Pop up warning
Page 2 of 4 • Share •
Page 2 of 4 •
1, 2, 3, 4 
Pop up warning
First topic message reminder :
Everytime I click a link I get a pop up that says windows cannot find that web address.
Anyone have a clue why this is happening..
Thanks in advance
Everytime I click a link I get a pop up that says windows cannot find that web address.
Anyone have a clue why this is happening..
Thanks in advance

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
I am still getting these pop ups
Windows cannot find 'http:www.website.com'.
.
Make sure you typed the name correctly, then try again.
I get this everytime I click a link from my email or a web page.
But the page always open up?
There is a red circle w. an X and a OK button in the pop up.
I tried to do a screen shot w/ the pop up warning but it will not work.
Again thanks for all your help...
.
Make sure you typed the name correctly, then try again.
I get this everytime I click a link from my email or a web page.
But the page always open up?
There is a red circle w. an X and a OK button in the pop up.
I tried to do a screen shot w/ the pop up warning but it will not work.
Again thanks for all your help...

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
- Download combofix from here
[You must be registered and logged in to see this link.]
* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".
2. During the download, rename Combofix to svchost as follows:


3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
- See [You must be registered and logged in to see this link.] for how to disable your AV.
- Double click on svchost.exe.
- Follow the prompts. NOTE:
- Allow combofix to run
- Post C:\combofix.txt back here.
Note:
Do not mouse click combofix's window whilst it's running. That may cause it to stall.



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
Caused my computer to crash?
It started in on a dos screen..
As it was running I got a blue scrambbled screen That had type saying my system crashed to reboot...
It started in on a dos screen..
As it was running I got a blue scrambbled screen That had type saying my system crashed to reboot...

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
I did disable my Avira Antivirus...
I did get a warning that I should run fix from a different site?
I did get a warning that I should run fix from a different site?

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
Did Combofix warn of Virut?



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
never finished because it crashed....
SHould I try again?
SHould I try again?

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
Yes please.



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
ComboFix 10-02-05.02 - Richard Abare 02/05/2010 16:27:54.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2813.1810 [GMT -5:00]
Running from: c:\users\Richard Abare\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3270954652-3410097223-3268541396-500
C:\LOG.TXT
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 21:35 . 2010-02-05 21:37 -------- d-----w- c:\users\Richard Abare\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Veda\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Cindy\AppData\Local\temp
2010-02-04 14:55 . 2010-02-04 14:56 -------- d-----w- c:\program files\iTunes
2010-02-04 14:50 . 2010-02-04 14:50 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-31 23:34 . 2010-02-01 00:25 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-31 23:34 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\programdata\Avira
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\program files\Avira
2010-01-31 21:51 . 2010-01-31 21:51 -------- d-----w- c:\users\Richard Abare\AppData\Local\IsolatedStorage
2010-01-31 21:50 . 2010-01-31 21:51 -------- d-----w- c:\program files\Virtual Earth 3D
2010-01-25 17:59 . 2010-01-25 17:59 -------- d-----w- c:\users\Richard Abare\AppData\Local\Cooliris
2010-01-25 17:58 . 2010-01-06 17:08 4726272 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-01-25 17:58 . 2010-01-06 17:08 103424 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-01-25 17:58 . 2010-01-06 17:08 57856 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-01-25 17:58 . 2010-01-06 17:08 545280 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-01-25 17:58 . 2010-01-06 17:08 4725760 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-01-25 17:58 . 2010-01-06 17:08 153600 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-01-25 17:58 . 2010-01-06 17:08 344064 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-01-25 17:41 . 2010-01-25 17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-21 22:42 . 2010-01-21 22:42 -------- d-----w- c:\users\Cindy\AppData\Local\Adobe
2010-01-21 00:41 . 2010-01-23 23:33 -------- d-----w- c:\users\Cindy\AppData\Roaming\skypePM
2010-01-19 19:12 . 2010-01-19 19:12 -------- d-----w- c:\users\Cindy\AppData\Local\Apple Computer
2010-01-19 16:27 . 2010-01-19 16:28 -------- d-----w- c:\users\Richard Abare\AppData\Local\Adobe
2010-01-18 14:02 . 2010-01-14 16:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-18 13:24 . 2010-01-30 18:43 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Skype
2010-01-17 23:22 . 2010-01-17 23:22 -------- d-----w- c:\windows\55A6283C638A4EE0B49151118554BDA2.TMP
2010-01-17 22:47 . 2010-01-20 18:57 -------- d-----w- c:\users\Richard Abare\AppData\Local\avjpod
2010-01-17 21:52 . 2010-01-17 21:52 -------- d-----w- c:\windows\Sun
2010-01-13 13:52 . 2010-01-13 13:59 -------- d-----w- C:\a55246872a5f253742d9d07fa527
2010-01-13 13:09 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 13:09 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 13:48 . 2009-08-03 04:31 119680 ----a-w- c:\users\Richard Abare\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-04 15:43 . 2009-08-10 02:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 14:55 . 2009-09-27 21:04 -------- d-----w- c:\program files\iPod
2010-02-04 14:55 . 2009-09-27 20:59 -------- d-----w- c:\program files\Common Files\Apple
2010-01-31 15:39 . 2010-01-03 19:18 680 ----a-w- c:\users\Richard Abare\AppData\Local\d3d9caps.dat
2010-01-28 22:06 . 2008-05-05 18:34 -------- d-----w- c:\program files\Google
2010-01-28 22:04 . 2009-08-10 02:21 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-28 11:47 . 2009-10-10 14:21 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:41 . 2008-05-05 18:33 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 17:39 . 2008-05-05 18:33 -------- d-----w- c:\program files\Java
2010-01-23 23:36 . 2009-12-09 19:48 -------- d-----w- c:\users\Cindy\AppData\Roaming\Skype
2010-01-22 15:43 . 2009-09-24 14:03 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 15:20 . 2009-08-11 14:35 -------- d-----w- c:\programdata\Intuit
2010-01-20 14:21 . 2008-05-13 17:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 23:23 . 2008-05-05 18:50 -------- d-----w- c:\programdata\Symantec
2010-01-17 23:22 . 2008-05-05 18:49 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-17 23:19 . 2008-05-05 18:52 -------- d-----w- c:\program files\Norton 360
2010-01-17 12:14 . 2009-08-13 16:47 -------- d-----w- c:\program files\Sprint Instinct Applications
2010-01-13 14:00 . 2009-08-03 06:42 -------- d-----w- c:\programdata\Microsoft Help
2010-01-13 13:59 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-07 21:07 . 2009-08-10 02:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-08-10 02:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 19:16 . 2009-08-03 07:09 -------- d-----w- c:\program files\Atheros
2010-01-03 19:15 . 2010-01-03 19:15 -------- d-----w- c:\program files\Cisco
2010-01-03 19:08 . 2009-10-22 15:36 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\InstallShield
2010-01-02 17:21 . 2010-01-02 17:21 -------- d-----w- c:\program files\Citrix
2010-01-02 17:21 . 2010-01-02 17:21 70984 ----a-w- c:\users\Richard Abare\g2mdlhlpx.exe
2010-01-02 06:38 . 2010-01-22 13:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 13:28 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 13:28 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 13:28 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-27 14:08 . 2009-12-27 14:08 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-27 14:07 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live
2009-12-27 14:06 . 2009-12-27 14:06 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-27 14:05 . 2009-12-27 14:05 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-27 14:04 . 2009-12-27 13:57 -------- d-----w- c:\program files\Microsoft
2009-12-27 14:03 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-27 13:58 . 2009-12-27 13:58 -------- d-----w- c:\program files\Common Files\Windows Live
2009-12-27 10:33 . 2009-12-27 10:33 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Amazon
2009-12-22 15:15 . 2009-12-22 15:15 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-20 15:53 . 2009-12-20 15:53 234016 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-12-14 18:41 . 2009-12-14 18:41 2353992 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-07 18:34 . 2009-12-07 18:34 314712 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-07 18:34 . 2009-12-07 18:34 25440 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-12-07 18:34 . 2009-12-07 18:34 15688 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-07 18:34 . 2009-12-07 18:34 168800 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-07 18:34 . 2009-12-07 18:34 349008 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-07 18:34 . 2009-12-07 18:34 17632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2009-12-07 18:34 . 2009-12-07 18:34 298336 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-07 18:34 . 2009-12-07 18:34 84320 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-07 18:32 . 2009-12-07 18:32 1630560 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-07 18:32 . 2009-12-07 18:32 246640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-07 18:32 . 2009-12-07 18:32 40288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-07 18:31 . 2009-12-07 18:31 68640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 303976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-14 18:42 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 64160 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 85352 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-07 18:31 664936 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-07 18:31 . 2009-12-07 18:31 3695616 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-07 18:29 . 2009-12-07 18:29 562552 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-07 18:29 . 2009-12-07 18:29 566632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-07 18:28 . 2009-12-07 18:28 640760 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-12-07 18:28 . 2009-12-07 18:28 520024 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-07 18:25 . 2009-12-07 18:25 1028432 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-05 13:42 . 2009-12-05 13:42 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb2558.tmp.exe
2009-12-03 19:14 . 2009-08-11 21:09 119680 ----a-w- c:\users\Veda\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-03 14:27 . 2009-12-03 14:27 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2009-12-03 14:27 . 2009-07-22 15:24 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-12-01 23:30 . 2009-08-10 11:43 119680 ----a-w- c:\users\Cindy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\DesktopMgr.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-11-26 15:28 . 2009-11-26 15:28 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-11-17 13:13 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\DesktopMgr.exe
2009-11-09 22:28 . 2009-10-24 17:58 680 ----a-w- c:\users\Veda\AppData\Local\d3d9caps.dat
2009-11-09 12:31 . 2009-12-11 18:33 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-11 18:33 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-11 18:33 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-08-03 04:30 . 2009-08-03 04:30 15 --sh--r- c:\windows\System32\drivers\fbd.sys
2009-08-03 04:30 . 2009-08-03 04:30 6 --sh--r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-20 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-03-19 716800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-14 98304]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-12-07 520024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-25 988512]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
c:\users\Cindy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-9-10 984352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):3b,70,56,c5,30,3a,ca,01
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [12/14/2009 1:42 PM 64160]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [8/3/2009 2:11 AM 20384]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [8/13/2009 9:15 PM 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [1/31/2010 6:34 PM 108289]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [4/17/2008 2:19 AM 40960]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1028432]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/17/2008 4:37 PM 149352]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [5/5/2008 1:06 PM 7168]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [4/24/2008 8:35 PM 73728]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 12:19 PM 135664]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/11/2008 11:32 PM 23888]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [12/27/2009 9:08 AM 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [8/3/2009 2:11 AM 954368]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-02-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:29]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]
2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{6F6388E8-E3A2-4FA3-BBA6-F552F9A58020}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{830FAA70-CE2D-4248-8F80-6AFD8F5C3873}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - prefs.js: network.proxy.type - 4
FF - component: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-FBSSA - c:\program files\SGPSA\ie3sh.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-02-05 16:37
Windows 6.0.6002 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
FBSSA = c:\program files\SGPSA\ie3sh.exe?Fast Browser Search\?.*???????????????????????????????????????????
scanning hȋdden files ...
c:\users\RICHAR~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hȋdden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-05 16:40:14
ComboFix-quarantined-files.txt 2010-02-05 21:40
Pre-Run: 122,384,326,656 bytes free
Post-Run: 123,387,977,728 bytes free
- - End Of File - - 8A1B9778618E78E01639E0BF06039AFD
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2813.1810 [GMT -5:00]
Running from: c:\users\Richard Abare\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3270954652-3410097223-3268541396-500
C:\LOG.TXT
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 21:35 . 2010-02-05 21:37 -------- d-----w- c:\users\Richard Abare\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Veda\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Cindy\AppData\Local\temp
2010-02-04 14:55 . 2010-02-04 14:56 -------- d-----w- c:\program files\iTunes
2010-02-04 14:50 . 2010-02-04 14:50 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-31 23:34 . 2010-02-01 00:25 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-31 23:34 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\programdata\Avira
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\program files\Avira
2010-01-31 21:51 . 2010-01-31 21:51 -------- d-----w- c:\users\Richard Abare\AppData\Local\IsolatedStorage
2010-01-31 21:50 . 2010-01-31 21:51 -------- d-----w- c:\program files\Virtual Earth 3D
2010-01-25 17:59 . 2010-01-25 17:59 -------- d-----w- c:\users\Richard Abare\AppData\Local\Cooliris
2010-01-25 17:58 . 2010-01-06 17:08 4726272 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-01-25 17:58 . 2010-01-06 17:08 103424 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-01-25 17:58 . 2010-01-06 17:08 57856 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-01-25 17:58 . 2010-01-06 17:08 545280 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-01-25 17:58 . 2010-01-06 17:08 4725760 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-01-25 17:58 . 2010-01-06 17:08 153600 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-01-25 17:58 . 2010-01-06 17:08 344064 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-01-25 17:41 . 2010-01-25 17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-21 22:42 . 2010-01-21 22:42 -------- d-----w- c:\users\Cindy\AppData\Local\Adobe
2010-01-21 00:41 . 2010-01-23 23:33 -------- d-----w- c:\users\Cindy\AppData\Roaming\skypePM
2010-01-19 19:12 . 2010-01-19 19:12 -------- d-----w- c:\users\Cindy\AppData\Local\Apple Computer
2010-01-19 16:27 . 2010-01-19 16:28 -------- d-----w- c:\users\Richard Abare\AppData\Local\Adobe
2010-01-18 14:02 . 2010-01-14 16:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-18 13:24 . 2010-01-30 18:43 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Skype
2010-01-17 23:22 . 2010-01-17 23:22 -------- d-----w- c:\windows\55A6283C638A4EE0B49151118554BDA2.TMP
2010-01-17 22:47 . 2010-01-20 18:57 -------- d-----w- c:\users\Richard Abare\AppData\Local\avjpod
2010-01-17 21:52 . 2010-01-17 21:52 -------- d-----w- c:\windows\Sun
2010-01-13 13:52 . 2010-01-13 13:59 -------- d-----w- C:\a55246872a5f253742d9d07fa527
2010-01-13 13:09 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 13:09 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 13:48 . 2009-08-03 04:31 119680 ----a-w- c:\users\Richard Abare\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-04 15:43 . 2009-08-10 02:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 14:55 . 2009-09-27 21:04 -------- d-----w- c:\program files\iPod
2010-02-04 14:55 . 2009-09-27 20:59 -------- d-----w- c:\program files\Common Files\Apple
2010-01-31 15:39 . 2010-01-03 19:18 680 ----a-w- c:\users\Richard Abare\AppData\Local\d3d9caps.dat
2010-01-28 22:06 . 2008-05-05 18:34 -------- d-----w- c:\program files\Google
2010-01-28 22:04 . 2009-08-10 02:21 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-28 11:47 . 2009-10-10 14:21 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:41 . 2008-05-05 18:33 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 17:39 . 2008-05-05 18:33 -------- d-----w- c:\program files\Java
2010-01-23 23:36 . 2009-12-09 19:48 -------- d-----w- c:\users\Cindy\AppData\Roaming\Skype
2010-01-22 15:43 . 2009-09-24 14:03 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 15:20 . 2009-08-11 14:35 -------- d-----w- c:\programdata\Intuit
2010-01-20 14:21 . 2008-05-13 17:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 23:23 . 2008-05-05 18:50 -------- d-----w- c:\programdata\Symantec
2010-01-17 23:22 . 2008-05-05 18:49 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-17 23:19 . 2008-05-05 18:52 -------- d-----w- c:\program files\Norton 360
2010-01-17 12:14 . 2009-08-13 16:47 -------- d-----w- c:\program files\Sprint Instinct Applications
2010-01-13 14:00 . 2009-08-03 06:42 -------- d-----w- c:\programdata\Microsoft Help
2010-01-13 13:59 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-07 21:07 . 2009-08-10 02:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-08-10 02:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 19:16 . 2009-08-03 07:09 -------- d-----w- c:\program files\Atheros
2010-01-03 19:15 . 2010-01-03 19:15 -------- d-----w- c:\program files\Cisco
2010-01-03 19:08 . 2009-10-22 15:36 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\InstallShield
2010-01-02 17:21 . 2010-01-02 17:21 -------- d-----w- c:\program files\Citrix
2010-01-02 17:21 . 2010-01-02 17:21 70984 ----a-w- c:\users\Richard Abare\g2mdlhlpx.exe
2010-01-02 06:38 . 2010-01-22 13:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 13:28 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 13:28 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 13:28 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-27 14:08 . 2009-12-27 14:08 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-27 14:07 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live
2009-12-27 14:06 . 2009-12-27 14:06 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-27 14:05 . 2009-12-27 14:05 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-27 14:04 . 2009-12-27 13:57 -------- d-----w- c:\program files\Microsoft
2009-12-27 14:03 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-27 13:58 . 2009-12-27 13:58 -------- d-----w- c:\program files\Common Files\Windows Live
2009-12-27 10:33 . 2009-12-27 10:33 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Amazon
2009-12-22 15:15 . 2009-12-22 15:15 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-20 15:53 . 2009-12-20 15:53 234016 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-12-14 18:41 . 2009-12-14 18:41 2353992 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-07 18:34 . 2009-12-07 18:34 314712 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-07 18:34 . 2009-12-07 18:34 25440 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-12-07 18:34 . 2009-12-07 18:34 15688 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-07 18:34 . 2009-12-07 18:34 168800 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-07 18:34 . 2009-12-07 18:34 349008 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-07 18:34 . 2009-12-07 18:34 17632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2009-12-07 18:34 . 2009-12-07 18:34 298336 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-07 18:34 . 2009-12-07 18:34 84320 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-07 18:32 . 2009-12-07 18:32 1630560 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-07 18:32 . 2009-12-07 18:32 246640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-07 18:32 . 2009-12-07 18:32 40288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-07 18:31 . 2009-12-07 18:31 68640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 303976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-14 18:42 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 64160 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 85352 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-07 18:31 664936 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-07 18:31 . 2009-12-07 18:31 3695616 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-07 18:29 . 2009-12-07 18:29 562552 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-07 18:29 . 2009-12-07 18:29 566632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-07 18:28 . 2009-12-07 18:28 640760 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-12-07 18:28 . 2009-12-07 18:28 520024 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-07 18:25 . 2009-12-07 18:25 1028432 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-05 13:42 . 2009-12-05 13:42 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb2558.tmp.exe
2009-12-03 19:14 . 2009-08-11 21:09 119680 ----a-w- c:\users\Veda\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-03 14:27 . 2009-12-03 14:27 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2009-12-03 14:27 . 2009-07-22 15:24 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-12-01 23:30 . 2009-08-10 11:43 119680 ----a-w- c:\users\Cindy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\DesktopMgr.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-11-26 15:28 . 2009-11-26 15:28 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-11-17 13:13 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\DesktopMgr.exe
2009-11-09 22:28 . 2009-10-24 17:58 680 ----a-w- c:\users\Veda\AppData\Local\d3d9caps.dat
2009-11-09 12:31 . 2009-12-11 18:33 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-11 18:33 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-11 18:33 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-08-03 04:30 . 2009-08-03 04:30 15 --sh--r- c:\windows\System32\drivers\fbd.sys
2009-08-03 04:30 . 2009-08-03 04:30 6 --sh--r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-20 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-03-19 716800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-14 98304]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-12-07 520024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-25 988512]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
c:\users\Cindy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-9-10 984352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):3b,70,56,c5,30,3a,ca,01
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [12/14/2009 1:42 PM 64160]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [8/3/2009 2:11 AM 20384]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [8/13/2009 9:15 PM 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [1/31/2010 6:34 PM 108289]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [4/17/2008 2:19 AM 40960]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1028432]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/17/2008 4:37 PM 149352]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [5/5/2008 1:06 PM 7168]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [4/24/2008 8:35 PM 73728]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 12:19 PM 135664]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/11/2008 11:32 PM 23888]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [12/27/2009 9:08 AM 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [8/3/2009 2:11 AM 954368]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-02-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:29]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]
2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{6F6388E8-E3A2-4FA3-BBA6-F552F9A58020}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{830FAA70-CE2D-4248-8F80-6AFD8F5C3873}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - prefs.js: network.proxy.type - 4
FF - component: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-FBSSA - c:\program files\SGPSA\ie3sh.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-02-05 16:37
Windows 6.0.6002 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
FBSSA = c:\program files\SGPSA\ie3sh.exe?Fast Browser Search\?.*???????????????????????????????????????????
scanning hȋdden files ...
c:\users\RICHAR~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hȋdden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-05 16:40:14
ComboFix-quarantined-files.txt 2010-02-05 21:40
Pre-Run: 122,384,326,656 bytes free
Post-Run: 123,387,977,728 bytes free
- - End Of File - - 8A1B9778618E78E01639E0BF06039AFD

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
Hello.
Please download the [You must be registered and logged in to see this link.].
Please post the OTMoveIt log.
Please download the [You must be registered and logged in to see this link.].
- Save it to your desktop.
- Please double-click OTM.exe to run it.
- Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:files
c:\program files\SGPSA
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FBSSA"=- - Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt
Please post the OTMoveIt log.



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
========== FILES ==========
File/Folder c:\program files\SGPSA not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\FBSSA not found.
OTM by OldTimer - Version 3.1.8.0 log created on 02052010_180117
File/Folder c:\program files\SGPSA not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\FBSSA not found.
OTM by OldTimer - Version 3.1.8.0 log created on 02052010_180117

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:
ComboFix /uninstall
This will also reset your restore points.
How is the machine running now?
ComboFix /uninstall
This will also reset your restore points.
How is the machine running now?



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
When I clicked on the link for these response I got the pop up warning again the windows could not find this website, although it did open?
Just not sure whats up..
Just not sure whats up..

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
What browser are you using?



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Re: Pop up warning
I use firefox..
I use windows mail for email..
I use windows mail for email..

rabare
Newbie Surfer
- Posts: 31
Joined: 2010-01-18
Operating System: Vista
Re: Pop up warning
Please download [You must be registered and logged in to see this link.] to your desktop
Let me know if you still get them errors.
- Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- It will close all programs when run, so make sure you have saved all your work before you begin.
- Click the Start
button to begin the process. Depending on how often you clean temp
files, execution time should be anywhere from a few seconds to a minute
or two. Let it run uninterrupted to completion. - Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
Let me know if you still get them errors.



From now on, I will no longer answer any requests for help via PM, please post in the forum.
If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.
"Dark Saviour, he can save you"

Belahzur
Super Moderator | Tech Officer
- Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre
Page 2 of 4 •
1, 2, 3, 4 
Permissions of this forum:
You cannot reply to topics in this forum











by 