📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

laptop won't shut down

Options
24

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    When you say things arnt running too well, is that since service pack 3 was installed?

    If so, uninstall it and we shall make your computer clean THEN install it
    :idea:
  • aliEnRIK wrote: »
    When you say things arnt running too well, is that since service pack 3 was installed?

    If so, uninstall it and we shall make your computer clean THEN install it

    yes. Ok ta. Can i just delete the service pack file located her: C:\WINDOWS\security\Database ?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    yes. Ok ta.

    Can be a nightmare that SP3
    But without it, your open to quite a few security attacks

    HOPEFULLY,...........once everythings clean............itll run a lot better
    (Ive also heard of people say its slow to start then speeds up after a day or 2!)
    :idea:
  • Can i just delete the service pack file located her: C:\WINDOWS\security\Database ? Malware still seems to be stopping. It stops when it reaches a file in local settings although I can't seem to locate the file! :-(
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Dont DELETE the file no! Youll probably kill your computer doing that!

    Did you try malwarebytes in safe mode?
    :idea:
  • aliEnRIK wrote: »
    Dont DELETE the file no! Youll probably kill your computer doing that!

    Did you try malwarebytes in safe mode?

    phew!!

    tried safe mode, but still no joy. At this stage I'm nearly ready to throw the thing out the window :p

    I'm surprised my McAfee let all these dodgy files slip through the net:mad:

    PS the malware always stops at a file called plugtmp something or other, but when I do a search on it it desnt come up!
  • I ran combo, which hopefully ran okay as I wasn't sure how to disable my McAfee.
    I kept getting pop ups on the bottom right of my screen saying I should run chkdsk (not sure how to do this) as there seemed to be a few corrupt files located in a temp folder (the one in documents and settings which I have been unable to locate).

    Things seem to be running a bit better now and an app that I use on my desktop that wasn't working is now working again.

    Not sure if this is relevant or not, but a few months ago my lappy completely crashed and I lost everything. Since then I have to avoid going into 'checking disk' when I log on as it freezes in the next screen.

    Really hope this is things sorted. Thanks for all your patience and help with this:beer::beer::beer::beer::beer::beer::beer::beer::beer:

    Is it worth posting the log file from combo?

    The only thing is shut down still won't work :-(

    Thanks again.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker

    Is it worth posting the log file from combo?

    Yes please :)

    If your unhappy with mcafee, there is free software you can use
    :idea:
  • I get McAfee free with my o2 broadband. As its a paid service I'm assuming its better than the free stuff out there?

    Here is the combo log, thanks.

    ComboFix 09-01-21.04 - Mark 2009-01-26 20:54:28.1 - FAT32x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1014.343 [GMT 0:00]
    Running from: c:\documents and settings\Mark\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning enabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
    * Created a new restore point
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\docume~1\Mark\LOCALS~1\Temp\lsass.exe
    c:\windows\system32\drivers\npf.sys
    c:\windows\system32\packet.dll
    c:\windows\system32\pthreadVC.dll
    c:\windows\system32\WanPacket.dll
    c:\windows\system32\wpcap.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Service_NPF


    ((((((((((((((((((((((((( Files Created from 2008-12-26 to 2009-01-26 )))))))))))))))))))))))))))))))
    .

    2009-01-26 17:21 . 2009-01-26 17:21 110,592 --a
    C:\image166.exe
    2009-01-26 17:21 . 2009-01-26 17:21 81,920 --a
    C:\image188.exe
    2009-01-26 17:21 . 2009-01-26 17:21 503 --a
    C:\image199.exe
    2009-01-26 15:59 . 2009-01-26 15:59 <DIR> d
    c:\windows\system32\scripting
    2009-01-26 15:59 . 2009-01-26 15:59 <DIR> d
    c:\windows\system32\en
    2009-01-26 15:59 . 2009-01-26 15:59 <DIR> d
    c:\windows\system32\bits
    2009-01-26 15:59 . 2009-01-26 15:59 <DIR> d
    c:\windows\l2schemas
    2009-01-26 15:56 . 2009-01-26 15:56 <DIR> d
    c:\windows\ServicePackFiles
    2009-01-26 13:25 . 2009-01-26 13:25 <DIR> d
    c:\program files\SUPERAntiSpyware
    2009-01-26 13:25 . 2009-01-26 13:25 <DIR> d
    c:\documents and settings\Mark\Application Data\SUPERAntiSpyware.com
    2009-01-26 13:25 . 2009-01-26 13:25 <DIR> d
    c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-01-26 13:24 . 2009-01-26 13:24 <DIR> d
    c:\program files\Common Files\Wise Installation Wizard
    2009-01-26 12:37 . 2009-01-26 12:37 <DIR> d
    c:\program files\Trend Micro
    2009-01-25 19:10 . 2009-01-25 19:10 <DIR> d
    c:\documents and settings\Mark\Application Data\PCF-VLC
    2009-01-19 14:28 . 2009-01-19 14:28 <DIR> d
    c:\program files\Simpleology
    2009-01-18 17:20 . 2009-01-18 17:20 <DIR> d
    c:\windows\system32\quicktime
    2009-01-18 17:20 . 2009-01-18 17:20 <DIR> d
    c:\program files\AVI Movie Player
    2009-01-18 15:01 . 2009-01-18 15:01 <DIR> d
    c:\documents and settings\Mark\Application Data\CyberLink
    2009-01-18 15:00 . 2009-01-18 15:00 <DIR> d
    c:\documents and settings\All Users\Application Data\CyberLink
    2009-01-18 14:58 . 2009-01-18 14:58 <DIR> d
    c:\documents and settings\Mark\Application Data\AVS4YOU
    2009-01-18 14:58 . 2009-01-18 14:58 <DIR> d
    c:\documents and settings\All Users\Application Data\AVS4YOU
    2009-01-18 14:57 . 2009-01-18 14:57 <DIR> d
    c:\windows\system32\drivers\umdf
    2009-01-18 14:57 . 2009-01-18 14:57 <DIR> d
    c:\program files\Common Files\AVSMedia
    2009-01-18 14:54 . 2009-01-18 14:54 <DIR> d
    c:\program files\AVS4YOU
    2009-01-18 14:54 . 2008-08-13 10:22 487,424 --a
    c:\windows\system32\msvcp70.dll
    2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d
    c:\program files\Common Files\Hypnotizer
    2009-01-17 19:39 . 2009-01-17 19:39 <DIR> d
    c:\program files\AskBarDis
    2009-01-17 19:39 . 2009-01-17 19:39 <DIR> d
    c:\documents and settings\Mark\Application Data\XXXXXXX
    2009-01-17 19:39 . 2009-01-17 19:39 <DIR> d
    c:\documents and settings\All Users\Application Data\XXXXXXX
    2009-01-17 19:37 . 2009-01-17 19:37 <DIR> d
    c:\program files\Vuze
    2009-01-17 17:32 . 2007-04-17 09:32 2,455,488
    c:\windows\system32\dllcache\ieapfltr.dat
    2009-01-17 17:32 . 2007-03-08 05:10 991,232
    c:\windows\system32\dllcache\ieframe.dll.mui
    2009-01-17 17:32 . 2008-10-16 20:38 459,264
    c:\windows\system32\dllcache\msfeeds.dll
    2009-01-17 17:32 . 2008-10-16 20:38 383,488
    c:\windows\system32\dllcache\ieapfltr.dll
    2009-01-17 17:32 . 2008-10-16 20:38 267,776
    c:\windows\system32\dllcache\iertutil.dll
    2009-01-17 17:32 . 2008-10-16 20:38 63,488
    c:\windows\system32\dllcache\icardie.dll
    2009-01-17 17:32 . 2008-10-16 20:38 52,224
    c:\windows\system32\dllcache\msfeedsbs.dll
    2009-01-17 17:32 . 2008-10-16 13:11 13,824
    c:\windows\system32\dllcache\ieudinit.exe
    2009-01-17 17:31 . 2008-10-16 20:38 6,066,176
    c:\windows\system32\dllcache\ieframe.dll
    2009-01-02 19:03 . 2009-01-02 19:03 188 --a
    c:\windows\system32\eDataSecurity.dat
    2009-01-02 19:02 . 2003-02-28 18:26 139,536 --a
    c:\windows\system32\javaee.dll
    2008-12-30 22:04 . 2008-12-30 22:04 <DIR> d
    c:\documents and settings\Mark\Application Data\Participatory Culture Foundation
    2008-12-30 22:03 . 2008-12-30 22:03 <DIR> d
    c:\program files\Participatory Culture Foundation
    2008-12-29 18:53 . 2008-12-29 18:53 <DIR> d
    c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-14 16:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2009-01-14 16:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
    2008-12-13 12:28
    d
    w c:\documents and settings\Mark\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2008-12-13 12:22
    d
    w c:\program files\Common Files\Adobe AIR
    2008-12-13 11:35
    d
    w c:\program files\NOS
    2008-12-13 11:35
    d
    w c:\documents and settings\All Users\Application Data\NOS
    2008-12-13 06:40 3,593,216
    w c:\windows\system32\dllcache\mshtml.dll
    2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
    2008-12-11 10:57 333,952
    w c:\windows\system32\dllcache\srv.sys
    2008-12-10 15:01
    d
    w c:\program files\Sanyo
    2008-12-10 14:59
    d
    w c:\program files\ArcSoft
    2008-12-09 17:05
    d
    w c:\documents and settings\Mark\Application Data\Malwarebytes
    2008-12-09 17:04
    d
    w c:\program files\Malwarebytes' Anti-Malware
    2008-12-09 17:04
    d
    w c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-11-27 09:19
    d
    w c:\program files\PDFCreator
    2008-11-26 10:02 530,822 ----a-w c:\windows\java\Packages\KJBPFTFN.ZIP
    2008-11-12 11:12 155,995 ----a-w c:\windows\java\Packages\W3F37XR1.ZIP
    2008-11-04 11:11 1,637,500 ----a-w c:\windows\XSitePro2 Uninstaller.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
    @="!!95A27763-F62A-4114-9072-E81D87DE3B68}"
    [HKEY_CLASSES_ROOT\CLSID\!!95A27763-F62A-4114-9072-E81D87DE3B68}]
    2008-10-16 23:42 579728 -ra
    c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
    @="{E300CD91-100F-4E67-9AF3-1384A6124015}"
    [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
    2008-10-16 23:42 579728 -ra
    c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
    @="!!5E529433-B50E-4bef-A63B-16A6B71B071A}"
    [HKEY_CLASSES_ROOT\CLSID\!!5E529433-B50E-4bef-A63B-16A6B71B071A}]
    2008-10-16 23:42 579728 -ra
    c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-11 21741864]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" [X]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
    "ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2006-05-15 45056]
    "ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
    "ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 352256]
    "Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-22 3080704]
    "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
    "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-06-23 225280]
    "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
    "LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 331776]
    "LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 15:55 73728]
    "LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
    "EPSON Stylus Photo R220 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE" [2005-03-09 98304]
    "Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-10-16 667280]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "Simpleology 1.0"="c:\program files\Simpleology\simpleology Wimiki\simpleology Wimiki.exe" [2007-01-31 499712]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
    "RTHDCPL"="RTHDCPL.EXE" [2006-06-28 c:\windows\RTHDCPL.exe]
    "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    PUSH650C.lnk - c:\windows\twain_32\PUSH650C.exe [11/4/2008 1:26:35 PM 36864]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "!!5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\O2\\bin\\wificfg.exe"=
    "c:\\Program Files\\O2\\agent\\bin\\bcont.exe"=
    "c:\\Program Files\\Common Files\\SupportSoft\\BIN\\ssrc.exe"=
    "c:\\Program Files\\O2\\agent\\bin\\bcont_nm.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

    R1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [10/15/2005 6:20:44 PM 12106]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 4:17:40 PM 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 4:17:38 PM 55024]
    R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [6/19/2006 12:20:24 PM 1097728]
    R3 NdisFilt;NdisFilt;c:\windows\system32\drivers\NdisFilt.sys [9/13/2005 3:34:40 PM 4392]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 4:17:42 PM 7408]
    R4 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [7/22/2008 7:25:38 AM 4096]
    R4 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [7/22/2008 7:25:38 AM 78208]
    R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [11/5/2008 8:06:29 AM 206096]
    R4 osaio;osaio;c:\windows\system32\drivers\osaio.sys [6/30/2005 4:58:24 PM 7296]
    R4 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [1/14/2005 3:57:16 PM 4010]
    R4 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\O2\bin\sprtsvc.exe [6/7/2007 4:19:40 PM 202280]
    S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/9/2008 5:04:58 PM 38496]
    S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [1/17/2009 7:39:04 PM 464264]
    S4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [1/17/2009 7:39:29 PM 234888]
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-04 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-11-04 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2009-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-CTFMON - (no file)


    .
    Supplementary Scan
    .
    uStart Page = https://mail.XXXXXXXXX.com/Remote/tsweb.aspx?Server=XXXXXXXXXX&Port=4125&iFS=1&User=XXXXXXXX&Domain=XXXXXXXXXXX&redirectPrinters=1&redirectAudio=2
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uInternet Connection Wizard,ShellNext = hxxp://en.uk.acer.yahoo.com/
    uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    DPF: Ulster Bank AnyTime - hxxps://www.anytimebusiness.ie/asp/AnyTime.cab
    FF - ProfilePath - c:\documents and settings\Mark\Application Data\Mozilla\Firefox\Profiles\6e40xmwd.default\
    FF - component: c:\documents and settings\Mark\Application Data\Mozilla\Firefox\Profiles\6e40xmwd.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

    ---- FIREFOX POLICIES ----
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-26 20:59:51
    Windows 5.1.2600 Service Pack 3 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\! nk
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\ . 0 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\, 0 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\Ï vk 1350139904 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\UpperFil.ter
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\CardPres.enc 491520 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\ 4489216 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\A 1638400 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\ 1638400 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\Þ * 163840 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\°c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\Ï vk 1350139904 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\t 7569408 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\o 1638400 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\Þ lh 884736 bytes
    c:\docume~1\Mark\LOCALS~1\Temp\WPDNSE\0+
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599.2K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.