GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

Rogue Scanner 962 removal from site

View previous topic View next topic Go down

Rogue Scanner 962 removal from site

Post by Longstreet1864 on Thu Jan 07, 2010 7:16 pm

This is my 1st posting so I am new. I have a Real Estate Web Site and After my developer uploaded new information my site shut down on my computer. I use AVG and get a WARNING: ROGUE SCANNER type 962 --- error and it shuts down the page. This also happens now in my CMS Admin for the site.

The site works on computers without AVG -- So how do I remove this ERROR???

Thank You

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Belahzur on Thu Jan 07, 2010 11:26 pm

Hello.

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste BOTH LOGS back here, use more than one post if needed.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 5:16 pm

Hello - Below are the files you requested. I appreciate your help & hope I am doing this correctly. The web site my spouce owns and is having this problem with is: coloradoresortbrokers.com Kind Regards


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 2/2/2009 2:46:05 AM
System Uptime: 1/6/2010 3:50:40 AM (54 hours ago)

Motherboard: TOSHIBA | | Satellite M305
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz | U2E1 | 1600/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 175.989 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP319: 12/4/2009 10:21:21 AM - Scheduled Checkpoint
RP320: 12/7/2009 9:40:31 AM - Windows Update
RP321: 12/8/2009 10:40:25 PM - Scheduled Checkpoint
RP322: 12/12/2009 6:29:03 AM - Windows Update
RP323: 12/13/2009 3:00:22 AM - Windows Update
RP324: 12/14/2009 9:17:18 AM - Windows Update
RP325: 12/15/2009 12:24:15 AM - Scheduled Checkpoint
RP326: 12/16/2009 12:27:54 AM - Scheduled Checkpoint
RP327: 12/16/2009 6:02:13 PM - Scheduled Checkpoint
RP328: 12/17/2009 6:54:08 AM - Scheduled Checkpoint
RP329: 12/17/2009 1:55:01 PM - Windows Update
RP330: 12/18/2009 10:44:58 AM - Scheduled Checkpoint
RP331: 12/21/2009 12:02:28 PM - Windows Update
RP332: 12/24/2009 7:49:46 AM - Windows Update
RP333: 12/25/2009 9:49:08 AM - Scheduled Checkpoint
RP334: 12/27/2009 8:45:37 PM - Scheduled Checkpoint
RP335: 12/28/2009 10:43:45 AM - Windows Update
RP336: 12/29/2009 - Scheduled Checkpoint
RP337: 12/30/2009 7:30:09 PM - Scheduled Checkpoint
RP338: 1/1/2010 3:44:03 PM - Windows Update
RP339: 1/2/2010 11:53:18 AM - Scheduled Checkpoint
RP340: 1/5/2010 9:59:59 AM - Windows Update
RP341: 1/6/2010 8:54:44 AM - Scheduled Checkpoint
RP342: 1/7/2010 8:34:12 AM - Scheduled Checkpoint
RP343: 1/7/2010 9:06:37 PM - Windows Update

==== Installed Programs ======================

6500_E709_eDocs
6500_E709_Help
6500_E709n
Acrobat.com
Add or Remove Adobe Creative Suite 3 Web Premium
Adobe Acrobat 8 Professional
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe BridgeTalk Plugin CS3
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Contribute CS3
Adobe Creative Suite 3 Web Premium
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe Extendscript Toolkit 2
Adobe Extension Manager CS3
Adobe Fireworks CS3
Adobe Flash CS3
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader 9.1.1
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Version Cue CS3 Server
Adobe WAS CS3
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
AHV content for Acrobat and Flash
bpd_scan
BPDSoftware
BPDSoftware_Ini
BufferChm
Business Contact Manager for Outlook 2007 SP2
Camera Assistant Software for Toshiba
CD/DVD Drive Acoustic Silencer
CyberLink PowerCinema for TOSHIBA
DesignPro 5.4 Limited Edition
Destination Component
DeviceDiscovery
DocMgr
DocProc
DVD MovieFactory for TOSHIBA
Fax
FileZilla Client 3.3.1
GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)
Google Chrome
Google Earth
Google Update Helper
GPBaseService2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
Hotfix for Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (KB944899)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946344)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946581)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB951708)
HP Update
HPProductAssistant
HPSSupply
ieSpell
IMprocessor 1.1
Java(TM) 6 Update 6
MarketResearch
Microsoft ASP.NET MVC 1.0
Microsoft Easy Assist v2
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Accounting 2007
Microsoft Office Accounting ADP Payroll Addin
Microsoft Office Accounting Equifax Addin
Microsoft Office Accounting Fixed Asset Manager
Microsoft Office Accounting PayPal Addin
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
Microsoft Office Small Business Connectivity Components
Microsoft Office Suite Activation Assistant
Microsoft Office Visual Web Developer 2007
Microsoft Office Visual Web Developer MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Silverlight 3 SDK
Microsoft Silverlight 3 Tools for Visual Web Developer Express 2008 SP1 - ENU
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Management Objects
Microsoft SQL Server 2008 Policies
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft SQL Server Compact 3.5 SP1 Query Tools English
Microsoft SQL Server Database Publishing Wizard 1.3
Microsoft SQL Server Driver for PHP 1.0
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU Service Pack 1 (KB945140)
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft Visual Studio Web Authoring Component
Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU
Microsoft XML Parser
Mozilla Firefox (3.0.14)
Mozilla Thunderbird (2.0.0.21)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My.Freeze.com NetAssistant
MySQL Connector Net 5.2.5
NetWaiting
PDF Settings
PHP 5.2.10
PrimoPDF
ProductContext
QuickBooks Financial Center
Scan
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Windows Media Encoder (KB954156)
Skype™ 4.0
SmartFTP Client Setup Files 3.0 (x64) (remove only)
SmartWebPrinting
SolutionCenter
Spelling Dictionaries Support For Adobe Reader 9
SQL Server System CLR Types
Status
TeamViewer 4
Toolbox
Toshiba Assist
TOSHIBA ConfigFree
TOSHIBA Desktop Links
TOSHIBA DVD PLAYER
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Face Recognition
TOSHIBA Hardware Setup
Toshiba Registration
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TrayApp
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Microsoft Visual Studio Web Authoring Component (KB945140)
Update for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB967144)
Update for Outlook 2007 Junk Email Filter (kb976884)
WebReg
Windows Media Encoder 9 Series
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

1/1/2010 3:39:46 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.4.38 for the Network Card with network address 0022FA1E6444 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================



DDS (Ver_09-12-01.01) - NTFSX64
Run by Owner at 9:57:21.27 on Fri 01/08/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3960.1523 [GMT -7:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k nȯne
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10d.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D41IFNF6\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uDefault_Page_URL = [You must be registered and logged in to see this link.]
mDefault_Page_URL = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files (x86)\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files (x86)\my.freeze.com netassistant\NetAssistant.dll
mWinlogon: Userinit=userinit.exe
BHO: MRI_DISABLED - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files (x86)\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files (x86)\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files (x86)\java\jre1.6.0_06\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files (x86)\my.freeze.com netassistant\NetAssistant.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files (x86)\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files (x86)\adobe\/Adobe Contribute CS3/contributeieplugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files (x86)\yahoo!\companion\installs\cpn\yt.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [NDSTray.exe] NDSTray.exe
mRun: [cfFncEnabler.exe] cfFncEnabler.exe
mRun: [ToshibaServiceStation] "c:\program files (x86)\toshiba\toshiba service station\TSS.exe" /hide
mRun: [Acrobat Assistant 8.0] "c:\program files (x86)\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: []
mRun: [Adobe_ID0EYTHM] c:\progra~2\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Sprint SmartView] "c:\program files (x86)\sprint\sprint smartview\SprintSV.exe" -a
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\adobea~2.lnk - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &ieSpell Options - c:\program files (x86)\iespell\iespell.dll/SPELLOPTION.HTM
IE: Append to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Check &Spelling - c:\program files (x86)\iespell\iespell.dll/SPELLCHECK.HTM
IE: Convert link target to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~1\office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - [You must be registered and logged in to see this link.] files (x86)\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - [You must be registered and logged in to see this link.] files (x86)\iespell\wikipedia.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - [You must be registered and logged in to see this link.] files (x86)\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - [You must be registered and logged in to see this link.] files (x86)\iespell\iespell.dll/SPELLOPTION.HTM
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files (x86)\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe
mRun-x64: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mo8ruan8.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files (x86)\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

============= SERVICES / DRIVERS ===============

R0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\drivers\tos_sps64.sys [2008-8-20 504912]
R2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\toshiba\configfree\CFProcSRVC.exe [2008-6-27 36864]
R2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\toshiba\configfree\CFSvcs.exe [2008-7-10 40960]
R2 ftpsvc;Microsoft FTP Service;c:\windows\system32\svchost.exe -k ftpsvc [2008-1-20 27648]
R2 TeamViewer4;TeamViewer 4;c:\program files (x86)\teamviewer\version4\TeamViewer_Service.exe [2009-8-24 185640]
R2 TMachInfo;TMachInfo;c:\program files (x86)\toshiba\toshiba service station\TMachInfo.exe [2008-8-20 46392]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 175104]
R3 CAXHWAZL;CAXHWAZL;c:\windows\system32\drivers\CAXHWAZL.sys [2008-3-25 294400]
R3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;c:\windows\system32\drivers\NETw5v64.sys [2008-4-28 4730368]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2mdx64.sys [2008-4-15 62040]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sdx64.sys [2008-4-8 51928]
R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [2007-4-9 9728]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-4-24 84992]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk60x64.sys [2008-7-25 404992]
S2 gupdate1c9ab582222ca4;Google Update Service (gupdate1c9ab582222ca4);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-3-22 133104]
S3 CASprint;Sprint Con App Svc;c:\program files (x86)\sprint\sprint smartview\ConAppsSvc.exe [2008-10-15 124160]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-3-17 93184]
S3 MsDepSvc;Web Deployment Agent Service;c:\program files\iis\microsoft web deploy\MsDepSvc.exe [2009-4-8 42888]
S3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\drivers\PCASp50a64.sys [2009-4-8 41280]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver;c:\windows\system32\PCTINDIS5X64.sys [2008-10-15 43032]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S4 KR10I64;KR10I64;c:\windows\system32\drivers\KR10I64.sys [2008-8-20 248320]
S4 KR10N64;KR10N64;c:\windows\system32\drivers\KR10N64.sys [2008-8-20 237568]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-3-30 61976]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 311656]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 427880]

=============== Created Last 30 ================

2009-12-17 00:02:57 0 d-----w- c:\users\owner\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-12-12 13:29:44 442368 ----a-w- c:\windows\system32\winhttp.dll

==================== Find3M ====================

2009-11-18 18:37:54 186342 ----a-w- c:\windows\hpwins23.dat
2009-11-18 18:25:53 51200 ----a-w- c:\windows\inf\infpub.dat
2009-11-18 18:25:53 143360 ----a-w- c:\windows\inf\infstrng.dat
2009-11-18 18:25:29 86016 ----a-w- c:\windows\inf\infstor.dat
2009-11-09 13:48:55 15872 ----a-w- c:\windows\system32\wamregps.dll
2009-11-09 13:47:20 32768 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 13:45:00 192512 ----a-w- c:\windows\system32\iisRtl.dll
2009-11-09 13:45:00 11264 ----a-w- c:\windows\system32\iisrstap.dll
2009-11-09 13:44:51 33792 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 13:42:58 61440 ----a-w- c:\windows\system32\ahadmin.dll
2009-11-09 13:42:53 54784 ----a-w- c:\windows\system32\admwprox.dll
2009-11-09 13:23:56 10752 ----a-w- c:\windows\syswow64\wamregps.dll
2009-11-09 13:22:34 24064 ----a-w- c:\windows\syswow64\nshhttp.dll
2009-11-09 13:20:23 8192 ----a-w- c:\windows\syswow64\iisrstap.dll
2009-11-09 13:20:23 153600 ----a-w- c:\windows\syswow64\iisRtl.dll
2009-11-09 13:20:16 31232 ----a-w- c:\windows\syswow64\httpapi.dll
2009-11-09 13:18:33 27136 ----a-w- c:\windows\syswow64\ahadmin.dll
2009-11-09 13:18:31 51712 ----a-w- c:\windows\syswow64\admwprox.dll
2009-11-09 11:47:53 16896 ----a-w- c:\windows\system32\iisreset.exe
2009-11-09 11:21:20 14848 ----a-w- c:\windows\syswow64\iisreset.exe
2009-11-03 03:42:06 226688 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 10:00:13 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-29 09:41:23 2048 ----a-w- c:\windows\syswow64\tzres.dll
2009-10-27 13:45:07 1032704 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 13:41:03 86528 ----a-w- c:\windows\system32\ieencode.dll
2009-10-27 13:20:19 833024 ----a-w- c:\windows\syswow64\wininet.dll
2009-10-27 13:20:05 1174528 ----a-w- c:\windows\syswow64\urlmon.dll
2009-10-27 13:18:49 146432 ----a-w- c:\windows\syswow64\occache.dll
2009-10-27 13:17:35 671232 ----a-w- c:\windows\syswow64\mstime.dll
2009-10-27 13:17:21 3584000 ----a-w- c:\windows\syswow64\mshtml.dll
2009-10-27 13:17:19 458240 ----a-w- c:\windows\syswow64\msfeeds.dll
2009-10-27 13:16:43 28160 ----a-w- c:\windows\syswow64\jsproxy.dll
2009-10-27 13:16:30 6069248 ----a-w- c:\windows\syswow64\ieframe.dll
2009-10-27 13:16:30 270848 ----a-w- c:\windows\syswow64\iertutil.dll
2009-10-27 13:16:28 78336 ----a-w- c:\windows\syswow64\ieencode.dll
2009-10-27 13:16:28 389120 ----a-w- c:\windows\syswow64\iedkcs32.dll
2009-10-27 13:16:28 380928 ----a-w- c:\windows\syswow64\ieapfltr.dll
2009-10-27 13:16:27 230400 ----a-w- c:\windows\syswow64\ieaksie.dll
2009-10-27 11:20:07 32768 ----a-w- c:\windows\system32\ieUnatt.exe
2009-10-27 10:55:39 26624 ----a-w- c:\windows\syswow64\ieUnatt.exe
2008-08-21 01:32:32 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 --sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 --sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-29 02:31:54 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-06-30 16:53:05 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-03-18 02:08:43 4 --sh--r- c:\windows\system32\drivers\taishop.sys
2009-03-18 02:08:45 14 --sh--r- c:\windows\syswow64\drivers\fbd.sys
2009-09-25 16:41:27 16384 --sha-w- c:\windows\temp\cookies\index.dat
2009-09-25 16:41:27 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat
2009-09-25 16:41:27 32768 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 9:58:42.00 ===============

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Belahzur on Fri Jan 08, 2010 5:44 pm

Hello.
Regarding your first post, are all computers reporting this running AVG? can you link me to your site and I'll run a quick check over it for hȋdden iframe code, it's possible it's not the machine, but your site maybe hacked.

  • Click Start >> Control Panel.
  • Under the Programs click Uninstall a Program
  • Highlight the following:

    Java(TM) 6 Update 6
    My.Freeze.com NetAssistant

  • Click on the Uninstall/Change button at the top.

Updating Java:

  • Download the latest version of [You must be registered and logged in to see this link.].
  • Select the second option where it says "This special release provides a few key fixes.".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-6u17-windows-i586.exe that you downloaded to install the newest version.

Please download [You must be registered and logged in to see this link.] and install it. It will install over version 3.0 you currently have installed, so you won't lose any bookmarked websites.

How is the machine now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 5:51 pm

Hello,
The site is [You must be registered and logged in to see this link.]
I will follow your instructions above.

Do you have any aspx/.net programmers that Ican pay to fix the site???

Kind regards

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 5:53 pm

OOPS!!! Only One computer has the AVG and it is the one reporting the problem

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Belahzur on Fri Jan 08, 2010 5:58 pm

Site is fine, Chrome shows no warnings nor any hȋdden iframes. AVG is likely showing a false positive, AVG is good at getting many things wrong, update your AVG database, see if you get the warning now.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 6:03 pm

Ran the AVG update -- I still get the error

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Belahzur on Fri Jan 08, 2010 6:05 pm

Doesn't suprise me, AVG suck. Annoyed or Unimpress

Uninstall AVG, and install Avira. Avira is takes less resources on the system and doesn't have nearly as many false positives.

Please install Avira antivirus otherwise you won't be protected.

1) [You must be registered and logged in to see this link.]
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 6:09 pm

I will give it a try and get back to you. Do you have any aspx/net programmers???

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Belahzur on Fri Jan 08, 2010 6:10 pm

You can ask in the programming forum, the site is fine, not hacked. Just had to check it in case you didn't chmod your files/change settings on .htaccess


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Rogue Scanner 962 removal from site

Post by Longstreet1864 on Fri Jan 08, 2010 6:13 pm

THANK YOU

Longstreet1864
Novice
Novice

Status :
Online
Offline

Posts : 7
Joined : 2010-01-07
OS : Windows7
Points : 25313
# Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum