We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
Problem getting lappy to switch on?
Comments
-
Done xxx Thank u again for all your help xxx
Hopefully that will be then end of the nightmare! xxxx#JusticeForGrenfell0 -
Unfortunately after a shutdown, whilst i prepared lunch the darn thing wouldn't boot, took 6 attempts to get it on, i don't get it as after doing all of above it worked fine i tested it 4 times over 10 mins and it was fine xx
Do i just bin it? or have i got a chance of saving this lappy? xxx
sorry to ask again xxx#JusticeForGrenfell0 -
FIX these using hijack ~
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [recinfo256] c:\RecInfo\RecInfo.exe
O18 - Protocol: x-cnote - !!8D32BA61-D15B-11D4-894B-000000000000} - C:\Program Files\Common Files\EzTools\hsppp.dll
reboot
run COMBOFIX
(Run ALL programs as admin):idea:0 -
Hanx RIK, missed them...fancy starting a tag-team ??

p.s. toniq, do you have your original vista disk ?? Just a thought...........Gettin' There, Wherever There is......
I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple
0 -
this is what the combo log states xxx
ComboFix 09-03-06.02 - stick 2009-03-08 14:40:04.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2038.1164 [GMT 0:00]
Running from: c:\users\stick\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))))))
.
2009-03-08 11:01 . 2009-03-08 11:01 <DIR> d
c:\users\All Users\Avira
2009-03-08 11:01 . 2009-03-08 11:01 <DIR> d
c:\programdata\Avira
2009-03-08 11:01 . 2009-03-08 11:01 <DIR> d
c:\program files\Avira
2009-03-08 10:55 . 2009-03-08 10:55 <DIR> d
c:\users\All Users\NortonInstaller
2009-03-08 10:55 . 2009-03-08 10:55 <DIR> d
c:\programdata\NortonInstaller
2009-03-08 10:29 . 2009-03-08 10:29 <DIR> d
C:\VundoFix Backups
2009-03-08 00:09 . 2008-06-20 01:18 781,344 --a
c:\windows\System32\PresentationNative_v0300.dll
2009-03-08 00:09 . 2008-06-20 01:17 622,080 --a
c:\windows\System32\icardagt.exe
2009-03-08 00:09 . 2008-06-20 01:18 326,160 --a
c:\windows\System32\PresentationHost.exe
2009-03-08 00:09 . 2008-06-20 01:18 105,016 --a
c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-03-08 00:09 . 2008-06-20 01:17 97,800 --a
c:\windows\System32\infocardapi.dll
2009-03-08 00:09 . 2008-06-20 01:18 43,544 --a
c:\windows\System32\PresentationHostProxy.dll
2009-03-08 00:09 . 2008-06-20 01:17 37,384 --a
c:\windows\System32\infocardcpl.cpl
2009-03-08 00:09 . 2008-06-20 01:17 11,264 --a
c:\windows\System32\icardres.dll
2009-03-08 00:07 . 2009-03-08 00:09 43,450,368 --a
c:\windows\ocsetup_install_NetFx3.etl
2009-03-08 00:07 . 2009-03-08 00:09 196,608 --a
c:\windows\ocsetup_cbs_install_NetFx3.perf
2009-03-08 00:07 . 2009-03-08 00:09 65,536 --a
c:\windows\ocsetup_cbs_install_NetFx3.dpx
2009-03-08 00:03 . 2008-07-27 18:00 282,112 --a
c:\windows\System32\mscoree.dll
2009-03-08 00:03 . 2008-07-27 18:00 96,760 --a
c:\windows\System32\dfshim.dll
2009-03-08 00:03 . 2008-07-27 18:00 41,984 --a
c:\windows\System32\netfxperf.dll
2009-03-08 00:02 . 2008-07-27 18:00 158,720 --a
c:\windows\System32\mscorier.dll
2009-03-08 00:02 . 2008-07-27 18:00 83,968 --a
c:\windows\System32\mscories.dll
2009-03-07 23:02 . 2009-03-07 23:02 <DIR> d
c:\users\All Users\SUPERAntiSpyware.com
2009-03-07 23:02 . 2009-03-07 23:02 <DIR> d
c:\programdata\SUPERAntiSpyware.com
2009-03-07 23:01 . 2009-03-07 23:01 <DIR> d
c:\users\stick\AppData\Roaming\SUPERAntiSpyware.com
2009-03-07 23:01 . 2009-03-07 23:01 <DIR> d
c:\program files\SUPERAntiSpyware
2009-03-07 21:14 . 2009-03-07 21:14 <DIR> d
c:\users\stick\AppData\Roaming\Malwarebytes
2009-03-07 21:14 . 2009-03-07 21:14 <DIR> d
c:\users\All Users\Malwarebytes
2009-03-07 21:14 . 2009-03-07 21:14 <DIR> d
c:\programdata\Malwarebytes
2009-03-07 21:14 . 2009-03-07 21:14 <DIR> d
c:\program files\Malwarebytes' Anti-Malware
2009-03-07 21:14 . 2009-02-11 10:19 38,496 --a
c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-07 21:14 . 2009-02-11 10:19 15,504 --a
c:\windows\System32\drivers\mbam.sys
2009-03-07 20:42 . 2009-03-07 20:42 <DIR> d
c:\program files\Trend Micro
2009-02-20 21:36 . 2009-02-20 21:36 <DIR> d
c:\windows\ArtistScope Plugin IE 42
2009-02-20 21:36 . 2009-02-20 21:36 266,240 --a
c:\windows\System32\CSHelper.exe
2009-02-20 21:36 . 2009-02-20 21:36 225,280 --a
c:\windows\System32\CSInstru.DLL
2009-02-16 08:35 . 2008-12-05 04:26 1,244,672 --a
c:\windows\System32\mcmde.dll
2009-02-16 08:35 . 2008-12-05 04:29 428,032 --a
c:\windows\System32\EncDec.dll
2009-02-16 08:35 . 2008-12-05 04:29 292,352 --a
c:\windows\System32\psisdecd.dll
2009-02-16 08:35 . 2008-12-05 04:29 217,088 --a
c:\windows\System32\psisrndr.ax
2009-02-16 08:35 . 2008-12-05 04:29 177,152 --a
c:\windows\System32\mpg2splt.ax
2009-02-16 08:35 . 2008-12-05 04:29 80,896 --a
c:\windows\System32\MSNP.ax
2009-02-16 08:35 . 2008-12-05 04:29 68,608 --a
c:\windows\System32\Mpeg2Data.ax
2009-02-16 08:35 . 2008-12-05 04:29 57,856 --a
c:\windows\System32\MSDvbNP.ax
2009-02-10 22:26 . 2009-02-10 22:26 <DIR> d
c:\program files\Photosynth
2009-02-08 21:30 . 2009-02-08 21:30 <DIR> d
c:\program files\SIM
2009-02-08 21:30 . 1999-03-23 08:12 299,520 --a
c:\windows\uninst.exe
2009-02-08 21:30 . 2009-02-08 21:30 0 --a
c:\windows\PROTOCOL.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 12:14 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-08 10:56
d
w c:\program files\Common Files\Symantec Shared
2009-03-07 23:01
d
w c:\program files\Common Files\Wise Installation Wizard
2009-02-12 06:39
d
w c:\program files\Windows Mail
2009-01-20 21:58
d
w c:\programdata\hps
2009-01-20 21:56
d
w c:\program files\CeWe Color
2009-01-15 04:16 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-15 04:16 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-15 04:15 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2009-01-10 18:51
d
w c:\program files\Java
2008-12-11 14:41 174 --sha-w c:\program files\desktop.ini
2008-12-20 11:13 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-20 11:13 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-20 11:13 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-20 11:13 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-20 11:13 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-03-08 10:12 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-03-08 10:12 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-03-08 10:12 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-06-22 07:58 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-22 07:58 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-22 07:58 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-08_ 9.48.50.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-08 10:35:44 306,176 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehepgdat\559f27a529e52218b5d4ab4a05b7c785\ehepgdat.ni.dll
+ 2009-03-08 10:35:45 39,424 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\c64470b2d13892a0ca8f51f517522136\ehExtCOM.ni.dll
+ 2009-03-08 10:35:49 246,272 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost\c4633c10e7dc94cb4f33d402ed064071\ehExtHost.ni.exe
+ 2009-03-08 10:35:46 23,552 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtCOM\6dbd12480f119249468f90945e63cd7d\ehiExtCOM.ni.dll
+ 2009-03-08 10:35:49 160,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\61d14bd7cc3bbac33456408c31eae3a5\ehiExtens.ni.dll
+ 2009-03-08 10:35:50 565,760 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiPlay\d06adbc46a2d579a4ec57879b812366f\ehiPlay.ni.dll
+ 2009-03-08 10:35:50 55,296 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiReplay\fefc782faf1f65479cef77eceac28bb9\ehiReplay.ni.dll
+ 2009-03-08 10:35:51 797,696 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\f9279c17f6eee0f63b98e643237370bb\ehiVidCtl.ni.dll
+ 2009-03-08 10:35:52 338,432 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiwmp\2262df94d83ee4dc6b47bc043f6869e4\ehiwmp.ni.dll
+ 2009-03-08 10:35:52 103,936 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehiWUapi\7d21f43601837a5612c3683a6df8bf0a\ehiWUapi.ni.dll
+ 2009-03-08 10:35:56 1,722,880 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\42173e29c1292a10eb3a0edba2122382\ehRecObj.ni.dll
+ 2009-03-08 10:36:16 11,849,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\7d06bf1f4fec105bda0586e8f2b415e4\ehshell.ni.dll
+ 2009-03-08 10:36:18 540,160 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\7fcc008753bdae6c5d452f97a29be3e6\EventViewer.ni.dll
+ 2009-03-08 10:36:16 68,608 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\2a159c5264b485ae158ced9b2e071fcf\loadmxf.ni.exe
+ 2009-03-08 10:35:59 644,096 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\86865d318e834571c1ec7ef3e133afc8\mcstore.ni.dll
+ 2009-03-08 10:36:00 217,600 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\3882fa6513eefdcc5504347ce9f43940\mcstoredb.ni.dll
+ 2009-03-08 10:36:27 244,736 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mcupdate\29de87dc5e080f930c7384434efc6a15\mcupdate.ni.exe
+ 2009-03-08 10:36:16 236,032 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Mcx2Dvcs\65939c2057d80510b4ea42819e94b1e2\Mcx2Dvcs.ni.dll
+ 2009-03-08 10:36:28 222,720 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\300b894f5f93950e037a3e965f18d19a\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-03-08 10:36:30 839,680 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\469f74b1a5c04d4d122298419a78ee5a\Microsoft.Build.Engine.ni.dll
+ 2009-03-08 10:36:30 65,024 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\0b3322dd033251dbfeb5ffaa63628e2b\Microsoft.Build.Framework.ni.dll
+ 2009-03-08 10:36:35 1,966,080 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\158f491d14b18b2c84dea624fa16f97e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-03-08 10:36:33 1,620,992 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\51998ee525859b487f792fa991b578e0\Microsoft.Build.Tasks.ni.dll
+ 2009-03-08 10:36:36 175,104 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\141d01ee47d7293ff827c087bebc8f80\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-03-08 10:36:36 144,384 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\fb6b64d9951841d62e4a7fdb69773753\Microsoft.Build.Utilities.ni.dll
+ 2009-03-08 10:36:37 1,356,288 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\230e4b8a53dffc37c370534931e5e58b\Microsoft.Ink.ni.dll
+ 2009-03-08 10:36:19 575,488 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\76ced991d8401f189ffb472496425791\Microsoft.ManagementConsole.ni.dll
+ 2009-03-08 10:35:47 590,848 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\1aabdbc0050be517d4b91b1ebb60f34f\Microsoft.MediaCenter.ni.dll
+ 2009-03-08 10:36:01 661,504 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\aeb1f00633ca53d069af79e416eb7b0e\Microsoft.MediaCenter.Sports.ni.dll
+ 2009-03-08 10:35:58 244,224 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b40c446346f5e7c456b95c08b8161f8d\Microsoft.MediaCenter.Shell.ni.dll
+ 2009-03-08 10:36:41 1,712,128 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\10fc12b6bf6510f0b967d20a2b04c476\Microsoft.VisualBasic.ni.dll
+ 2009-03-08 10:36:25 5,843,456 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\84c61da1957ec2c2de7f33e20be5630f\MIGUIControls.ni.dll
+ 2009-03-08 10:36:44 1,531,392 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\b82a8adfccc4c48f48fd68e961fecc29\MMCEx.ni.dll
+ 2009-03-08 10:36:20 283,648 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\683027751803820e53367579ad1c025c\MMCFxCommon.ni.dll
+ 2009-03-08 10:36:45 67,584 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\26e6d4f072c7a3d10d020be2278e4591\napcrypt.ni.dll
+ 2009-03-08 10:36:45 103,424 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\54f50d29e552b533aac050fd328cdea6\naphlpr.ni.dll
+ 2009-03-08 10:36:46 110,080 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\b07e721e05b8c42d6db49e0c667ec58a\napinit.ni.dll
+ 2009-03-08 10:36:47 722,944 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\e6c1181ea4cb00c19c2e3fded7fd0eb6\napsnap.ni.dll
+ 2009-03-08 10:36:50 2,538,496 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\155b02ef85edc0b1bce415aa278494c2\Narrator.ni.exe
+ 2009-03-08 10:36:52 1,451,008 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\291b46ea56e2487200a16d5f8c4f4e7b\PresentationBuildTasks.ni.dll
+ 2009-03-08 10:36:59 1,657,856 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\bdc87c67f45de6c8798344e2625d3801\PresentationUI.ni.dll
+ 2009-03-08 10:37:06 2,128,896 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\bbab0671945f6dfb330735832b8db69c\ReachFramework.ni.dll
+ 2009-03-08 10:38:29 232,448 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\559a52145a3500b9be72f13c1a3e1018\sysglobl.ni.dll
+ 2009-03-08 10:37:08 82,944 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\995b89ec2f32e0c5989f84a8a96ceb28\System.AddIn.Contract.ni.dll
+ 2009-03-08 10:37:07 633,856 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\e40798cf217d051ccb60ce51df76608a\System.AddIn.ni.dll
+ 2009-03-08 10:37:12 94,208 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\8e4110e20bba40ee1fe7f23aaff7d2ee\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-03-08 10:37:12 2,295,296 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\7749403068ce1f517692d61ae5af97cb\System.Core.ni.dll
+ 2009-03-08 10:37:13 135,680 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\ae6e232c6323706a525ea09110674d84\System.Data.DataSetExtensions.ni.dll
+ 2009-03-08 10:38:07 756,736 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\959bf3a05aa862385201a0fc7ff82b7c\System.Data.Entity.Design.ni.dll
+ 2009-03-08 10:38:05 9,924,096 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\c17219ce79b8df5966381230bd9e2130\System.Data.Entity.ni.dll
+ 2009-03-08 10:38:14 939,008 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\66e561a2111eb84b814de5ee29acfe6e\System.Data.Services.Client.ni.dll
+ 2009-03-08 10:38:15 354,816 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\d14d5cbf6da54f47fa2480aabc3287a4\System.Data.Services.Design.ni.dll
+ 2009-03-08 10:38:12 1,328,128 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\58408e7157a149ee82d88687489d61ed\System.Data.Services.ni.dll
+ 2009-03-08 10:38:17 881,152 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4c8a9e6f92e1274ad537e52cbbfe63b1\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-03-08 10:38:18 330,752 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\9c1bbc7a8431ba14f3138a9b9d0b2758\System.Management.Instrumentation.ni.dll
+ 2009-03-08 10:38:19 621,056 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\892f786ce75bd2e0ca400a8dae347a58\System.Net.ni.dll
+ 2009-03-08 10:37:01 1,035,264 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\9def64da16f075e10ce1b0cb97e44646\System.Printing.ni.dll
+ 2009-03-08 10:38:25 1,706,496 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\463d79ec2065b26873bffcd35615d00b\System.ServiceModel.Web.ni.dll
+ 2009-03-08 10:38:28 1,917,440 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\a4524eb304ba9694838780c3d707bb6e\System.Speech.ni.dll
+ 2009-03-08 10:38:30 141,312 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\3b49817ad348c94fc41bbf26fdde9eec\System.Web.Abstractions.ni.dll
+ 2009-03-08 10:38:37 36,864 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\40591112ed6a3fac4dbfa337c00d2122\System.Web.DynamicData.Design.ni.dll
+ 2009-03-08 10:38:36 547,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\6f2bb0a35c228aba6e3a02a1238beb20\System.Web.DynamicData.ni.dll
+ 2009-03-08 10:38:39 301,056 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\c52120bb862d84082d917c4bb0a738c5\System.Web.Entity.Design.ni.dll
+ 2009-03-08 10:38:38 328,704 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\1ecd0493d33f74af1d96570662979a66\System.Web.Entity.ni.dll
+ 2009-03-08 10:38:35 2,403,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\060fca61fc10971f381204ccb623fc58\System.Web.Extensions.ni.dll
+ 2009-03-08 10:38:41 859,648 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\40b16dc65e32c4b7800bbde94fd4f9b7\System.Web.Extensions.Design.ni.dll
+ 2009-03-08 10:38:44 2,209,280 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\50dbb91ff2cd5f634b7cc56fb2125d55\System.Web.Mobile.ni.dll
+ 2009-03-08 10:38:31 129,536 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\71e9648c03c18a69e85293da03413183\System.Web.Routing.ni.dll
+ 2009-03-08 10:38:45 37,888 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\ade62baef300f037ae756f801663f9c5\System.Windows.Presentation.ni.dll
+ 2009-03-08 10:38:49 1,356,288 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\770bd1f92877fcca1e7d5520deb1524b\System.WorkflowServices.ni.dll
+ 2009-03-08 10:38:50 400,896 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\85e2233bc3d7c5cf8fc07f9a8ce241cd\System.Xml.Linq.ni.dll
+ 2009-03-08 10:38:51 241,152 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\92ab88c7d7701966de65406443a7de55\TaskScheduler.ni.dll
+ 2009-03-08 10:38:51 447,488 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\50adf5948f698ac2a6fd66a05c77fa6b\UIAutomationClient.ni.dll
+ 2009-03-08 10:38:53 1,049,600 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\bf4b41f6504f6e0bb9ebfe81ee898f41\UIAutomationClientsideProviders.ni.dll
+ 2009-03-08 10:38:54 240,128 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\41dcf4e0061193634534f67cea2d360e\WindowsFormsIntegration.ni.dll
- 2009-03-08 09:24:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-08 14:36:18 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-08 09:24:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-08 14:36:18 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-08 09:48:18 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-08 14:38:27 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-08 14:38:27 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.L!!!
- 2009-03-08 09:31:05 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-08 14:38:22 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-08 14:38:22 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.L!!!
- 2009-03-08 09:44:45 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-08 11:02:47 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-08 09:44:45 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-08 11:02:47 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-08 09:44:45 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-08 11:02:47 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-30 10:21:03 75,072 ----a-w c:\windows\System32\drivers\avipbb.sys
+ 2007-03-01 09:34:22 28,352 ----a-w c:\windows\System32\drivers\ssmdrv.sys
- 2009-01-10 18:51:31 144,792 ----a-w c:\windows\System32\java.exe
+ 2009-03-08 12:14:46 144,792 ----a-w c:\windows\System32\java.exe
- 2009-01-10 18:51:31 144,792 ----a-w c:\windows\System32\javaw.exe
+ 2009-03-08 12:14:46 144,792 ----a-w c:\windows\System32\javaw.exe
- 2009-01-10 18:51:31 148,888 ----a-w c:\windows\System32\javaws.exe
+ 2009-03-08 12:14:46 148,888 ----a-w c:\windows\System32\javaws.exe
- 2009-03-08 09:30:42 108,526 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-08 14:29:53 108,526 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-08 09:30:42 623,342 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-08 14:29:53 623,342 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-08 09:32:25 11,888 ----a-w c:\windows\System32\WDI\!!86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-598834151-1873842658-3423174849-1000_UserData.bin
+ 2009-03-08 14:38:49 12,096 ----a-w c:\windows\System32\WDI\!!86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-598834151-1873842658-3423174849-1000_UserData.bin
- 2009-03-08 09:32:23 63,286 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-08 14:38:49 64,514 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-08 08:52:12 42,842 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-08 14:38:47 44,590 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-02-08 1232896]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 511248]#JusticeForGrenfell0 -
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-02-08 160592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-29 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-02-17 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-27 153136]
"recinfo256"="c:\recinfo\RecInfo.exe" [2007-10-23 2764800]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-11-25 155648]
"Copperhead"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-11-25 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-13 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-02-08 160592]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"!!5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A6DB402E-33E8-4BE7-9C8B-EA865CA6FDFB}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C9F11ED4-7657-4C02-A17F-6506E329F222}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"!!4323425F-6B58-4AD7-8B15-18996616DD43}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F1159610-C2D7-4A63-A373-12C5B5474C17}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E3C45DD6-9099-4439-A083-FDCF989DA2DC}"= UDP:c:\program files\Internet Explorer\iexplore.exe:Internet Explorer
"!!8043D1E6-6894-410F-BED9-1AB921B2EDDC}"= TCP:c:\program files\Internet Explorer\iexplore.exe:Internet Explorer
"!!43B4F1D3-CC9E-4F11-80BD-23A1F9C139D7}"= UDP:c:\users\stick\AppData\Local\Temp\7zS9961.tmp\SymNRT.exe:Norton Removal Tool
"!!42E7EF02-5153-4EB4-AA77-65D2ED44FCBB}"= TCP:c:\users\stick\AppData\Local\Temp\7zS9961.tmp\SymNRT.exe:Norton Removal Tool
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 CSHelper;CopySafe Helper Service;c:\windows\System32\CSHelper.exe [2009-02-20 266240]
R2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 uisp;Freescale USB JW32 driver;c:\windows\System32\drivers\USBICP.sys [2008-06-21 14592]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [2008-06-22 11596]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\!!4496b294-5bf0-11dd-b835-00030d80d3ec}]
\shell\AutoRun\command - F:\StartPortableApps.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-08 c:\windows\Tasks\User_Feed_Synchronization-{BAF5C204-08B4-4965-AE72-C9E9971FF7AC}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://home.sweetim.com
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Customize Menu - [URL="file:///c:/program"]file://c:\program[/URL] files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - [URL="file:///c:/program"]file://c:\program[/URL] files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Lookup on Merriam Webster - [URL="file:///c:/program"]file://c:\program[/URL] files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - [URL="file:///c:/program"]file://c:\program[/URL] files\ieSpell\wikipedia.HTM
IE: RoboForm Toolbar - [URL="file:///c:/program"]file://c:\program[/URL] files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - [URL="file:///c:/program"]file://c:\program[/URL] files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
FF - ProfilePath - c:\users\stick\AppData\Roaming\Mozilla\Firefox\Profiles\vjbfs7pu.default\
FF - prefs.js: browser.search.selectedEngine - Big Snap
FF - prefs.js: browser.startup.homepage - hxxp://try.bigsnapsearch.com/
FF - prefs.js: keyword.URL - hxxp://www.bigsnapsearch.com/results.aspx?mkt=en-GB&FORM=MIFUAK&q=
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_19.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-08 14:42:57
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
LOCKED REGISTRY KEYS
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\!!0140DF95-9128-4053-AE72-F43F0CFCA062}\iexplore]
@DACL=(02 0000)
"Type"=dword:00000003
"Flags"=dword:00000000
"Count"=dword:00000002
"Time"=hex:d8,07,0b,00,06,00,16,00,02,00,37,00,05,00,81,01
.
Completion time: 2009-03-08 14:45:16
ComboFix-quarantined-files.txt 2009-03-08 14:44:38
ComboFix2.txt 2009-03-08 09:50:26
Pre-Run: 58,510,028,800 bytes free
Post-Run: 58,557,591,552 bytes free
338 --- E O F --- 2009-03-08 08:54:06#JusticeForGrenfell0 -
I don't have the original disk, it was pre installed xxxxxx#JusticeForGrenfell0
-
-
not yet xxx i will try it thanks xxx#JusticeForGrenfell0
-
DR WEB does a standard short scan by default. Let it run that THEN tick to do a FULL scan and run that:idea:0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 354K Banking & Borrowing
- 254.3K Reduce Debt & Boost Income
- 455.3K Spending & Discounts
- 247.1K Work, Benefits & Business
- 603.7K Mortgages, Homes & Bills
- 178.3K Life & Family
- 261.2K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.7K Read-Only Boards

