Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

PC virus

  • 09-05-2008 5:27pm
    #1
    Registered Users, Registered Users 2 Posts: 10


    I read the thread by Aidan Walsh on what do do and ran all the antivirus and antispyware and nothing showed so I will post the script from the last scan of Deckards scan.

    Basically a few weeks ago I got a virus and it deleted all my photos, music, docs etc. So put pctools antispyware and the full AVG 8 version on my pc.
    But last week I sync'd my sony MP3 and all the music deleted from the player and all my photos uploaded onto the player with my instruction. Also recently the dial-up modem keeps popping up and it sends my internet to offline even though I have broadband.
    I ran the antivirus on safemode and there was various trojans showing like killav and zapchast. But everytime I run antivirus they don't show. I think there is something lurking in the background hiding from me. Any help would be greatly appreciated.

    Deckard's System Scanner v20071014.68
    Run by admin on 2008-05-09 17:56:58
    Computer is in Normal Mode.
    -- System Restore
    Successfully created a Deckard's System Scanner Restore Point.

    -- Last 5 Restore Point(s) --
    117: 2008-05-09 16:57:05 UTC - RP659 - Deckard's System Scanner Restore Point
    116: 2008-05-08 17:22:36 UTC - RP658 - Installed SUPERAntiSpyware Free Edition
    115: 2008-05-08 16:25:13 UTC - RP657 - Removed Google Toolbar for Internet Explorer
    114: 2008-05-07 20:52:11 UTC - RP656 - System Checkpoint
    113: 2008-05-06 16:44:48 UTC - RP655 - System Checkpoint

    -- First Restore Point --
    1: 2008-02-09 20:34:36 UTC - RP543 - System Checkpoint

    Backed up registry hives.
    Performed disk cleanup.

    -- HijackThis Clone

    Emulating logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2008-05-09 17:58:44
    Platform: Windows XP Service Pack 2 (5.01.2600)
    MSIE: Internet Explorer (7.00.6000.16640)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\system32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\AVG\AVG8\avgfws8.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\system32\msdtc.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\FixCamera.exe
    C:\Program Files\AVG\AVG8\avgam.exe
    C:\WINDOWS\tsnp2std.exe
    C:\WINDOWS\vsnp2std.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Creative\Mixer\CTSVolFE.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\WINDOWS\system32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\WINDOWS\system32\alg.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\FixCamera.exe
    C:\WINDOWS\tsnp2std.exe
    C:\WINDOWS\vsnp2std.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Creative\Mixer\CTSVolFE.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\AVG\AVG8\avgnsx.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\JNCXNE9M\dss[1].exe
    C:\WINDOWS\system32\wuauclt.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eircom.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
    O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
    O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
    O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [CTSVolFE] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ie\msntabres.dll.mui/229?7c12778d554040638e136b7abe2ad3ea
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ie\msntabres.dll.mui/230?7c12778d554040638e136b7abe2ad3ea
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - [URL]file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx[/URL]
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} () -
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158868176670
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1159452818515
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} () - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - [URL]file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx[/URL]
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
    O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
    O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
    O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
    O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
    O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgfws8.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 12119 bytes
    -- File Associations
    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
    R2 mdmxsdk - c:\windows\system32\drivers\mdmxsdk.sys <Not Verified; Conexant; Diagnostic Interface>
    R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>
    R3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>
    R3 HSFHWBS2 - c:\windows\system32\drivers\hsfhwbs2.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>
    R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
    R3 SNP2STD (USB2.0 PC Camera (SNP2STD)) - c:\windows\system32\drivers\snp2sxp.sys <Not Verified; ; USB2.0 PC Camera driver>
    R3 STHDA (SigmaTel High Definition Audio CODEC) - c:\windows\system32\drivers\sthda.sys <Not Verified; SigmaTel, Inc.; C-Major Audio>
    R3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
    R3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>
    S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
    S3 DCamUSBNW820 (DV) - c:\windows\system32\drivers\pccam.sys
    S3 htcpip6 - c:\docume~1\admin\locals~1\temp\htcpip6.sys (file missing)
    S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    All services whitelisted.

    -- Device Manager: Disabled
    Class GUID: TI Technologies Inc.
    Description: RADEON X300 SE 128MB HyperMemory Secondary
    Device ID: PCI\VEN_1002&DEV_5B70&SUBSYS_06031002&REV_00\4&1603E009&0&0108
    Manufacturer: ATI Technologies Inc.
    Name: RADEON X300 SE 128MB HyperMemory Secondary
    PNP Device ID: PCI\VEN_1002&DEV_5B70&SUBSYS_06031002&REV_00\4&1603E009&0&0108
    Service: ati2mtag

    -- Files created between 2008-04-09 and 2008-05-09
    2008-05-09 09:14:14 23600 --a
    C:\WINDOWS\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
    2008-05-08 19:32:45 0 d
    C:\WINDOWS\LastGood
    2008-05-08 19:32:45 0 d
    C:\Program Files\Panda Security
    2008-05-08 18:22:54 0 d
    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-05-08 18:22:38 0 d
    C:\Program Files\SUPERAntiSpyware
    2008-05-08 18:22:37 0 d
    C:\Documents and Settings\admin\Application Data\SUPERAntiSpyware.com
    2008-05-08 18:22:21 0 d
    C:\Program Files\Common Files\Wise Installation Wizard
    2008-05-08 17:41:13 0 d
    C:\WINDOWS\pss
    2008-05-07 21:23:30 0 d
    C:\Program Files\ThreatExpert Memory Scanner
    2008-05-07 17:45:17 0 dr-h
    C:\Documents and Settings\Administrator\Application Data
    2008-05-07 17:45:17 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
    2008-05-07 17:45:17 0 d
    C:\Documents and Settings\Administrator\Application Data\Apple Computer
    2008-05-07 17:45:16 0 d
    C:\Documents and Settings\Administrator\Favorites
    2008-05-07 17:45:16 0 d
    C:\Documents and Settings\Administrator\Desktop
    2008-05-07 17:45:16 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
    2008-05-07 17:45:15 0 dr-h
    C:\Documents and Settings\Administrator\SendTo
    2008-05-07 17:45:15 0 d--h
    C:\Documents and Settings\Administrator\Recent
    2008-05-07 17:45:15 0 d--h
    C:\Documents and Settings\Administrator\PrintHood
    2008-05-07 17:45:15 0 d--h
    C:\Documents and Settings\Administrator\NetHood
    2008-05-07 17:45:15 0 d
    C:\Documents and Settings\Administrator\My Documents
    2008-05-07 17:45:15 0 d--h
    C:\Documents and Settings\Administrator\Local Settings
    2008-05-07 17:45:14 0 d--h
    C:\Documents and Settings\Administrator\Templates
    2008-05-07 17:45:14 0 dr
    C:\Documents and Settings\Administrator\Start Menu
    2008-05-07 17:45:13 786432 --ah
    C:\Documents and Settings\Administrator\NTUSER.DAT
    2008-05-06 13:21:56 0 d
    C:\Program Files\McDonaldsFairies
    2008-04-30 19:19:23 0 d
    C:\Program Files\Bonusprint PIX
    2008-04-29 12:09:01 0 d
    C:\Program Files\Common Files\xing shared

    -- Find3M Report
    2008-05-09 17:50:00 0 d
    C:\Documents and Settings\admin\Application Data\Skype
    2008-05-09 13:19:51 0 d
    C:\Program Files\Spyware Doctor
    2008-05-08 18:22:21 0 d
    C:\Program Files\Common Files
    2008-05-08 17:44:20 0 d
    C:\Program Files\Google
    2008-04-29 12:08:45 0 d
    C:\Program Files\Common Files\Real
    2008-04-22 15:41:58 0 d
    C:\Documents and Settings\admin\Application Data\Real
    2008-04-09 20:25:26 0 d
    C:\Documents and Settings\admin\Application Data\Vso
    2008-03-18 21:31:14 0 d
    C:\Documents and Settings\admin\Application Data\CopyToDvd
    2008-03-16 16:44:23 0 d
    C:\Program Files\Apple Software Update
    2008-03-16 15:04:37 0 d
    C:\Program Files\Sony
    2008-03-16 15:04:37 0 d--h
    C:\Program Files\InstallShield Installation Information
    2008-03-15 20:14:13 0 d
    C:\Documents and Settings\admin\Application Data\PC Tools
    2008-03-13 22:49:38 0 d
    C:\Program Files\Migo Software
    2008-03-13 18:39:49 0 d
    C:\Documents and Settings\admin\Application Data\Media Player Classic
    2008-03-13 00:15:23 0 d
    C:\Program Files\Diskeeper Corporation
    2008-03-13 00:14:18 0 d
    C:\Documents and Settings\admin\Application Data\Diskeeper Corporation
    2008-03-12 22:58:30 0 d
    C:\Documents and Settings\admin\Application Data\AVGTOOLBAR
    2008-03-12 21:01:53 0 d
    C:\Program Files\AVG
    2008-03-12 20:12:20 0 d
    C:\Program Files\Dell
    2008-03-12 20:11:56 0 d
    C:\Documents and Settings\admin\Application Data\Symantec

    -- Registry Dump
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    28/03/2008 10:42 2051328 --a
    C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [28/03/2008 10:42 2051328]
    [-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
    [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [09/02/2006 10:05]
    "MsmqIntCert"="regsvr32 /s mqrt.dll" []
    "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [23/02/2005 04:19]
    "SigmatelSysTrayApp"="stsystra.exe" [22/03/2005 05:20 C:\WINDOWS\stsystra.exe]
    "FixCamera"="C:\WINDOWS\FixCamera.exe" [06/12/2005 01:08]
    "tsnp2std"="C:\WINDOWS\tsnp2std.exe" [24/11/2005 05:01]
    "snp2std"="C:\WINDOWS\vsnp2std.exe" [23/11/2005 10:00]
    "CmUsbSound"="cmcnfgu.cpl" []
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [11/12/2007 11:56]
    "CTSVolFE"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [23/02/2005 04:57]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 11:16]
    "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [28/03/2008 10:42]
    "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [01/02/2008 01:55]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [29/04/2008 12:08]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [10/08/2004 12:00]
    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [15/03/2007 11:09]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [19/01/2007 01:54]
    "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [13/10/2006 06:20]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [29/02/2008 04:03]
    C:\Documents and Settings\admin\Start Menu\Programs\Startup\
    Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [14/08/2006 10:11:59]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [24/06/2006 22:09:16]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=avgrsstx.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @=&quot;Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc
    *Newly Created Service* - RKPAVPROC
    *Newly Created Service* - SASDIFSV
    *Newly Created Service* - SASENUM
    *Newly Created Service* - SASKUTIL
    *Newly Created Service* - TVICHW32

    -- End of Deckard's System Scanner: finished at 2008-05-09 18:00:34
    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.
    -- System Information
    Microsoft Windows XP Professional (build 2600) SP 2.0
    Architecture: X86; Language: English
    CPU 0: Intel(R) Pentium(R) D CPU 2.80GHz
    CPU 1: Intel(R) Pentium(R) D CPU 2.80GHz
    Percentage of Memory in Use: 63%
    Physical Memory (total/avail): 1022.07 MiB / 370.29 MiB
    Pagefile Memory (total/avail): 2460.59 MiB / 1481.48 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1913.41 MiB
    C: is Fixed (NTFS) - 127.99 GiB total, 111.8 GiB free.
    D: is CDROM (No Media)
    E: is Removable (No Media)
    F: is Removable (No Media)
    G: is Removable (No Media)
    I: is Removable (No Media)
    [URL="file://\\.\PHYSICALDRIVE0"]\\.\PHYSICALDRIVE0[/URL] - ST3160812AS - 149.01 GiB - 1 partition
    \PARTITION0 (bootable) - Installable File System - 127.99 GiB - C:
    [URL="file://\\.\PHYSICALDRIVE1"]\\.\PHYSICALDRIVE1[/URL] - TEAC USB HS-CF Card USB Device
    [URL="file://\\.\PHYSICALDRIVE3"]\\.\PHYSICALDRIVE3[/URL] - TEAC USB HS-MS Card USB Device
    [URL="file://\\.\PHYSICALDRIVE4"]\\.\PHYSICALDRIVE4[/URL] - TEAC USB HS-SD Card USB Device
    [URL="file://\\.\PHYSICALDRIVE2"]\\.\PHYSICALDRIVE2[/URL] - TEAC USB HS-xD/SM USB Device

    -- Security Center
    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is disabled.
    FirstRunDisabled is set.
    AntiVirusDisableNotify is set.
    FirewallDisableNotify is set.
    FW: AVG Firewall v8.0 (AVG Technologies CZ, s.r.o.)
    AV: AVG Internet Security v8.0 (AVG Technologies)
    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
    "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

    -- Environment Variables
    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\admin\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=ADMIN-D82AMS0DZ
    ComSpec=C:\WINDOWS\system32\cmd.exe
    CWALTAHOME=C:\Program Files\ContentWatch
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\admin
    LOGONSERVER=\\ADMIN-D82AMS0DZ
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\WBEM;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 4, GenuineIntel
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=0404
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
    RNLOG_BASEKEY=Software\RealNetworks\RealPlayer\6.0\Preferences\BrowserRecordPluginLog
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\admin\LOCALS~1\Temp
    TMP=C:\DOCUME~1\admin\LOCALS~1\Temp
    USERDOMAIN=ADMIN-D82AMS0DZ
    USERNAME=admin
    USERPROFILE=C:\Documents and Settings\admin
    windir=C:\WINDOWS
    __COMPAT_LAYER=EnableNXShowUI

    -- User Profiles
    admin (admin)
    Shane (admin)
    ellen
    Paul (admin)
    Administrator (admin)

    -- Add/Remove Programs
    --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56EC9D19-61CD-4982-8634-F5CBF3ED5550}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7E9BE6D1-680B-49B2-A2B0-CBC32D20DF04}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x9 /removeonly -removeonly
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x9 /removeonly -removeonly
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x9 /removeonly -removeonly
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x9 /removeonly -removeonly
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
    ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    AVG 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
    C-Media USB Sound --> C:\WINDOWS\CmiUSB2Uninstall.exe C:\Program Files\C-Media USB Sound#C-Media USB Sound#C-Media USB Sound#
    C-Media USB Sound Driver --> C:\WINDOWS\system32\cmdrvrmu.exe
    Conexant D850 56K V.9x DFVc Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
    Dell Recommends --> "C:\Program Files\DellSupport\Direct.exe" remove
    Dell Resource CD --> MsiExec.exe /X{FCD9CD52-7222-4672-94A0-A722BA702FD0}
    DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
    Digital Camera Driver --> C:\PROGRA~1\DIGITA~2\UNWISE.EXE C:\PROGRA~1\DIGITA~2\INSTALL.LOG
    Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
    Disney Interactive Global Compatibility Update June 2003 --> C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{4acec804-8c2c-4c78-9127-6c6b756e44e2}.sdb"
    DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
    Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
    High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
    Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    Intel(R) PRO Network Connections Drivers --> Prounstl.exe
    InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
    Memory Stick File Rescue --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\Setup.exe" -l0x9
    Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Migo Digital Rescue 4 Premium --> "C:\WINDOWS\Digital Rescue 4 Premium\uninstall.exe" "/U:C:\Program Files\Migo Software\Digital Rescue 4 Premium\Uninstall\uninstall.xml"
    Mixer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7E9BE6D1-680B-49B2-A2B0-CBC32D20DF04}\setup.exe" -l0x9 /remove
    Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\admin\Application Data\Move Networks\ie_bin\Uninst.exe
    MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
    Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
    Peppa Pig --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A21BB2C2-B505-44B5-80D4-70233203FB6C}\setup.exe" -l0x9 -removeonly
    PowerDVD 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
    QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
    RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    SigmaTel Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
    Skype 2.5 --> "C:\Program Files\Skype\Phone\unins000.exe"
    Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
    Sony Picture Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x9 /removeonly uninstall -removeonly
    Sony USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\Setup.exe" UNINSTALL
    Sound Blaster Audigy ADVANCED MB Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56EC9D19-61CD-4982-8634-F5CBF3ED5550}\setup.exe" -l0x9 /remove
    Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
    SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
    Tabbed Browsing (Windows Live Toolbar) --> MsiExec.exe /X{47FBF7F9-FBD3-43EF-823B-7684D56C1962}
    tangram --> C:\WINDOWS\uninst.exe -f"C:\Program Files\MOSoft\tangram\DeIsL1.isu" -c"C:\Program Files\MOSoft\tangram\_ISREG32.DLL"
    USB2.0 PC Camera --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75438C0E-9925-412E-AD85-D0E71C6CE2ED}\Setup.exe" -l0x9
    VSO CopyToDVD 4 --> "C:\Program Files\VSO\unins000.exe"
    WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
    Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
    Windows Live Sign-in Assistant --> MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
    Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
    Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
    Windows Live Toolbar Extension (Windows Live Toolbar) --> MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
    Windows Live Toolbar Feed Detector (Windows Live Toolbar) --> MsiExec.exe /X{68108E66-D13A-4EE8-A6F4-40E4B90C2A26}
    Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"

    -- Application Event Log
    Event Record #/Type50160 / Warning
    Event Submitted/Written: 05/08/2008 05:52:05 PM
    Event ID/Source: 4147 / Ci
    Event Description:
    The IISADMIN service is not available, so virtual roots cannot be indexed.
    Event Record #/Type50145 / Success
    Event Submitted/Written: 05/08/2008 05:46:19 PM
    Event ID/Source: 12001 / usnjsvc
    Event Description:
    The Messenger Sharing USN Journal Reader service started successfully.
    Event Record #/Type50143 / Warning
    Event Submitted/Written: 05/08/2008 05:45:28 PM
    Event ID/Source: 1015 / EvntAgnt
    Event Description:
    TraceLevel parameter not located in registry;
    Default trace level used is 32.
    Event Record #/Type50142 / Warning
    Event Submitted/Written: 05/08/2008 05:45:28 PM
    Event ID/Source: 1003 / EvntAgnt
    Event Description:
    TraceFileName parameter not located in registry;
    Default trace file used is .
    Event Record #/Type50137 / Warning
    Event Submitted/Written: 05/08/2008 05:42:31 PM
    Event ID/Source: 1524 / Userenv
    Event Description:
    Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

    -- Security Event Log
    No Errors/Warnings found.

    -- System Event Log
    Event Record #/Type80983 / Error
    Event Submitted/Written: 05/09/2008 05:45:52 PM
    Event ID/Source: 32003 / ipnathlp
    Event Description:
    The Network Address Translator (NAT) was unable to request an operation
    of the kernel-mode translation module.
    This may indicate misconfiguration, insufficient resources, or
    an internal error.
    The data is the error code.
    Event Record #/Type80981 / Error
    Event Submitted/Written: 05/09/2008 05:45:48 PM
    Event ID/Source: 1002 / Dhcp
    Event Description:
    The IP address lease 192.168.1.33 for the Network Card with network address 001372CA1BED has been
    denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    Event Record #/Type80979 / Warning
    Event Submitted/Written: 05/09/2008 09:19:36 AM
    Event ID/Source: 8 / Print
    Event Description:
    Printer HP 2000C was purged.
    Event Record #/Type80977 / Warning
    Event Submitted/Written: 05/09/2008 07:24:39 AM
    Event ID/Source: 36 / W32Time
    Event Description:
    The time service has not been able to synchronize the system time
    for 49152 seconds because none of the time providers has been able to
    provide a usable time stamp. The system clock is unsynchronized.
    Event Record #/Type80949 / Error
    Event Submitted/Written: 05/08/2008 05:46:07 PM
    Event ID/Source: 7003 / Service Control Manager
    Event Description:
    The Simple Mail Transfer Protocol (SMTP) service depends on the following nonexistent service: IISADMIN

    -- End of Deckard's System Scanner: finished at 2008-05-09 18:00:34


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Looks ok

    1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner and click Accept

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.




        Download NIAP to your desktop and unzip it to it's own folder

        Close all windows and run NIAP_XRay_FileMgr
        • Click the Log tab at the top and click Create System log. Check the boxes beside Autorun.inf file. and System Critical Files and click OK. Save the log to your desktop and let the program run.
        • Exit out of NIAP_XRay_FileMgr


        Next run NIAP_XRay_Regedit
        • Click the Log tab then click on Get log. Once it is finished scanning, click Save and call the log NiapReg, then save it to your desktop
        • Exit out of NIAP_XRay_Regedit


        Finally run NIAP_XRay_System
        • Click the Log tab and click Create log. Check all the boxes and click Log, save it to your desktop. Let the program run.
        • Once it is done close the program and post the log back here along with the other two logs.


      • Registered Users, Registered Users 2 Posts: 10 Candy11


        I had a problem with the NIAP XRay File Mgr I did the log and ticked the two boxes and then a note popped up "ntdll.dll hooked, restore and when I clicked OK nothing happened.


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Ok leave that

        Go and run Kaspersky


      • Registered Users, Registered Users 2 Posts: 10 Candy11


        No Viruses found but these files could not be scanned as they were locked!

        C:\Documents and Settings\admin\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log
        Object is locked skipped C:\Documents and Settings\admin\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped C:\Documents and Settings\admin\Application Data\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped C:\Documents and Settings\admin\Application Data\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\call256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\callmember256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chat4096.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chat512.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chat8192.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chatmsg1024.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chatmsg2048.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chatmsg256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\chatmsg512.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\contactgroup256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\index2.dat Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\profile256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\user1024.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\user16384.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\user4096.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\Skype\acasserly\voicemail256.dbb Object is locked skipped C:\Documents and Settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-5-10-2008( 9-2-23 ).LOG Object is locked skipped C:\Documents and Settings\admin\Cookies\index.dat Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\pending.dat Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\Working\database_7A6C_BDE4_6CBD_9AF9\dfsr.db Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\Working\database_7A6C_BDE4_6CBD_9AF9\fsr.log Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\Working\database_7A6C_BDE4_6CBD_9AF9\fsrtmp.log Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Messenger\shanepcasserly@hotmail.com\SharingMetadata\Working\database_7A6C_BDE4_6CBD_9AF9\tmp.edb Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Windows Live Contacts\shanepcasserly@hotmail.com\real\members.stg Object is locked skipped C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Windows Live Contacts\shanepcasserly@hotmail.com\shadow\members.stg Object is locked skipped C:\Documents and Settings\admin\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DF8683.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DF8694.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DFA59F.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DFA69F.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DFDA7D.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temp\~DFDA98.tmp Object is locked skipped C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\admin\ntuser.dat Object is locked skipped C:\Documents and Settings\admin\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgfw8u.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgui.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpub.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Inetpub\catalog.wci\00000002.ps1 Object is locked skipped C:\Inetpub\catalog.wci\00000002.ps2 Object is locked skipped C:\Inetpub\catalog.wci\00010002.ci Object is locked skipped C:\Inetpub\catalog.wci\cicat.fid Object is locked skipped C:\Inetpub\catalog.wci\cicat.hsh Object is locked skipped C:\Inetpub\catalog.wci\CiCL0001.000 Object is locked skipped C:\Inetpub\catalog.wci\CiP10000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiP20000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiPT0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiSL0001.000 Object is locked skipped C:\Inetpub\catalog.wci\CiSP0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiST0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiVP0000.000 Object is locked skipped C:\Inetpub\catalog.wci\INDEX.000 Object is locked skipped C:\Inetpub\catalog.wci\propstor.bk1 Object is locked skipped C:\Inetpub\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\00010005.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{06F19798-4F9A-4B21-A374-BEB73F7F9748}\RP659\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{A48733DE-4FC1-49D4-86F4-2DEE503C8612}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\Logfiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped C:\WINDOWS\system32\msmq\storage\QMLog Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_210.dat Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Nothing to worry about

        You can delete the tools that we used

        You now need to update your Java and remove your older versions.

        Please follow these steps to remove older version Java components.

        * Click Start > Control Panel.
        * Click Add/Remove Programs.
        * Check any item with Java Runtime Environment (JRE) in the name.
        * Click the Remove or Change/Remove button.

        Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
        here



        Now we need to create a new System Restore point.

        Click Start Menu > Run > type (or copy and paste)

        %SystemRoot%\System32\restore\rstrui.exe

        Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

        Next goto Start Menu > Run > type

        cleanmgr

        Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

        To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



        Below I have included a number of recommendations for how to protect your computer against malware infections.

        * Keep Windows updated by regularly checking their website at :
        http://windowsupdate.microsoft.com/
        This will ensure your computer has always the latest security updates available installed on your computer.

        * To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
        SpywareBlaster protects against bad ActiveX
        IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
        Have a look at this tutorial for IE-Spyad here

        * SpywareGuard offers realtime protection from spyware installation attempts.

        Make Internet Explorer more secure
        • Click Start > Run
        • Type Inetcpl.cpl & click OK
        • Click on the Security tab
        • Click Reset all zones to default level
        • Make sure the Internet Zone is selected & Click Custom level
        • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
        • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

        * MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

        * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
        secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
        blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
        Here

        * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
        Here

        Thank you for your patience, and performing all of the procedures requested.


      • Advertisement
      • Registered Users, Registered Users 2 Posts: 10 Candy11


        Hey thanks so much for all that work. I am a lot more vigilent now so hopefully I will be more lucky in the future. I discovered the sync on my media player was ticked to sync everything in the last month, unless the virus caused it I don't know how that would have got ticked as it wasn't a problem before.

        I also havent had the dial up pop up today so hopefully that is sorted too.

        Many many thanks.
        Candy


      Advertisement