GeekPolice
Welcome to GeekPolice.net!

GeekPolice is a website which provides free Computer Technical Support & Virus/Spyware Removal to our members.

You are currently viewing the forum as "Guest" which doesn't give you the same privilege as members to ask questions or post comments.

Click the Register button below to unlock the limitations of this website and start asking questions to discover new computer knowledge now!

Pop up warning

Post new topic   Reply to topic

Page 2 of 4 Previous  1, 2, 3, 4  Next

View previous topic View next topic Go down

Pop up warning

Post by rabare on Sun 31 Jan 2010, 11:08 am

First topic message reminder :

Everytime I click a link I get a pop up that says windows cannot find that web address.
Anyone have a clue why this is happening..
Thanks in advance

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down


I am still getting these pop ups

Post by rabare on Fri 05 Feb 2010, 7:59 am

Windows cannot find 'http:www.website.com'.
.
Make sure you typed the name correctly, then try again.
I get this everytime I click a link from my email or a web page.
But the page always open up?
There is a red circle w. an X and a OK button in the pop up.
I tried to do a screen shot w/ the pop up warning but it will not work.
Again thanks for all your help...

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 10:49 am

1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to svchost as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on svchost.exe.
  • Follow the prompts. NOTE:
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 11:15 am

Caused my computer to crash?
It started in on a dos screen..
As it was running I got a blue scrambbled screen That had type saying my system crashed to reboot...

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 11:17 am

I did disable my Avira Antivirus...
I did get a warning that I should run fix from a different site?

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 12:44 pm

Did Combofix warn of Virut?






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 2:57 pm

never finished because it crashed....
SHould I try again?

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 3:07 pm

Yes please.






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 3:42 pm

ComboFix 10-02-05.02 - Richard Abare 02/05/2010 16:27:54.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2813.1810 [GMT -5:00]
Running from: c:\users\Richard Abare\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3270954652-3410097223-3268541396-500
C:\LOG.TXT

.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.

2010-02-05 21:35 . 2010-02-05 21:37 -------- d-----w- c:\users\Richard Abare\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Veda\AppData\Local\temp
2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\users\Cindy\AppData\Local\temp
2010-02-04 14:55 . 2010-02-04 14:56 -------- d-----w- c:\program files\iTunes
2010-02-04 14:50 . 2010-02-04 14:50 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-31 23:34 . 2010-02-01 00:25 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-31 23:34 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\programdata\Avira
2010-01-31 23:34 . 2010-01-31 23:34 -------- d-----w- c:\program files\Avira
2010-01-31 21:51 . 2010-01-31 21:51 -------- d-----w- c:\users\Richard Abare\AppData\Local\IsolatedStorage
2010-01-31 21:50 . 2010-01-31 21:51 -------- d-----w- c:\program files\Virtual Earth 3D
2010-01-25 17:59 . 2010-01-25 17:59 -------- d-----w- c:\users\Richard Abare\AppData\Local\Cooliris
2010-01-25 17:58 . 2010-01-06 17:08 4726272 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-01-25 17:58 . 2010-01-06 17:08 103424 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-01-25 17:58 . 2010-01-06 17:08 57856 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-01-25 17:58 . 2010-01-06 17:08 545280 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-01-25 17:58 . 2010-01-06 17:08 4725760 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-01-25 17:58 . 2010-01-06 17:08 153600 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-01-25 17:58 . 2010-01-06 17:08 344064 ----a-w- c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-01-25 17:41 . 2010-01-25 17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-21 22:42 . 2010-01-21 22:42 -------- d-----w- c:\users\Cindy\AppData\Local\Adobe
2010-01-21 00:41 . 2010-01-23 23:33 -------- d-----w- c:\users\Cindy\AppData\Roaming\skypePM
2010-01-19 19:12 . 2010-01-19 19:12 -------- d-----w- c:\users\Cindy\AppData\Local\Apple Computer
2010-01-19 16:27 . 2010-01-19 16:28 -------- d-----w- c:\users\Richard Abare\AppData\Local\Adobe
2010-01-18 14:02 . 2010-01-14 16:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-18 13:24 . 2010-01-30 18:43 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Skype
2010-01-17 23:22 . 2010-01-17 23:22 -------- d-----w- c:\windows\55A6283C638A4EE0B49151118554BDA2.TMP
2010-01-17 22:47 . 2010-01-20 18:57 -------- d-----w- c:\users\Richard Abare\AppData\Local\avjpod
2010-01-17 21:52 . 2010-01-17 21:52 -------- d-----w- c:\windows\Sun
2010-01-13 13:52 . 2010-01-13 13:59 -------- d-----w- C:\a55246872a5f253742d9d07fa527
2010-01-13 13:09 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 13:09 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 13:48 . 2009-08-03 04:31 119680 ----a-w- c:\users\Richard Abare\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-04 15:43 . 2009-08-10 02:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 14:55 . 2009-09-27 21:04 -------- d-----w- c:\program files\iPod
2010-02-04 14:55 . 2009-09-27 20:59 -------- d-----w- c:\program files\Common Files\Apple
2010-01-31 15:39 . 2010-01-03 19:18 680 ----a-w- c:\users\Richard Abare\AppData\Local\d3d9caps.dat
2010-01-28 22:06 . 2008-05-05 18:34 -------- d-----w- c:\program files\Google
2010-01-28 22:04 . 2009-08-10 02:21 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-28 11:47 . 2009-10-10 14:21 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:41 . 2008-05-05 18:33 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 17:39 . 2008-05-05 18:33 -------- d-----w- c:\program files\Java
2010-01-23 23:36 . 2009-12-09 19:48 -------- d-----w- c:\users\Cindy\AppData\Roaming\Skype
2010-01-22 15:43 . 2009-09-24 14:03 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 15:20 . 2009-08-11 14:35 -------- d-----w- c:\programdata\Intuit
2010-01-20 14:21 . 2008-05-13 17:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 23:23 . 2008-05-05 18:50 -------- d-----w- c:\programdata\Symantec
2010-01-17 23:22 . 2008-05-05 18:49 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-17 23:19 . 2008-05-05 18:52 -------- d-----w- c:\program files\Norton 360
2010-01-17 12:14 . 2009-08-13 16:47 -------- d-----w- c:\program files\Sprint Instinct Applications
2010-01-13 14:00 . 2009-08-03 06:42 -------- d-----w- c:\programdata\Microsoft Help
2010-01-13 13:59 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-07 21:07 . 2009-08-10 02:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-08-10 02:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 19:16 . 2009-08-03 07:09 -------- d-----w- c:\program files\Atheros
2010-01-03 19:15 . 2010-01-03 19:15 -------- d-----w- c:\program files\Cisco
2010-01-03 19:08 . 2009-10-22 15:36 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\InstallShield
2010-01-02 17:21 . 2010-01-02 17:21 -------- d-----w- c:\program files\Citrix
2010-01-02 17:21 . 2010-01-02 17:21 70984 ----a-w- c:\users\Richard Abare\g2mdlhlpx.exe
2010-01-02 06:38 . 2010-01-22 13:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 13:28 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 13:28 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 13:28 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-27 14:08 . 2009-12-27 14:08 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-27 14:07 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live
2009-12-27 14:06 . 2009-12-27 14:06 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-27 14:05 . 2009-12-27 14:05 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-27 14:04 . 2009-12-27 13:57 -------- d-----w- c:\program files\Microsoft
2009-12-27 14:03 . 2009-12-27 14:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-27 13:58 . 2009-12-27 13:58 -------- d-----w- c:\program files\Common Files\Windows Live
2009-12-27 10:33 . 2009-12-27 10:33 -------- d-----w- c:\users\Richard Abare\AppData\Roaming\Amazon
2009-12-22 15:15 . 2009-12-22 15:15 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-20 15:53 . 2009-12-20 15:53 234016 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-12-14 18:41 . 2009-12-14 18:41 2353992 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-07 18:34 . 2009-12-07 18:34 314712 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-07 18:34 . 2009-12-07 18:34 25440 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-12-07 18:34 . 2009-12-07 18:34 15688 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-07 18:34 . 2009-12-07 18:34 168800 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-07 18:34 . 2009-12-07 18:34 349008 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-07 18:34 . 2009-12-07 18:34 17632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2009-12-07 18:34 . 2009-12-07 18:34 298336 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-07 18:34 . 2009-12-07 18:34 84320 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-07 18:32 . 2009-12-07 18:32 1630560 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-07 18:32 . 2009-12-07 18:32 246640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-07 18:32 . 2009-12-07 18:32 40288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-07 18:31 . 2009-12-07 18:31 68640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 303976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-14 18:42 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 64160 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-12-07 18:31 . 2009-12-07 18:31 85352 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-12-07 18:31 . 2009-12-07 18:31 664936 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-07 18:31 . 2009-12-07 18:31 3695616 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-07 18:29 . 2009-12-07 18:29 562552 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-07 18:29 . 2009-12-07 18:29 566632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-07 18:28 . 2009-12-07 18:28 640760 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-12-07 18:28 . 2009-12-07 18:28 520024 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-07 18:25 . 2009-12-07 18:25 1028432 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-05 13:42 . 2009-12-05 13:42 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb2558.tmp.exe
2009-12-03 19:14 . 2009-08-11 21:09 119680 ----a-w- c:\users\Veda\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-03 14:27 . 2009-12-03 14:27 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2009-12-03 14:27 . 2009-07-22 15:24 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-12-01 23:30 . 2009-08-10 11:43 119680 ----a-w- c:\users\Cindy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-12-01 16:02 . 2009-12-01 16:02 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\DesktopMgr.exe
2009-12-01 16:02 . 2009-12-01 16:02 49152 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-11-26 15:28 . 2009-11-26 15:28 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-11-17 13:13 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-11-12 18:59 . 2009-11-12 18:59 69632 ----a-r- c:\users\Richard Abare\AppData\Roaming\Microsoft\Installer\{1BD05B04-7A33-409A-A714-613163E41935}\DesktopMgr.exe
2009-11-09 22:28 . 2009-10-24 17:58 680 ----a-w- c:\users\Veda\AppData\Local\d3d9caps.dat
2009-11-09 12:31 . 2009-12-11 18:33 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-11 18:33 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-11 18:33 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-08-03 04:30 . 2009-08-03 04:30 15 --sh--r- c:\windows\System32\drivers\fbd.sys
2009-08-03 04:30 . 2009-08-03 04:30 6 --sh--r- c:\windows\System32\drivers\taishop.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-20 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-03-19 716800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-14 98304]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-12-07 520024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-25 988512]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\users\Cindy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-9-10 984352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):3b,70,56,c5,30,3a,ca,01

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [12/14/2009 1:42 PM 64160]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [8/3/2009 2:11 AM 20384]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [8/13/2009 9:15 PM 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [1/31/2010 6:34 PM 108289]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [4/17/2008 2:19 AM 40960]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1028432]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/17/2008 4:37 PM 149352]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [5/5/2008 1:06 PM 7168]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [4/24/2008 8:35 PM 73728]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 12:19 PM 135664]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/11/2008 11:32 PM 23888]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [12/27/2009 9:08 AM 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [8/3/2009 2:11 AM 954368]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:29]

2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]

2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 17:18]

2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{6F6388E8-E3A2-4FA3-BBA6-F552F9A58020}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]

2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{830FAA70-CE2D-4248-8F80-6AFD8F5C3873}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - prefs.js: network.proxy.type - 4
FF - component: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Richard Abare\AppData\Roaming\Mozilla\Firefox\Profiles\3iipee3r.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-FBSSA - c:\program files\SGPSA\ie3sh.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-02-05 16:37
Windows 6.0.6002 Service Pack 2 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
FBSSA = c:\program files\SGPSA\ie3sh.exe?Fast Browser Search\?.*???????????????????????????????????????????

scanning hȋdden files ...


c:\users\RICHAR~1\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hȋdden files: 1

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-05 16:40:14
ComboFix-quarantined-files.txt 2010-02-05 21:40

Pre-Run: 122,384,326,656 bytes free
Post-Run: 123,387,977,728 bytes free

- - End Of File - - 8A1B9778618E78E01639E0BF06039AFD

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 4:23 pm

Hello.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :files
    c:\program files\SGPSA

    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "FBSSA"=-


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 5:02 pm

========== FILES ==========
File/Folder c:\program files\SGPSA not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\FBSSA not found.

OTM by OldTimer - Version 3.1.8.0 log created on 02052010_180117

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 5:19 pm

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 5:47 pm

When I clicked on the link for these response I got the pop up warning again the windows could not find this website, although it did open?
Just not sure whats up..

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 6:14 pm

What browser are you using?






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: Pop up warning

Post by rabare on Fri 05 Feb 2010, 6:32 pm

I use firefox..
I use windows mail for email..

rabare

Newbie Surfer
Newbie Surfer

Posts: 31
Joined: 2010-01-18
Operating System: Vista

View user profile

Back to top Go down

Re: Pop up warning

Post by Belahzur on Fri 05 Feb 2010, 6:36 pm

Please download [You must be registered and logged in to see this link.] to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


Let me know if you still get them errors.






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 25971
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Page 2 of 4 Previous  1, 2, 3, 4  Next

View previous topic View next topic Back to top


Permissions of this forum:
You cannot reply to topics in this forum