Documents and Settings\Sean\My Documents\My Dropbox\HauntedHouse.exeHigh
2011-09-17 12:07DeletedTrojan program Trojan.Win32.VBKrypt.cyhlC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292837.exeHigh
2011-09-17 12:07DeletedTrojan program Trojan.Win32.VBKrypt.cyhlC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292837.exe//UPXHigh
2011-09-17 12:07DeletedTrojan program Trojan.Win32.VBKrypt.cyhlC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292837.exe//UPX//data0002High
2011-09-17 12:07DeletedTrojan program Trojan.Win32.Chifrax.dC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292836.exeHigh
Status: Quarantined (events: 4)
2011-09-17 12:08Quarantinedvirus HEUR:Trojan.Win32.GenericC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1292\A1297543.exeHigh
2011-09-17 12:08Quarantinedvirus HEUR:Trojan.Win32.GenericC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1292\A1297543.exe//data0037.resHigh
2011-09-17 12:08Quarantinedvirus HEUR:Trojan.Win32.GenericC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1292\A1297543.exe//data0037.res//winTray.exeHigh
2011-09-17 12:08Quarantinedvirus HEUR:Trojan.Win32.GenericC:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1292\A1297543.exe//data0037.res//winTray.exe//.NETZHigh

[regaining space - attachment deleted by admin]*censored*, the same 2 pop-ups are still coming up.... Quote

censored*, the same 2 pop-ups are still coming up
Is it the popup that you posted in your first post? Did you install any new programs just prior to getting this problem?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and BEGIN scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Quote from: SuperDave on September 17, 2011, 04:24:30 PM
Is it the popup that you posted in your first post? Did you install any new programs just prior to getting this problem?
Yes, the first popup I posted and the second one as well, they seem to appear within seconds of each other, other then this problem the computer is running quite well, if I could just track down where they are coming from.....

ESET scan-
C:\Documents and Settings\Sean\Application Data\loaristrojanremover.exea variant of Win32/1AntiVirus applicationdeleted - quarantined
C:\Documents and Settings\Sean\desktop\Assorted Shortcuts\New Torrents\Wallpapers(*censored*)(High Quality)[owez77][h33t]\Allok AVI to DVD SVCD VCD Converter v3.6.1107\Allok AVI to DVD SVCD VCD Converter v3.6.1107.rara variant of Win32/Keygen.AT applicationdeleted - quarantined
C:\Program Files\Loaris\Trojan Remover\ltr.exea variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined
C:\Program Files\Loaris\Trojan Remover\ltr.exe.baka variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined
C:\Program Files\Unlocker\eBay_shortcuts_1016.exeWin32/Adware.ADON applicationdeleted - quarantined
C:\Program Files\Yahoo Games\Pizza Chef\PizzaChef.exeprobably a variant of Win32/TrojanDownloader.Agent.NBCQTKF trojancleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\FhPVxyxx.ini.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1288\A1292838.exeprobably a variant of Win32/Agent.CFYQYYM trojandeleted - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306610.exea variant of Win32/1AntiVirus applicationdeleted - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306611.exea variant of Win32/Keygen.AT applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306640.exea variant of Win32/1AntiVirus applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306642.exeWin32/Adware.ADON applicationdeleted - quarantined
C:\System Volume Information\_restore{EA10BEA4-2D2C-494D-9EF3-5EC8A5B65143}\RP1313\A1306643.exeprobably a variant of Win32/TrojanDownloader.Agent.NBCQTKF trojancleaned by deleting - quarantined
C:\WINDOWS\system32\drivers\up.exea variant of Win32/Adware.SafeSurf.AA applicationcleaned by deleting - quarantined
C:\WINDOWS\system32\weber\updater.exeWin32/Adware.SafeSurf applicationdeleted - quarantined
* Go to Start > Run and type mrt.exe then press Enter on the keyboard).
* (Vista and Windows 7 users go to Start and type mrt.exe in the search box then press Enter on the keyboard.
* Click Next.
* Choose Full Scan and click Next.
* Once the scan is finished click VIEW detailed results of the scan.

Look through the list and let me know if anything was found infected.'No malicious software was detected'
I cannot believe how hard this thing is to get rid of....Please download Bootkit Remover by eSage Lab from here.

NOTE: This is a file compressed with Winrar. If you do not have the means to unpack it, you can download and install 7-zip from here.

  • •Unpack remover.exe from the bootkit_remover.rar archive and save it to your Desktop
  • •Doubleclick remover.exe to run the tool
  • •A DOS window will open with the results of the scan
  • •Rightclick that window and choose Select all
  • •Simultaneously press [CTRL] + C (copy) and paste the text in your next reply.
I dont think it ran right, it 1 second it was done.....

Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com

Program version: 1.2.0.0
OS Version: Microsoft Windows XP Home Edition Service Pack 3 (build 2600

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00007e00
Boot sector MD5 is: 6def5ffcbcdbdb4082f1015625e597bd

Size Device Name MBR Status
--------------------------------------------
93 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


Done;
Press any key to quit...
Any change?Quote from: SuperDave on September 20, 2011, 01:35:09 PM
Any change?
Nope, they still pop up at least once every half an hour, I think next I'm going to rule out its a firefox addon by running my browser in safe mode for an hour and see what happens.....T think it must be an add-on, when in safe mode it doesn't pop up, now I just have to figure out what add-on it is thats causing it.....
Thanx for all your help SuperDave.... Ok. We might as well do some cleanup for now.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
********************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (BELONGING to the program we have used) hasn't been deleted, please delete it manually.
******************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!It happened to me too, when I visit a certain sites it keeps on popping and it's irritating me. Quote from: beckymaccery on September 23, 2011, 02:08:34 AM
It happened to me too, when I visit a certain sites it keeps on popping and it's irritating me.
Please do not hijack someone else's thread. It's very rude. If you need help, start your own thread.
286.

Solve : Malware or Virus?

Answer»

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows 7 Home Edition (6.1.7600)
[32_bits] - Intel64 Family 6 Model 37 Stepping 2, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[MpsSvc] RUNNING (state:4)
Windows Firewall -> Enabled
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.7600.16385
Mozilla Firefox 3.6.22 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:285 Go - Free:153 Go )
D:\ [CD_Rom]
.
Scan : 17:33.42
Path : C:\Users\John\Desktop\Rooter.exe
User : John ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
______ ? (372)
______ ? (524)
______ ? (576)
______ ? (596)
______ ? (640)
______ ? (660)
______ ? (668)
______ ? (764)
______ ? (856)
______ ? (924)
______ ? (972)
______ ? (988)
______ ? (124)
______ ? (468)
______ ? (1128)
______ C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1268)
______ ? (1516)
______ ? (1556)
______ ? (1644)
______ ? (1668)
______ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1752)
______ C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1772)
______ ? (1816)
______ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1876)
______ ? (1976)
______ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (1152)
______ ? (1828)
______ ? (2512)
______ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (2836)
______ ? (2908)
______ ? (2944)
______ ? (528)
______ ? (460)
______ ? (2940)
______ ? (3044)
______ ? (1224)
______ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (2696)
______ C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (728)
______ ? (3116)
______ ? (3160)
______ ? (3180)
______ ? (3188)
______ ? (3208)
______ ? (3232)
______ C:\Program Files (x86)\Advanced System Optimizer\memtuneup.exe (3312)
______ ? (3352)
______ ? (3592)
______ ? (3656)
______ ? (3724)
______ C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (3872)
______ ? (4000)
______ C:\Program Files (x86)\iTunes\iTunesHelper.exe (4016)
______ C:\Program Files\AVAST Software\Avast\AvastUI.exe (4032)
______ C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe (4068)
______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (548)
______ C:\Program Files (x86)\TimeLeft3\TimeLeft.exe (3360)
______ ? (3632)
______ ? (3696)
______ ? (4320)
______ ? (5192)
Locked audiodg.exe (4188)
______ ? (5356)
______ ? (3832)
______ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (840)
______ ? (3048)
______ ? (5832)
______ ? (4604)
______ C:\Users\John\Desktop\Rooter.exe (5232)
______ ? (5280)
______ ? (5780)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:1048576 | Length:13631488000)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:13632536576 | Length:104857600)
\Device\Harddisk0\Partition3 (Start_Offset:13737394176 | Length:306334490624)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 17:33.54
.
C:\Rooter$\Rooter_1.txt - (21/09/2011 | 17:33.54)
Edited.First of all I'd like to thank you for your time, I really APPRECIATE your help. My responses usually go once a day because of my work schedule, I work every day and don't have time to run scans or check up on this board. I'm at least able to play my games when I get home from work which is enough for me, but my laptop still runs slow and I want to make sure it's virus free before I relax.

I continue to run avast! daily, and it still picks up cookies. I wonder if I should uninstall stumble(even though I hardly use it now), it might be collecting more unwanted files on my computer.

Additionally, there are a few problems I have uninstalling unwanted programs, for example, an old pluggin I used to manage itunes and firefox at once, Foxytunes, won't uninstall from the add/remove programs list, and I don't know how else to remove it since searches come up blank.

Lastly, avast! is continuing to give me a notification of it blocking a file, the one I mentioned EARLIER, coming from a C:\Program Files\Internet Explorer\iexplore.exe process. I'm wondering if it's a corrupted file or something. I turned off avast! once and I ended up getting another blue screen, so I'm not sure if it's causing a crash or if it's just a coincidence.

Thanks again for all your time and patience, and I look forward to your next reply.Quote

I continue to run avast! daily, and it still picks up cookies. I wonder if I should uninstall stumble(even though I hardly use it now), it might be collecting more unwanted files on my computer.
If you're going on the internet, your bound to pick up cookies unless you set up the browser to not ACCEPT them. Not all cookies are bad.

Quote
Additionally, there are a few problems I have uninstalling unwanted programs, for example, an old pluggin I used to manage itunes and firefox at once, Foxytunes, won't uninstall from the add/remove programs list, and I don't know how else to remove it since searches come up blank.
It's there in your installed programs but it's probably been uninstalled previously. Let's try this to get rid of it.

Please download: HiJackThis to your Desktop.
  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
  • Accept the license agreement.


•Start HijackThis

•Click on the Open the Misc Tools section

•Click on the Open Uninstall Manager button.

•Highlight the entry you want to remove. (Foxytunes)
•Click Delete this entry
******************************************************
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
[/list]C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SIGRLK1M\index-functions[1].jsWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\Launcher.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rbmonitor.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rbnotifier.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_move_serial.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_ubm.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\Local\Temp\mia8972.tmp\data\OFFLINE\D038292B\DBD9B16A\registrybooster.exeWin32/RegistryBooster applicationcleaned by deleting - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-24641d49probably a variant of Java/Agent.BR trojandeleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-506c04d6a variant of Java/Agent.BR trojandeleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\404cf589-7d48dfdbJava/TrojanDownloader.OpenStream.NCA trojandeleted - quarantined
C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\uluf7408.default\extensions\{9c0b4b35-0418-4b05-9889-938f63eac03b}\chrome.manifestWin32/TrojanDownloader.Tracur.F trojancleaned by deleting - quarantined
C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\uluf7408.default\extensions\{9c0b4b35-0418-4b05-9889-938f63eac03b}\chrome\xulcache.jarJS/Agent.NDJ trojandeleted - quarantined


I tried calling a friend on skype too and I was unable to use my webcam as well, an error came up saying it was already in use...
Nevermind, just tried it again, it works. This must have fixed something.How's your computer working now? Any other issues?I think we're ok, is the virus clear? I don't want to stop running scans if there's any issues.

Also, are any of the programs you suggested worth keeping around? I want to keep the antivirus software that works best around if I get other symptoms.Quote
is the virus clear? I don't want to stop running scans if there's any issues.
I would say that your computer is clean. Let's do some cleanup.

Quote
Also, are any of the programs you suggested worth keeping around? I want to keep the antivirus software that works best around if I get other symptoms.
You may keep SAS and MBAM, if you WISH. Update them and run them on a regular basis to keep your computer clean. Also there are other suggestions below. As for the best AV. Everyone has their opinion about which AV is best. Avast is as good or better than most.

To uninstall COMBOFIX

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
********************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
********************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************************

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Ok, I attempted to install the first two firewalls, but they don't seem to work, I think it's the 64-bit OS again. In the comments for the other two I saw the same problems, so I skipped that. I'm not sure if they're really worth the trouble if I'm keeping MBAM, avast!, and SAS.

I'm updating windows, and I downloaded TFC and WoT. I was planning a disk defrag soon, since I haven't done one since I downloaded WoW for the first time on this computer, so after windows finishes updating, I'll do just that.

Thank you again, Dave. I truly appreciate your help.Quote
but they don't seem to work, I think it's the 64-bit OS again
Yes, you need to pick one that works with 64 bit machines.
Quote
Thank you again, Dave. I truly appreciate your help.
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
287.

Solve : relevant knowledge and atdm?

Answer»

MBAM seems to be working fine now tyThat sounds good. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
***************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!could not run TFC or Secuna Software Inspector and I haven't been able to get my emailsQuote
I haven't been able to get my emails
What happens when you try to get them? What are you using for e-mail?OPENING TFC.exe asks to 'save file' a window opens with 'Downloads' FTC(3).exe is highlighted with no options, so i doulbe click TFC(3).exe and this opens window with 'Open Executable File ?' and says exe files can contain viruses, etc am I sure i want to launch, I click 'ok' popup is 'Open File -Security Warning' i clicked 'Run' and popup with TFC in top left HAND corner and a title that says
Temp File Cleaner by OldTimer v 3.1.7.0 I click start and a popup says 'System modification attempt DeepGuard has noticed that a program i trying to manipulate or terminat... What should be done? I click 'I trust" and 'Ok' and same screen a second time. Then some writing shows up in popup window 'TFC 'Getting user folders and Stopping running processes. The mouse arrow is now a solid Hour Glass and nothing happens. I can't click exit, click top x button and "End Program" - TFC= This program is not responding - hour glass is quickly flashing beside smaller mouse arrow, forever clicking 'End program' must reboot, I press reset button under main TURN off button on computer tower, this time i'm allowed to go to Start, shut down and it works

Outlook Express is my email, noon today will be 2 days. I thought we were done, i went to another part of this forum and a suggested to find out if my IE 8 was slow or the computer was to download Firefox. I did. Now IE 8 firstly would not load, and now says it's add-ons are turned off with no option in the yellow bar to turn them back on. I didn't turn them off. ty Will send Secuna infoHad to login before using Secunia, used firefox and need to use IE for Microsoft Updates. Got to Microsoft Update Welcome Screen: says Install the Active X but the yellow information bar does not give me the option to right click and click "Install Active Control" Secunia found two older versions of Adobe Flash Player 10 (active x and npapi)installed Adobe Flash Player, IE 8 fired up and so did my Outlook Express email but froze with MESSAGE - Program not responding and sent error report to microsoft. Rebooted and went to start, 'Internet Explorer (no Add-ons) and computer froze again. rebooted using the reset button on computer tower. Secunia needed me to log in and I will run it again. there were many updates not installed according to them, when i went to windows update they found none. I'll be backran Secunia with firefox and I believe it fixed active x (NPAPI) but still says i got two versions of active x and says I need the latest patch version for active x, Please see list below for details and about missing patches. I have hundreds of patches not installed. Can't run Secunia with IE 8 it says: There might be problems loading the Java Applet in you browser. I'll stop posting now and wait for you. tyPlease just forget about Secunia. Sometimes it works well and other times it sort of goes crazy. The most important is to keep your Windows and Java up-to-date.

•Please download Dial-A-Fix from one of the following mirrors:

Primary mirror
Secondary mirror

•Extract the zip file to your desktop.

•Double click Dial-a-Fix.exe to start the program. Dial-A-Fix might give you a lot errors, just ignore them and Click
to continue.

•Press the green double checkmark box (Looks like this:


UNcheck Empty Temp Folders, as well as Adjust Time/Date in the prep section. The prep section should then look like this:





•Click on Go

•Wait for Dial-A-Fix to finish (All the checks marks will be all gone)

•Close Dial-A-FixI did it Quote from: darcomputer on September 25, 2011, 04:52:42 PM
I did it - Dial-A-Fix
can i try and fix "Internet Explorer is currently running with add-ons disabled. Click here to manage, disable, or remove your add-ons. Went to another forum and was suggested to disable all the add-ons and one by one add them to find the problem. I think the add-ons are very important. ty
Quote
can i try and fix "Internet Explorer is currently running with add-ons disabled.
I'm getting that same message on my laptop but I haven't tried to fix it.
I will lock this thread. If you need it re-opened, please send me a pm.
288.

Solve : browser hijacking....help please!?

Answer»

Quote

This may sound stupid, I wasn't sure if deleting would cause them to be re-installed later down the line somehow, but is it okay to just go ahead and delete the quarantined FILES ESET found?
Yes, you can. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, HIDES System files and folders, and resets System Restore.
******************************************************
To remove all of the TOOLS we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* DEPENDING on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO REPLACEMENT for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Awesome. Did everything, cleaned up the programs, downloaded a couple virus protection programs and got a new firewall. Everything still seems to be running good. Anything else I should do?Quote from: wiiman86 on September 27, 2011, 10:26:35 PM
Awesome. Did everything, cleaned up the programs, downloaded a couple virus protection programs and got a new firewall. Everything still seems to be running good. Anything else I should do?
Just stay safe. I will lock this thread. If you need it re-opened, please send me a pm.
289.

Solve : help with removal of http://gooogle-analytics.com/ga.min.js problem?

Answer»

Quote

the problem is still there because it in firefox ABP part when I OPEN that up. Plus it doing strange things in firefox when I go to some websites.
I'm not really sure what exactly the problem is with FireFox. Please explain it to me.The problem with firefox is that http://gooogle-analytics.com/ga.min.js was popping up all the time as malware in avast. The last several things you had me did stop the pop ups. Now it has integrate into adblockedplus script as this http://gooogle-analytics.com/ga.min.js as a script. The this makes sense.Quote
The problem with firefox is that http://gooogle-analytics.com/ga.min.js was popping up all the time as malware in avast.
Will Avast fix it?Avast was reporting it problem. With help it not popping up no more in Avast. But it still in adblocked plus scripted in firefox. The Avast pop up is gone now. The only worry is that adblocked plus is still has gooogle problem is in the script. I have not bank site yet or during my online class.Quote
The only worry is that adblocked plus is still has gooogle problem is in the script
Sorry. I can't help you with this.
We can now do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*****************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
***************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is FINISHED.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************************

Go to Microsoft Windows Update and get all critical updates.
----------
I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!I uninstall combofix and the google problem came back and Avast is going crazy again. SighsCould not get TFC by oldtimer to work on vista ultimate. It froze my computer three times and stall out was not responding.
290.

Solve : Google redirect problem?

Answer»

You can use this tool to remove McAfee.

•McAfee Consumer Products Removal Tool - Use on McAfee, AOL distributions of McAfee, CA distributions of McAfee - McAfee Consumer Products Removal tool (MCPR.exe)

Sorry. Please try doing this:
Note: If you still have HJT on your desktop you can skip number 1 and go to number 2.
1. Please download: HiJackThis to your Desktop.
2. Double Click the HijackThis icon, located on your Desktop.
By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
3. Accept the license agreement.
4. Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

Trusted Zone: google.com\earth
Trusted Zone: internet
Trusted Zone: mcafee.com


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.
*****************************************************
Please run RootRepeal even if HJT doesn't run for you.
Dave,

I ran the McAfee Consumer products Removal Tool and all the old McAfee files are gone (I scanned my system as a check). Though there is a new McAffee file, McAfee.xml (in C:\Program Files\common Files\the shield deluxe\Setup Info\(alpha numeric code)\extern), from my re-installation of The Shield Deluxe antivirus checker (see next paragraph) that is part of that install.

I took a big detour in order to run the programs you requested in your last post. I had to re-install the Shield Deluxe (I now have the 2011 version) because I forgot my password that is needed in order to disable the checker in order to run RootRepeal--really stupid mistake on my part losing my password. I latter found the password buried in my notes.

It was lucky I found my password because the re-install of Shield Deluxe still insisted on my password to change any settings. By the way, I decided to password protect the Shield Deluxe antivirus setting because I think something (not me) changed only one of the settings, the real time protection, without my knowledge while the other settings were left alone (when I disable my virus checker I turn off all settings).

I tried to run HiJackThis as you requested in your last post. I could not get it to run on my system. When I tried to run it I got a window that said "C:\Documents & Settings\User\Desktop\HiJackThisInstaller.exe is not a valid win32 application".

I tried to run RootRepeal, as you requested in your last post, after I turned off my Windows Firewall and the Shield Deluxe anti-virus checker. I could not get it to run on my system. When I tried to run it I got a pop-up window from the Shield Deluxe that said "RootRepeal has been terminated by Active Virus Control". I turned off all the product settings on the preferences window of the Shield Deluxe in preparation for the RootRepeal run. I must not be missing something somewhere and I didn't see the Shield Deluxe listed in your link to methods to disable programs.

What do I do next?

Ken

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next REPLY.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Dave,

I ran the ESET OnlineScanner and no threats were found. It took about four hours to scan my system's seventy thousand files.

My observations of my current system status: my system does not have the redirect problem and I have sound thanks to your directions to remedy those problems.

However, I think I still have some less serious issues regarding connection. During the mid-afternoon portion of the day (between about 2pm and 5pm) and mid-evening (about 7pm to 9pm) I have problems connecting to the Internet or, while on the Internet during those time periods, my system is so slow it seems as though my machine has locked up. I think this might be a problem with the Internet service provider (Earthlink) because my wife's computer, with whom I share that service via a wireless connection, has a similar problem but her's is not as severe.

Also, I think some of my connection problem might be caused by my wireless network connection (Trendnet to Linksys router) since the signal STRENGTH changes occasionally; the signal strength is not steady since it changes from excellent or good to average on occasion.

Additionally, I think an icon in the system tray on my computer is indicating intermittent or loss of wireless network connection when the wave symbol, that normally lights up periodically (white color to green color) next to the monitor symbol, either freezes in the on position (green light) or fails to light (white color).

Any suggestions? What do I do next? I'm interested in making sure all viruses and malware have been removed from my system.

I do appreciate all your help; my improved Internet experience due to your help has allowed me to explore and navigate all the health care options for my ailing father and mother in-law. Again, thank you.

Ken Quote
Any suggestions? What do I do next? I'm interested in making sure all viruses and malware have been removed from my system.
I'm quite confident that your computer is clean. Let's run one more scan to check that connection problem

Please download MiniToolBox to Desktop and run it.



Checkmark the following boxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • List content of Hosts
    • List IP Configuration
    • Lst Last 10 Event Viewer Errors
    • List Users, Partitions and Memory Size
    • [/b]
    Click Go and copy/paste the log (Result.txt) into your next post. .
    Dave,

    The MiniToolBox log:

    MiniToolBox by Farbar
    Ran by User (administrator) on 06-09-2011 at 11:45:46
    Microsoft Windows XP Service Pack 3 (X86)

    ***************************************************************************

    ========================= Flush DNS: ===================================


    Windows IP Configuration



    Successfully flushed the DNS Resolver Cache.


    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.
    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.
    ========================= Hosts content: =================================

    127.0.0.1 localhost

    ========================= IP Configuration: ================================

    # ----------------------------------
    # Interface IP Configuration
    # ----------------------------------
    pushd interface ip


    # Interface IP Configuration for "Local Area Connection"

    set address name="Local Area Connection" source=dhcp
    set dns name="Local Area Connection" source=dhcp register=PRIMARY
    set wins name="Local Area Connection" source=dhcp

    # Interface IP Configuration for "Wireless Network Connection 11"

    set address name="Wireless Network Connection 11" source=dhcp
    set dns name="Wireless Network Connection 11" source=dhcp register=PRIMARY
    set wins name="Wireless Network Connection 11" source=dhcp


    popd
    # End of interface IP configuration




    Windows IP Configuration



    Host Name . . . . . . . . . . . . : KenComputer

    Primary Dns Suffix . . . . . . . :

    Node Type . . . . . . . . . . . . : Unknown

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No



    Ethernet adapter Local Area Connection:



    Media State . . . . . . . . . . . : Media disconnected

    Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet for hp

    Physical Address. . . . . . . . . : 00-0F-20-6F-6B-2E



    Ethernet adapter Wireless Network Connection 11:



    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : TRENDnet TEW-424UB 54M USB Dongle

    Physical Address. . . . . . . . . : 00-14-D1-48-33-9E

    Dhcp Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    IP Address. . . . . . . . . . . . : 192.168.2.102

    Subnet Mask . . . . . . . . . . . : 255.255.255.0

    Default Gateway . . . . . . . . . : 192.168.2.1

    DHCP Server . . . . . . . . . . . : 192.168.2.1

    DNS Servers . . . . . . . . . . . : 192.168.1.1

    Lease Obtained. . . . . . . . . . : Tuesday, September 06, 2011 9:31:46 AM

    Lease Expires . . . . . . . . . . : Wednesday, September 07, 2011 9:31:46 AM

    Server: UnKnown
    Address: 192.168.1.1

    Name: google.com
    Addresses: 74.125.93.106, 74.125.93.103, 74.125.93.147, 74.125.93.105
    74.125.93.99, 74.125.93.104



    Pinging google.com [74.125.93.99] with 32 bytes of data:



    Reply from 74.125.93.99: bytes=32 time=95ms TTL=53

    Reply from 74.125.93.99: bytes=32 time=94ms TTL=53



    Ping statistics for 74.125.93.99:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 94ms, Maximum = 95ms, Average = 94ms

    Server: UnKnown
    Address: 192.168.1.1

    Name: yahoo.com
    Addresses: 209.191.122.70, 67.195.160.76, 69.147.125.65, 72.30.2.43
    98.137.149.56



    Pinging yahoo.com [98.137.149.56] with 32 bytes of data:



    Reply from 98.137.149.56: bytes=32 time=41ms TTL=56

    Reply from 98.137.149.56: bytes=32 time=71ms TTL=56



    Ping statistics for 98.137.149.56:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 41ms, Maximum = 71ms, Average = 56ms



    Pinging 127.0.0.1 with 32 bytes of data:



    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



    Ping statistics for 127.0.0.1:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 0ms, Maximum = 0ms, Average = 0ms

    ===========================================================================
    Interface List
    0x1 ........................... MS TCP Loopback interface
    0x10003 ...00 0f 20 6f 6b 2e ...... Broadcom NetXtreme Gigabit Ethernet for hp
    0x10004 ...00 14 d1 48 33 9e ...... TRENDnet TEW-424UB 54M USB Dongle
    ===========================================================================
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.102 25
    127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
    192.168.2.0 255.255.255.0 192.168.2.102 192.168.2.102 25
    192.168.2.102 255.255.255.255 127.0.0.1 127.0.0.1 25
    192.168.2.255 255.255.255.255 192.168.2.102 192.168.2.102 25
    224.0.0.0 240.0.0.0 192.168.2.102 192.168.2.102 25
    255.255.255.255 255.255.255.255 192.168.2.102 10003 1
    255.255.255.255 255.255.255.255 192.168.2.102 192.168.2.102 1
    Default Gateway: 192.168.2.1
    ===========================================================================
    Persistent Routes:
    None

    ========================= Event log errors: ===============================

    Application errors:
    ==================
    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list SEQUENCE number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.

    Error: (08/29/2011 00:11:04 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.


    System errors:
    =============
    Error: (09/06/2011 09:30:46 AM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/04/2011 10:37:16 AM) (Source: Windows Update Agent) (User: )
    Description: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

    Error: (09/04/2011 10:35:32 AM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/01/2011 09:57:19 PM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/01/2011 09:30:57 PM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/01/2011 09:08:36 PM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/01/2011 08:19:46 PM) (Source: Service Control Manager) (User: )
    Description: The IPSEC Services service terminated with the following error:
    %%1747

    Error: (09/01/2011 08:18:51 PM) (Source: Service Control Manager) (User: )
    Description: The Remote Access Connection Manager service failed to start due to the following error:
    %%231

    Error: (09/01/2011 08:18:51 PM) (Source: Service Control Manager) (User: )
    Description: The Remote Access Connection Manager service failed to start due to the following error:
    %%231

    Error: (09/01/2011 08:18:22 PM) (Source: Service Control Manager) (User: )
    Description: The Remote Access Connection Manager service DEPENDS on the Telephony service which failed to start because of the following error:
    %%1070


    Microsoft Office Sessions:
    =========================
    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:06 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:05 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

    Error: (08/29/2011 00:11:04 PM) (Source: crypt32)(User: )
    Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.


    ========================= Memory info: ===================================

    Percentage of memory in use: 36%
    Total physical RAM: 1527.48 MB
    Available physical RAM: 966.02 MB
    Total Pagefile: 2904.86 MB
    Available Pagefile: 2485.6 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1905.03 MB

    ========================= Partitions: =====================================

    1 Drive c: () (Fixed) (Total:74.53 GB) (Free:51.72 GB) NTFS

    ========================= Users: ========================================

    User accounts for \\

    Administrator ASPNET Guest
    HelpAssistant SUPPORT_388945a0 User


    **** End of log ****
    The signal is going through but, like you said, it is intermittent. Have you tried hardwiring your computer to the modem? It would appear to be a problem with the wireless. Also, please reset your modem and router. Unplug them for a minute. Dave,

    With a hardwire connecting my computer to the router located at my wife's computer, I have a good Internet connection.

    My wife reset the router (pushed the button and unplugged the unit) and disconnected the modem (turned it off at the switch as well as unplugged the unit). It was a lot of work to follow the instructions to get the router, that is wired directly to my wife's system, back up and running but she was finally able to accomplish the task and she has her Internet phone and Internet connection back. There was a side benefit of all this work: we found and properly filed our computer system literature and found some other missing items as well!

    My system required more work and was not entirely successful. My wireless Internet connection is worse since the router/modem reset and my reinstalling the wireless software & adapter.

    After the resetting the modem and router, I could not hookup my system to the Internet (my system: Trendnet wireless USB adapter [TEW-424UB] to Linksys router [Wireless-G Broadband Router--mdl. WRT54G2]). After checking on the Trendnet status, I reentered the security key and was able to get some activity on that device (searching to establish a connection with the router) but still no connection.

    I decided to reinstall the Trendnet software on my computer. Immediately after reinstalling, I got fifteen minutes of uninterrupted, though slow, Internet connection until I was disconnected. I could only continue intermittent connection by repairing the connection (by clicking on the icon in the system tray to pop-up a window for that device and then clicking on "Repair"). I had to do this continually to receive about a minute or two of connection.

    I kept an eye on the signal strength during this phase of the problem and noticed that it would go from a good connection (multi-bar green) to weak connection (single bar red) back to fair connection (no bar) back to good connection and so forth. The Internet connection was slow during this time frame (for a minute or two) until I loss the connection entirely (red "X"). I have not had this condition in the past.

    Before the router/modem reset and my reinstalling the Trendnet software and adapter, I would routinely get periods of no connection to connection periods of an hour or two. Things have gone downhill in regard to wireless connectivity.

    By the way, I wonder if the wireless connection is having problems due to the building structure where I live. My place is a small townhouse and has concrete party walls (the wall between units) with wood framing in the interior of the unit. The router is located about twenty five feet away from my computer and is in another room.

    Again, the hardwire connection between my computer and the router is working very well and the Google redirect problem has been solved due to your direction. I have an uninterrupted Internet connection with the hardwire.

    I'm not sure if my wireless Internet connection problem is a virus\malware issue; perhaps I should start a new post? If so, please advise if I should uninstall the various anti virus software packages that I have installed on my system at your direction. Please include any tips on making the uninstalls successful.

    Thank you for your help to date.

    Ken Quote
    I'm not sure if my wireless Internet connection problem is a virus\malware issue
    From what you described to me, it would appear that the problem is with the router sending the signal or the receiver. Unfortunately, I can't help you with this. You could start another thread in another forum. Perhaps that may help.
    Let's do some cleanup.

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    *************************************************
    To remove all of the tools we used and the files and folders they created do the following:
    Double click OTL.exe.
    • Click the CleanUp button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
    **************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    *****************************************************
    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    Dave,

    I successfully completed the uninstall of ComboFix.

    I don't have OTL.exe on my system; it must have been removed by my running my anti-virus during this Google redirect problem process (see my reply #12, August 10--I shouldn't have done that as you mention in your introductory instructions). Do I delete or try to uninstall the following programs that are on my desktop that I downloaded at your direction?


    1. TDSKiller.exe
    2. tdskiller zip
    3. Support-LogMeInRescue.exe
    4. RootRepeal zip
    5. MiniToolBox.exe
    6. HjackThisInstaller.exe
    7. esetsmartinstalaler_enu.exe


    I want to make sure I don't accidentally run these programs again. To delete I should double right click on the icon and left click on delete in that window? If I need to uninstall any of these programs, please provide instructions.

    Are there any other things I have to do to take care of any possible buried files from my deletion of programs that were on my system prior to my reply #12 of August 10 (deleted due to my errant running of my Deluxe Shield anti virus and PC Tools Spyware Doctor)? Those programs were:


    1. Super Antispyware (SAS)
    2. Malawarebytes
    3. DDS
    4. RKill
    5. Combo.fix
    6. Jotti's Malaware scan (I don't think this was a downloaded program?)


    The following describes what I did at that time of deletion of those programs (from my reply #12 in August):

    "I re-enabled my Deluxe Shield as well as my PC Tools Spyware Doctor antivirus checkers and ran them after the ComboFix scan. I'm not sure I did a good thing. The PC Tools Spyware caught a lot of items, though did not defined what items it caught, and fixed those files and the system does not run better."


    Thank you,

    KenQuote
    Do I delete or try to uninstall the following programs that are on my desktop that I downloaded at your direction?
    Yes. If the programs are installed on your desktop, simply delete them or drag them to your Recycling bin. If not installed on your desktop, uninstall them.
    Support-LogMeInRescue.exe is not one of the programs I asked you to install.
    You may keep SAS and MBAM, if you wish. Update them and run them on a regular basis. All the others can go. Dave,

    I got the other programs off my system per your direction. My system is running very well--thank you.

    Sorry about the "Support-LogMeIn" program citing. That was the Shield Deluxe anti-virus personnel log-in to help me install their new 2011 program after I thought I lost my password for the 2010 edition. That was a big mess and totally my fault. I now take better care of my passwords.

    I think I have one last question. To prevent the loss of my files on the hard drive, I saved some of my files (personal files and not programs I think) on thumb drives (two or three thumb drives up to 1GB capacity each) prior to all your work on my system. I want to know if I can reuse those thumb drives without jeopardizing my system? In other words, can I can plug those thumb drives back into my system, delete the contents, and reuse the thumb drives? I thought I should be safe rather than sorry and ask you before I do this.

    Ken Quote
    In other words, can I can plug those thumb drives back into my system, delete the contents, and reuse the thumb drives? I thought I should be safe rather than sorry and ask you before I do this.
    Yes. When you plug in the thumb drives hold the Shift key down for about 10 secs. while inserting them in the USB drive. Then, scan them with your AV and also with SAS and MBAM to be sure that they're clean.
    I will lock this thread. If you need it re-opened, please send me a pm.
    291.

    Solve : remove Virus?

    Answer»

    Need Help with REMOVE Trojon And Adware VirusPlease GO to this link and FOLLOW the directions and post the required LOGS.

    292.

    Solve : Please help - Fake Spy Pro issues?

    Answer»

    Ok. One more scan.

    Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:

    •Double-click on drweb-cureit.exe and then click Start

    •An information notice will appear, click OK.

    •This starts a short scan that will scan the files currently RUNNING in memory.
    •If you get a prompt to buy the full version just EXIT out of the window. The scanner will still work without buying the full version

    •If or when something is found, click the Yes button when it asks you if you want to cure it.
    •Once the short scan has finished, Click SETTINGS > Change Settings

    •Under the Scanning tab UNcheck Heuristic analysis and click OK

    •Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.

    •Click Yes to all if it asks if you want to cure/move any file(s).

    •When the scan is done.
    •In the Dr.Web CureIt menu on top left, click File and choose Save report list.

    •Save the DrWeb.csv report to your Desktop.

    •Exit Dr.Web Cureit.
    Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    * After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
    * Copy and paste that log in the next replyNo viruses found :-)That looks good. If there's no other issues, let's do some clean-up

    * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
    * Now type Combofix /uninstall in the runbox
    * Make sure there's a space between Combofix and /Uninstall
    * Then hit Enter

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a new, clean Restore Point.

    ===============================

    Download OTC by OldTimer and save it to your desktop.

    1. Double-click OTC to run it.
    2. Click the CleanUp! button.
    3. Select Yes when the "Begin cleanup Process?" prompt appears.
    4. If you are prompted to Reboot during the cleanup, select Yes
    5. OTC should delete itself once it finishes, if not delete it yourself.

    ===============================

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have SAVED all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    ================================

    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) COMODO Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

    =================================

    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!

    293.

    Solve : IE 7 Redirects?

    Answer»

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and FEATURES in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    ===============================

    Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Antivirus/Antispyware

    • Microsoft Security Essentials: this is Microsoft's free antivirus/antispyware program. It equips you with protection against viruses, spyware, trojans, rootkits, and worms. It is also light on the computer's performance. Note: when installing this, you have both an antivirus and antispyware. Make sure you also get a firewall.
    • AVG Free: this is one of the most powerful, and easiest to use security software. The free version equips you with protection against viruses, spyware, trojans, rootkits, worms, and rogue software. Note: when installing this, you have both an antivirus and antispyware. Make sure you also get a firewall.
    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    Note: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    RESIDENT Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Rogue programs help
    There are a lot of rogue programs out there that want to scare you into GIVING them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention.DragonMaster Jay - Thank you for your help and guidance in solving these computer issues!You're welcome.
    294.

    Solve : fake "windows security center" virus; won't allow me to run any programs?

    Answer»

    Results of screen317's Security Check version 0.99.4
    Windows XP Service Pack 2
    Out of date service pack!!
    Internet Explorer 6 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Disabled!
    ESET Online Scanner v3
    McAfee Total Protection
    McAfee Uninstall Wizard
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java(TM) 6 Update 15
    Out of date Java installed!
    Adobe Flash Player 10.0.45.2
    Adobe Reader 9.1.3
    Out of date Adobe Reader installed!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    ````````````````````````````````
    DNS VULNERABILITY Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````
    Please upgrade to Windows XP SP3, because it includes all previously RELEASED updates. It also includes a small number of new functionalities. Some of the updates that Service Pack 3 provides, you may not have. It is now available via Windows Update.

    More info about SP3: http://www.geekpolice.net/operating-systems-f20/windows-xp-service-pack-3-information-t16956.htm

    =================================================

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still LEAVE you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and FEATURES in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    ==

    Please download the newest version of Java from Java.com.

    Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

    Once old versions are gone, please install the newest version.

    ==================================================

    See this page for more info about malware and prevention.

    Any more questions?Everything is working perfectly now. Thanks very much! Your help is appreciated.

    295.

    Solve : "Ssytem" at top of Task Manager?

    Answer»

    But if I remove AVG free edition, what will I protect my computer with?That was why I said to install Avira free from http://www.free-av.comDragonMaster Jay, I renounce God and now pray to you!! Thank you for the miracle!! My SYSTEM is ridonculously low. from 97K to 240 stable, not EVEN fluctuating at all. Just 240.Glad that worked.

    AVG bothers me a lot. I don't RECOMMEND them very MUCH anymore.

    296.

    Solve : Re: Need some help?

    Answer»

    i have the exact same problem however I have been able to run combofix. Here is the output file:

    ComboFix 10-06-15.02 - Clivey 16/06/2010 10:37:39.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.544 [GMT 10:00]
    Running from: c:\documents and settings\Clivey\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1296 [VPS 100324-1] *On-access scanning DISABLED* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\clivey\local settings\application data\pdpdpdul\vatqmh.exe
    c:\program files\Internet Explorer\SET14.tmp
    c:\program files\Internet Explorer\SET15.tmp

    .
    ((((((((((((((((((((((((( Files Created from 2010-05-16 to 2010-06-16 )))))))))))))))))))))))))))))))
    .

    2010-06-16 00:18 . 2010-06-16 00:18--------d-----w-c:\documents and settings\All Users\Application Data\SITEguard
    2010-06-16 00:10 . 2010-06-16 00:10--------d-----w-c:\program files\STOPzilla!
    2010-06-16 00:10 . 2010-06-16 00:10--------d-----w-c:\program files\Common Files\iS3
    2010-06-16 00:10 . 2010-06-16 00:42--------d-----w-c:\documents and settings\All Users\Application Data\STOPzilla!
    2010-06-15 12:51 . 2010-06-16 00:42--------d-----w-c:\documents and settings\Clivey\Local Settings\Application Data\pdpdpdul
    2010-06-15 12:50 . 2010-06-15 12:50--------d-----w-c:\windows\Sun
    2010-06-13 01:20 . 2010-05-06 10:41743424-c----w-c:\windows\system32\dllcache\iedvtool.dll
    2010-06-02 06:21 . 2010-06-02 06:21503808----a-w-c:\documents and settings\Clivey\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5d161ea7-n\msvcp71.dll
    2010-06-02 06:21 . 2010-06-02 06:21499712----a-w-c:\documents and settings\Clivey\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5d161ea7-n\jmc.dll
    2010-06-02 06:21 . 2010-06-02 06:21348160----a-w-c:\documents and settings\Clivey\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5d161ea7-n\msvcr71.dll
    2010-05-17 12:00 . 2010-05-17 12:00286720----a-w-c:\windows\iun506.exe
    2010-05-17 12:00 . 2010-05-17 13:02--------d-----w-C:\Bridge BASE Online

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-06-16 00:37 . 2010-06-16 00:331504----a-w-c:\windows\system32\drivers\kgpcpy.cfg
    2010-05-13 11:00 . 2010-05-13 11:00--------d-----w-c:\documents and settings\LocalService\Application Data\McAfee
    2010-05-13 11:00 . 2009-09-29 13:31--------d-----w-c:\program files\McAfee Security Scan
    2010-05-06 10:41 . 2008-04-15 03:00916480----a-w-c:\windows\system32\wininet.dll
    2010-05-02 05:22 . 2008-04-15 03:001851264----a-w-c:\windows\system32\win32k.sys
    2010-04-20 05:30 . 2008-04-15 03:00285696----a-w-c:\windows\system32\atmfd.dll
    2010-03-24 15:41 . 2010-03-24 15:41411368----a-w-c:\windows\system32\deploytk.dll
    2010-03-24 15:40 . 2010-03-24 15:40152576----a-w-c:\documents and settings\Clivey\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
    2010-03-21 08:03 . 2010-03-21 08:030----a-w-c:\windows\nsreg.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-29 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-03-24 149280]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Domino's Pizza ANZ VPN Client.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Domino's Pizza ANZ VPN Client.lnk
    backup=c:\windows\pss\Domino's Pizza ANZ VPN Client.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
    backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchApp]
    Alaunch [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2008-10-14 15:0439792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2005-05-03 10:4369632----a-w-c:\windows\Alcmtr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
    2006-07-17 14:4053248------w-c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
    2008-05-22 07:30425984----a-w-c:\acer\Empowering Technology\eRecovery\eRAgent.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
    2008-04-15 03:00208952----a-w-c:\windows\ime\imjp8_1\imjpmig.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 12:421695232------w-c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
    2008-04-15 03:0059392----a-w-c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
    2008-04-15 03:00455168----a-w-c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
    2008-04-15 03:00455168----a-w-c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
    2008-05-16 06:3916862720----a-w-c:\windows\RTHDCPL.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    2008-04-25 01:321044480----a-w-c:\program files\Synaptics\SynTP\SynTPEnh.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=

    R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [7/12/2009 5:59 PM 61328]
    R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [24/02/2010 3:06 PM 173328]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [13/01/2009 12:51 PM 111184]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13/01/2009 12:51 PM 20560]
    R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [5/05/2008 5:01 PM 254976]
    S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [7/12/2009 5:59 PM 61328]
    S3 BCUMXMIDI;BCUMXMIDI;c:\windows\system32\drivers\bumxmidi.sys [12/01/2006 12:18 PM 22752]
    S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\Drivers\L6TPortGX.sys --> c:\windows\system32\Drivers\L6TPortGX.sys [?]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 10:49 PM 227232]
    .
    .
    ------- SUPPLEMENTARY Scan -------
    .
    uStart Page = hxxp://www.google.com.au/
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uInternet Connection Wizard,ShellNext = hxxp://en.au.acer.yahoo.com/
    uInternet Settings,ProxyServer = http=127.0.0.1:1034
    uInternet Settings,ProxyOverride =
    uSearchURL,(Default) = hxxp://au.rd.yahoo.com/customize/ycomp/defaults/su/*http://au.yahoo.com
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: line6.net
    FF - ProfilePath - c:\documents and settings\Clivey\Application Data\Mozilla\Firefox\Profiles\o9an9j44.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 1034
    FF - prefs.js: network.proxy.type - 1
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-vjnxhcmqetcuv - c:\documents and settings\clivey\local settings\application data\pdpdpdul\vatqmh.exe
    HKLM-Run-vjnxhcmqetcuv - c:\documents and settings\clivey\local settings\application data\pdpdpdul\vatqmh.exe
    Notify-TPSvc - TPSvc.dll



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-06-16 10:42
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
    .
    Completion time: 2010-06-16 10:45:06
    ComboFix-quarantined-files.txt 2010-06-16 00:45

    Pre-Run: 103,741,587,456 bytes free
    Post-Run: 103,943,630,848 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    - - End Of File - - 6B44C3EE7D1AD9C6D935254EA02EC309


    any help would be great thanksafter a restart it actually has resolved the issues. though it mentioned to enter the code anyway.Please run a free online scan with the ESET Online Scanner

    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    297.

    Solve : Application is executed the file --------- maybe infected?

    Answer»

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4052

    Windows 6.0.6001 Service Pack 1
    Internet Explorer 7.0.6001.18000

    6/17/2010 2:30:31 PM
    mbam-log-2010-06-17 (14-30-31).txt

    Scan TYPE: Full scan (C:\|D:\|)
    Objects scanned: 258307
    Time elapsed: 1 hour(s), 43 minute(s), 16 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    Here is the second scan after updating malware

    ------------
    www.malwarebytes.org

    Database version: 4210

    Windows 6.0.6001 Service Pack 1
    Internet Explorer 7.0.6001.18000

    6/17/2010 4:22:45 PM
    mbam-log-2010-06-17 (16-22-45).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 266126
    Time elapsed: 1 hour(s), 46 minute(s), 12 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)Please run a free online scan with the ESET Online Scanner

    • Tick the box NEXT to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the OPTIONS Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the LOGFILE located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    Jay -

    something strange happened.

    The first time i rant eh scan it foudn 3 objects infected, then before it could finish the scan it restarted my computer.

    I had to start all over again, and when it was finished it found no viruses.

    this is the log it created
    -------------
    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OK
    esets_scanner_update returned -1 esets_gle=53251
    esets_scanner_update returned -1 esets_gle=53251Ok good.

    Anymore alerts?

    Cleanup time?nope no more alerts.


    any other steps?If there are no more issues, then it is time to clean up.

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name i.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive i.e. C
    • For a few moments the system will make some calculations
    • Select the More Options tab
    • In the System Restore and Shadow Backups select Clean up
    • Select Delete on the pop up
    • Select OK
    • Select Delete
    You are now done

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    298.

    Solve : Need some help?

    Answer»

    Ok it rebooted and automatically opened note pad, heres the report

    All processes killed
    ========== FILES ==========
    C:\Users\Shaun\AppData\Local\ecveys folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash CACHE emptied: 41044 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: PUBLIC
    ->Temp folder emptied: 0 bytes

    User: Shaun
    ->Temp folder emptied: 110469118 bytes
    ->Temporary Internet Files folder emptied: 87079490 bytes
    ->Java cache emptied: 81037941 bytes
    ->Google Chrome cache emptied: 6138516 bytes
    ->Apple Safari cache emptied: 54583490 bytes
    ->Flash cache emptied: 518465 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 712960 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 4196537 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 329.00 mb


    OTM by OldTimer - Version 3.1.12.2 log created on 06172010_230816

    Files moved on Reboot...
    File C:\Users\Shaun\AppData\Local\Temp\Low\hsperfdata_Shaun\5392 not found!
    C:\Users\Shaun\AppData\Local\Temp\Low\~DF1B55.tmp moved successfully.
    C:\Users\Shaun\AppData\Local\Temp\Low\~DFA6E4.tmp moved successfully.
    C:\Users\Shaun\AppData\Local\Temp\~DF6F83.tmp moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RNT03TX0\BuddyList[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RNT03TX0\im[2].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RNT03TX0\login_status[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RNT03TX0\ToastFull[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OMK6IQ7J\bannerCADGYYER.htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OMK6IQ7J\login_status[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OMK6IQ7J\xd_receiver[3].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DVLBEMN3\bannerCAYJ3GTI.htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DVLBEMN3\default[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A8N2HY9C\xd_receiver[3].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A8N2HY9C\xd_receiver[4].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\63PRNWD1\InboxLight[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\63PRNWD1\info[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\63PRNWD1\pngbehavior[1].htc moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\63PRNWD1\ToastMini[1].htm moved successfully.
    C:\Users\Shaun\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
    File C:\Windows\temp\mcafee_DIbLc8iLU64K0kP not found!
    File C:\Windows\temp\mcmsc_bqQxZcKHVBFJA7D not found!
    File C:\Windows\temp\mcmsc_MKCpwXE8n79Jnqn not found!
    File C:\Windows\temp\mcmsc_T2v8DhzVUTDV7g5 not found!
    File C:\Windows\temp\mcmsc_yoIRmlHgQ484Ges not found!
    File C:\Windows\temp\sqlite_Ah0XIS30w6zna8z not found!
    File C:\Windows\temp\sqlite_f2JvGUH9plFieiW not found!
    File C:\Windows\temp\sqlite_JG9tBcMuzLLE8mI not found!
    File C:\Windows\temp\sqlite_TUGLZ5EHUU0AW2n not found!

    Registry entries deleted on Reboot...
    Please run the F-Secure Online Scanner

    • Follow the Instruction Here for installation.
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
    its not working tried twice and around 64% of downloading it brings up an error message - The programme could not download all the necessary files. Make sure you are connected to the internet.
    the computer is definatly still connected to the internetPlease run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the TERMS of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you MAY close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OK
    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name i.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive i.e. C
    • For a few moments the system will make some calculations
    • Select the More Options tab
    • In the System Restore and Shadow Backups select Clean up
    • Select Delete on the pop up
    • Select OK
    • Select Delete
    You are now done

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Results of screen317's Security Check version 0.99.4
    Windows Vista Service Pack 1 (UAC is enabled)
    Out of date service pack!!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Antivirus
    ESET Online Scanner v3
    McAfee SecurityCenter
    WMI entry may not exist for antivirus; attempting automatic update.
    avast! successfully updated!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Java(TM) 6 Update 20
    Adobe Flash Player 10.0.45.2
    Adobe Reader 9
    Out of date Adobe Reader installed!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Alwil Software Avast4 aswUpdSv.exe
    Alwil Software Avast4 ashServ.exe
    Alwil Software Avast4 ashMaiSv.exe
    Alwil Software Avast4 ashWebSv.exe
    McAfee VIRUSS~1 mcshield.exe
    McAfee VIRUSS~1 mcsysmon.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log```````````` Please consider updating to Windows Vista Service Pack 2 (SP2).
    Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards.
    It is now available via Windows Update or as a standalone installation here.

    =============================

    Please download the NEWEST version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    =============================

    See this page for more info about malware and prevention.Updated everythingGood. cheers for your help
    299.

    Solve : ?!?!?!?! - new malware problem - need help please - ?!?!?!?!?

    Answer»

    You're WELCOME.

    300.

    Solve : Getting pop-ups & Error messages!?

    Answer»

    Non more pop-ups but,10+ alerts from MicroSoft Security Essentials.

    Here is the log:
    C:\Program Files\Mozilla Firefox\o.data variant of Win32/Kryptik.DUI trojancleaned by deleting - quarantined
    C:\Program Files\Unlocker\eBay_shortcuts_1016.exea variant of Win32/Adware.ADON applicationdeleted - quarantined
    C:\QooBox\Quarantine\C\WINDOWS\system32\AdcMmnpo.ini.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\QooBox\Quarantine\C\WINDOWS\system32\AdcMmnpo.ini2.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\QooBox\Quarantine\C\WINDOWS\system32\akatibok.ini.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\QooBox\Quarantine\C\WINDOWS\system32\rfutbqhv.ini.virWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP666\A0088062.iniWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP666\A0088063.iniWin32/Adware.Virtumonde.NEO applicationcleaned by deleting - quarantined
    C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP667\A0088889.exea variant of Win32/Adware.ADON applicationdeleted - quarantined
    Is this the log from ESET or MSE? Anymore alerts?Quote from: SuperDave on June 24, 2010, 07:45:48 PM

    Is this the log from ESET or MSE? Anymore alerts?

    ESET.
    And not as of yet Ok. If there are no other issues, it's time for some clean-up.

    * Click START then RUN - Vista users press the Windows KEY and the R keys for the Run box.
    * Now type Combofix /uninstall in the runbox
    * Make sure there's a space between Combofix and /Uninstall
    * Then hit Enter

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a NEW, clean Restore Point.

    =========================

    Uninstall GMER

    Click on Start &GT; Run and type in or copy/paste all of the Red text into the Run box.

    %windir%\gmer_uninstall.cmd

    Click OK to remove GMER.
    =============================

    Download OTC by OldTimer and save it to your desktop.

    1. Double-click OTC to run it.
    2. Click the CleanUp! button.
    3. Select Yes when the "Begin cleanup Process?" prompt appears.
    4. If you are prompted to Reboot during the cleanup, select Yes
    5. OTC should delete itself once it finishes, if not delete it yourself.

    ===============================

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    =================================

    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

    =====================================

    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!