We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help - missing images

For some reason certain images are missing from internet sites - clickable and non-clickable yet others are still there. There's no box where the images should be or error messages or something, nothing comes up when I rollover - they are just missing! Its the same on both firefox and internet explorer, ive tried looking at the internet options and zone alarm options and I can't see anything that would explain this.

It's getting annoying because im trying to do an online shop at asda, when I clicked on the special offers page in the past there used to be symbols next to each type of offer that you'd click on to get to those pages. The symbols are missing and when I click where they should be nothing happens. Again, same on firefox and IE and the site works fine at my parents house so it must be my computer.

Any suggestions?

Comments

  • weegie.geek
    weegie.geek Posts: 3,432 Forumite
    Sounds like a firewall or something is blocking javascript or something similar.
    They say it's genetic, they say he can't help it, they say you can catch it - but sometimes you're born with it
  • Wolfsbayne
    Wolfsbayne Posts: 514 Forumite
    Sounds like a firewall or something is blocking javascript or something similar.

    I thought that but the block javascript in my firewall is unticked. And a lot of sites I can access and use properly use javascript.
  • weegie.geek
    weegie.geek Posts: 3,432 Forumite
    I know it's the same on FF and on IE but you could always grab Opera and see if it's the same there.

    In fact, you're probably better disabling the firewall for a bit to see if it's that doing it. Might be some settings hidden away somewhere doing it.
    They say it's genetic, they say he can't help it, they say you can catch it - but sometimes you're born with it
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    Click DO A SCAN AND SAVE A LOGFILE (Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    :idea:
  • Wolfsbayne
    Wolfsbayne Posts: 514 Forumite
    edited 18 April 2009 at 5:02PM
    ok, here's the log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:01:14, on 18/04/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CSHelper.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\mmm.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\WINDOWS\system32\kkw_run.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\kmw_run.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
    C:\Program Files\Messenger\Msmsgs.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\WINDOWS\system32\KMW_SHOW.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PowerTweak Menu] C:\WINDOWS\system32\mmm.exe
    O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    O4 - HKLM\..\Run: [kkw_run.exe] kkw_run.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [GEST] =
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 11669 bytes
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Download MALWAREBYTES (Make sure you click 'DOWNLOAD NOW')
    http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
    UPDATE and FULL SCAN
    Post the log here AFTER youve deleted everything it finds
    :idea:
  • Wolfsbayne
    Wolfsbayne Posts: 514 Forumite
    For some reason the log won't save (keeps creating blank files) so I can't paste it.

    It found

    trojan.agent file C:\Windows\system32\mmm.exe
    trojan.BHO Registry Key HKEY_CURRENT_USER\SOFTWAR. . .
    hijack.controlpa Registry Value HKEY_CURRENT_USER\SOFTWAR. . .
    trojan.agent Registry Value HKEY_LOCAL_MACHINE\SOFTWAR...
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Please run COMBOFIX
    Follow the simple instructions it gives
    Post the COMPLETE log it creates here (Split into sections if need be)

    If it comes up with a RENAMING error then RIGHT click the exe file and RENAME and call it QWERTY (Making the complete file name 'QWERTY.exe')
    :idea:
  • Wolfsbayne
    Wolfsbayne Posts: 514 Forumite
    [FONT=&quot]ComboFix 09-04-19.01 - Administrator 18/04/2009 21:25.1 - NTFSx86[/FONT]
    [FONT=&quot]Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1136 [GMT 1:00][/FONT]
    [FONT=&quot]Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe[/FONT]
    [FONT=&quot] * Created a new restore point[/FONT]
    [FONT=&quot] * Resident AV is active[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat[/FONT]
    [FONT=&quot]c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat[/FONT]
    [FONT=&quot]c:\windows\system32\msconfig.exe[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]
    BITS: Possible infected sites
    [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]hxxp://sunmicro.ht.rd.llnw.net[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]2009-04-18 19:16 . 2009-04-18 19:16 61440 ----a-w c:\windows\system32\drivers\fhjmqwrs.sys[/FONT]
    [FONT=&quot]2009-04-18 17:40 . 2009-04-18 17:40
    d
    w c:\documents and settings\Administrator\Application Data\Malwarebytes[/FONT]
    [FONT=&quot]2009-04-18 17:40 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys[/FONT]
    [FONT=&quot]2009-04-18 17:40 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys[/FONT]
    [FONT=&quot]2009-04-18 17:40 . 2009-04-18 17:40
    d
    w c:\documents and settings\All Users\Application Data\Malwarebytes[/FONT]
    [FONT=&quot]2009-04-07 17:33 . 2009-04-07 17:33
    d
    w c:\documents and settings\Administrator\Application Data\MailFrontier[/FONT]
    [FONT=&quot]2009-04-03 12:16 . 2009-04-03 12:16
    d
    w c:\documents and settings\NetworkService\Local Settings\Application Data\Apple[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot](((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]2009-04-18 20:31 . 2009-03-11 15:01 57254432 --sha-w c:\windows\system32\drivers\fidbox.dat[/FONT]
    [FONT=&quot]2009-04-18 19:18 . 2009-04-18 17:40
    d
    w c:\program files\Malwarebytes' Anti-Malware[/FONT]


    [FONT=&quot]2009-04-18 19:16 . 2009-04-18 19:16 152 ----a-w C:\uxpwpg.txt[/FONT]
    [FONT=&quot]2009-04-18 17:28 . 2009-03-09 16:20 959 ----a-w C:\rollback.ini[/FONT]
    [FONT=&quot]2009-04-18 16:54 . 2009-04-18 16:54
    d
    w c:\program files\Trend Micro[/FONT]
    [FONT=&quot]2009-04-18 11:19 . 2009-03-12 12:57 7304 ----a-w c:\windows\TMP0001.TMP[/FONT]
    [FONT=&quot]2009-04-17 20:18 . 2009-03-11 15:01 457844 --sha-w c:\windows\system32\drivers\fidbox.idx[/FONT]
    [FONT=&quot]2009-04-13 11:40 . 2008-12-03 12:41 13470362 ----a-w c:\windows\Internet Logs\tvDebug.zip[/FONT]
    [FONT=&quot]2009-04-08 17:29 . 2008-07-01 22:02 4212 ---ha-w c:\windows\system32\zllictbl.dat[/FONT]
    [FONT=&quot]2009-04-03 19:56 . 2009-04-04 19:11 2114048 ----a-w c:\windows\Internet Logs\xDBA.tmp[/FONT]
    [FONT=&quot]2009-04-03 19:06 . 2008-11-29 22:40
    d
    w c:\documents and settings\All Users\Application Data\Napster[/FONT]
    [FONT=&quot]2009-04-03 18:57 . 2009-04-03 19:02 2107904 ----a-w c:\windows\Internet Logs\xDB9.tmp[/FONT]
    [FONT=&quot]2009-04-03 17:19 . 2008-07-01 21:52
    d
    w c:\program files\Common Files\Adobe[/FONT]
    [FONT=&quot]2009-04-02 18:36 . 2009-03-11 14:40 514 ----a-w C:\INSTALL.LOG[/FONT]
    [FONT=&quot]2009-04-02 18:20 . 2009-04-02 18:20 187209 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_04_02_19_00_50_small.dmp.zip[/FONT]
    [FONT=&quot]2009-04-02 18:06 . 2009-04-02 18:15 2105344 ----a-w c:\windows\Internet Logs\xDB8.tmp[/FONT]
    [FONT=&quot]2009-04-02 18:05 . 2009-04-02 18:15 2676736 ----a-w c:\windows\Internet Logs\xDB7.tmp[/FONT]
    [FONT=&quot]2009-04-02 18:00 . 2009-04-02 18:03 2104832 ----a-w c:\windows\Internet Logs\xDB6.tmp[/FONT]
    [FONT=&quot]2009-04-01 17:51 . 2008-11-11 22:35
    d
    w c:\program files\Java[/FONT]
    [FONT=&quot]2009-03-31 18:20 . 2009-03-11 14:57 72584 ----a-w c:\windows\zllsputility.exe[/FONT]
    [FONT=&quot]2009-03-31 18:20 . 2009-03-11 14:57 1221512 ----a-w c:\windows\system32\zpeng25.dll[/FONT]
    [FONT=&quot]2009-03-29 14:27 . 2009-03-29 14:27 191813 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_29_15_19_16_small.dmp.zip[/FONT]
    [FONT=&quot]2009-03-29 14:19 . 2009-03-29 14:22 2083328 ----a-w c:\windows\Internet Logs\xDB5.tmp[/FONT]
    [FONT=&quot]2009-03-29 14:14 . 2009-03-29 14:13 183415 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_29_15_04_55_small.dmp.zip[/FONT]
    [FONT=&quot]2009-03-29 14:04 . 2009-03-29 14:08 2083328 ----a-w c:\windows\Internet Logs\xDB4.tmp[/FONT]
    [FONT=&quot]2009-03-28 20:01 . 2009-03-28 20:01 185781 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_28_19_50_30_small.dmp.zip[/FONT]
    [FONT=&quot]2009-03-28 19:50 . 2009-03-28 19:56 2077696 ----a-w c:\windows\Internet Logs\xDB3.tmp[/FONT]
    [FONT=&quot]2009-03-26 09:03 . 2009-03-26 09:03 185310 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_25_22_29_25_small.dmp.zip[/FONT]


    [FONT=&quot]2009-03-25 22:29 . 2009-03-26 08:58 2068480 ----a-w c:\windows\Internet Logs\xDB2.tmp[/FONT]
    [FONT=&quot]2009-03-25 19:48 . 2009-03-25 19:48 199409 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_25_19_24_37_small.dmp.zip[/FONT]
    [FONT=&quot]2009-03-25 19:24 . 2009-03-25 19:43 2067968 ----a-w c:\windows\Internet Logs\xDB1.tmp[/FONT]
    [FONT=&quot]2009-03-15 20:36 . 2009-02-27 15:12
    d
    w c:\documents and settings\All Users\Application Data\Sony[/FONT]
    [FONT=&quot]2009-03-15 20:36 . 2009-02-27 15:12
    d
    w c:\documents and settings\Administrator\Application Data\Sony[/FONT]
    [FONT=&quot]2009-03-15 20:35 . 2008-11-08 22:01
    d
    w c:\program files\Sony[/FONT]
    [FONT=&quot]2009-03-15 20:35 . 2009-03-15 20:01
    d
    w c:\program files\Sony Ericsson[/FONT]
    [FONT=&quot]2009-03-15 20:33 . 2009-03-15 20:33
    d
    w c:\documents and settings\Administrator\Application Data\Apple Computer[/FONT]
    [FONT=&quot]2009-03-15 20:32 . 2008-11-30 00:25
    d
    w c:\program files\QuickTime[/FONT]
    [FONT=&quot]2009-03-15 20:32 . 2009-03-15 20:32
    d
    w c:\documents and settings\All Users\Application Data\Apple Computer[/FONT]
    [FONT=&quot]2009-03-15 20:31 . 2009-02-27 15:10
    d
    w c:\program files\Apple Software Update[/FONT]
    [FONT=&quot]2009-03-15 20:31 . 2009-03-15 20:31
    d
    w c:\documents and settings\All Users\Application Data\Apple[/FONT]
    [FONT=&quot]2009-03-15 20:13 . 2008-11-08 18:54 38408 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT[/FONT]
    [FONT=&quot]2009-03-15 20:05 . 2009-03-15 20:05
    d
    w c:\program files\Avanquest update[/FONT]
    [FONT=&quot]2009-03-15 20:05 . 2008-07-01 19:34
    d--h--w c:\program files\InstallShield Installation Information[/FONT]
    [FONT=&quot]2009-03-15 20:04 . 2009-03-15 20:04
    d
    w c:\documents and settings\All Users\Application Data\BVRP Software[/FONT]
    [FONT=&quot]2009-03-15 20:01 . 2009-03-15 20:01
    d
    w c:\documents and settings\All Users\Application Data\Sony Ericsson[/FONT]
    [FONT=&quot]2009-03-15 14:17 . 2009-03-15 13:42
    d
    w c:\documents and settings\All Users\Application Data\Microsoft Help[/FONT]
    [FONT=&quot]2009-03-15 13:50 . 2009-03-15 13:18
    d
    w c:\documents and settings\Administrator\Application Data\GetRightToGo[/FONT]
    [FONT=&quot]2009-03-15 13:46 . 2009-03-15 13:46
    d
    w c:\program files\Microsoft Works[/FONT]
    [FONT=&quot]2009-03-15 13:45 . 2009-03-15 13:45
    d
    w c:\program files\Microsoft.NET[/FONT]
    [FONT=&quot]2009-03-15 13:44 . 2008-07-01 21:52
    d
    w c:\program files\Microsoft ActiveSync[/FONT]
    [FONT=&quot]2009-03-13 15:38 . 2009-03-13 15:38 206976 ----a-w c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_03_13_15_33_40_small.dmp.zip[/FONT]
    [FONT=&quot]2009-03-13 12:27 . 2009-03-13 12:26
    d
    w c:\documents and settings\Administrator\Application Data\Kensington[/FONT]


    [FONT=&quot]2009-03-12 12:51 . 2009-03-12 12:45
    d
    w c:\program files\Kensington[/FONT]
    [FONT=&quot]2009-03-11 15:11 . 2008-07-01 21:54
    d
    w c:\documents and settings\All Users\Application Data\avg8[/FONT]
    [FONT=&quot]2009-03-11 14:31 . 2009-03-11 14:31
    d
    w c:\documents and settings\All Users\Application Data\SMW[/FONT]
    [FONT=&quot]2009-03-11 14:31 . 2009-03-11 14:31
    d
    w c:\documents and settings\All Users\Application Data\Super Media Wizard[/FONT]
    [FONT=&quot]2009-03-09 04:19 . 2008-11-11 22:35 410984 ----a-w c:\windows\system32\deploytk.dll[/FONT]
    [FONT=&quot]2009-02-27 21:21 . 2009-02-25 19:48
    d
    w c:\program files\Free RAR Extract Frog[/FONT]
    [FONT=&quot]2009-02-27 15:11 . 2008-11-08 22:00
    d
    w c:\program files\Common Files\Sony Shared[/FONT]
    [FONT=&quot]2009-02-26 19:12 . 2009-02-26 19:12 66748 ----a-w c:\windows\Internet Logs\vsmon_2nd_2009_02_25_21_36_22_small.dmp.zip[/FONT]
    [FONT=&quot]2009-02-25 21:13 . 2009-02-25 21:13
    d
    w c:\documents and settings\NetworkService\Application Data\Trusteer[/FONT]
    [FONT=&quot]2009-02-24 19:03 . 2009-02-24 19:03
    d
    w c:\documents and settings\Administrator\Application Data\Trusteer[/FONT]
    [FONT=&quot]2009-02-24 19:03 . 2009-02-24 19:03
    d
    w c:\program files\Trusteer[/FONT]
    [FONT=&quot]2009-02-21 14:33 . 2009-02-21 14:33 266240 ----a-w c:\windows\system32\CSHelper.exe[/FONT]
    [FONT=&quot]2009-02-21 14:33 . 2009-02-21 14:33 225280 ----a-w c:\windows\system32\CSInstru.DLL[/FONT]
    [FONT=&quot]2009-02-21 12:27 . 2009-02-21 12:27
    d
    w c:\program files\Write Your Own Novel Standard[/FONT]
    [FONT=&quot]2009-02-03 13:16 . 2009-02-03 13:16 439 ----a-w C:\nsinst.log[/FONT]
    [FONT=&quot]2009-02-02 23:20 . 2009-02-02 23:20 24426094 ----a-w c:\windows\Internet Logs\vsmon_on_demand_thread_2009_02_02_23_19_24_full.dmp.zip[/FONT]
    [FONT=&quot]2009-02-02 23:10 . 2009-02-02 23:09 24393242 ----a-w c:\windows\Internet Logs\vsmon_on_demand_thread_2009_02_02_23_08_32_full.dmp.zip[/FONT]
    [FONT=&quot]2008-11-20 14:36 . 2008-11-20 14:36 26368 ----a-w c:\documents and settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT[/FONT]
    [FONT=&quot]2008-11-08 22:57 . 2008-11-08 22:57 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat[/FONT]
    [FONT=&quot]2008-08-22 14:2009-02-04 09:28 37:38 . c:\program files\mozilla firefox\components\nsgkff30_meter1.dll[/FONT]
    [FONT=&quot]2008-07-01 19:25 . 2008-07-01 19:26 16384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat[/FONT]
    [FONT=&quot]2008-07-01 19:25 . 2008-07-01 19:26 16384 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat[/FONT]
    [FONT=&quot]2008-07-01 19:25 . 2008-07-01 19:26 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]
    Sigcheck
    [/FONT]

    [FONT=&quot][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][-] 2008-05-21 20:49 361344 68F06FE0021B01E670AF37B8C5964FDF c:\windows\system32\drivers\tcpip.sys[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][-] 2008-05-21 21:05 547328 A55B8899D2EA2E800061BCFD456E34DC c:\windows\system32\winlogon.exe[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][-] 2008-05-21 21:03 1551872 C26978D5F821A7330439DD7F0AAAF678 c:\windows\explorer.exe[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][-] 2008-05-21 21:03 25088 B5E8782D4AF1B3756F38E11E7C157BBE c:\windows\system32\ctfmon.exe[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]*Note* empty entries & legit default entries are not shown [/FONT]
    [FONT=&quot]REGEDIT4[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/FONT]
    [FONT=&quot]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-05-21 25088][/FONT]
    [FONT=&quot]"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976][/FONT]
    [FONT=&quot]"MSMSGS"="c:\program files\Messenger\Msmsgs.exe" [2008-06-02 1660952][/FONT]
    [FONT=&quot]"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-20 133104][/FONT]
    [FONT=&quot]"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216][/FONT]
    [FONT=&quot]"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-11 160592][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/FONT]
    [FONT=&quot]"GEST"="=" [X][/FONT]
    [FONT=&quot]"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-01 15872][/FONT]
    [FONT=&quot]"NielsenOnline"="c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2008-10-10 45056][/FONT]
    [FONT=&quot]"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920][/FONT]
    [FONT=&quot]"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840][/FONT]
    [FONT=&quot]"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696][/FONT]
    [FONT=&quot]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888][/FONT]
    [FONT=&quot]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696][/FONT]
    [FONT=&quot]"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408][/FONT]
    [FONT=&quot]"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600][/FONT]
    [FONT=&quot]"kkw_run.exe"="kkw_run.exe" - c:\windows\system32\kkw_run.exe [2005-12-15 106496][/FONT]

    [FONT=&quot][/FONT]
    [FONT=&quot]"kmw_run.exe"="kmw_run.exe" - c:\windows\system32\kmw_run.exe [2005-09-01 118784][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run][/FONT]
    [FONT=&quot]"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-05-21 25088][/FONT]
    [FONT=&quot]"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce][/FONT]
    [FONT=&quot]"ShowDeskFix"="shell32" [X][/FONT]
    [FONT=&quot]"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-03-01 124928][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]c:\documents and settings\Administrator\Start Menu\Programs\Startup\[/FONT]
    [FONT=&quot]OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]c:\documents and settings\All Users\Start Menu\Programs\Startup\[/FONT]
    [FONT=&quot]Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-1 113664][/FONT]
    [FONT=&quot]HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472][/FONT]
    [FONT=&quot]HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728][/FONT]
    [FONT=&quot]Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer][/FONT]
    [FONT=&quot]"NoSMConfigurePrograms"= 1 (0x1)[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer][/FONT]
    [FONT=&quot]"NoSMHelp"= 1 (0x1)[/FONT]
    [FONT=&quot]"ForceClassicControlPanel"= 1 (0x1)[/FONT]
    [FONT=&quot]"NoSMConfigurePrograms"= 1 (0x1)[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot][HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List][/FONT]
    [FONT=&quot]"%windir%\\Network Diagnostic\\xpnetdiag.exe"=[/FONT]
    [FONT=&quot]"%windir%\\system32\\sessmgr.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=[/FONT]

    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\Messenger\\Msmsgs.exe"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=[/FONT]
    [FONT=&quot]"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=[/FONT]
    [FONT=&quot]"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]R3 adxapie;adxapie; [x][/FONT]
    [FONT=&quot]S1 nnrnstdi;nnrnstdi; [x][/FONT]
    [FONT=&quot]S2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2009-02-21 266240][/FONT]
    [FONT=&quot]S3 KKW_HID;Kensington HIDClass Filter Driver;c:\windows\system32\DRIVERS\KKW_HID.sys [2005-12-01 14208][/FONT]
    [FONT=&quot]S3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [2008-08-22 8832][/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]Contents of the 'Scheduled Tasks' folder[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]2009-04-10 c:\windows\Tasks\AppleSoftwareUpdate.job[/FONT]
    [FONT=&quot]- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34][/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]- - - - ORPHANS REMOVED - - - -[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]HKLM-Run-MSWheel - (no file)[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]
    Supplementary Scan
    [/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]uStart Page = hxxp://www.google.com/[/FONT]
    [FONT=&quot]uInternet Settings,ProxyOverride = *.local[/FONT]
    [FONT=&quot]IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html[/FONT]
    [FONT=&quot]IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000[/FONT]
    [FONT=&quot]IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html[/FONT]
    [FONT=&quot]IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html[/FONT]
    [FONT=&quot]IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html[/FONT]
    [FONT=&quot]FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4pdtzf2p.default\[/FONT]
    [FONT=&quot]FF - prefs.js: browser.startup.homepage - hxxp://uk.mc242.mail.yahoo.com/mc/showFolder;_ylt=AsjhvOUBAsE8Y839tlFZf9hLAb4X?&fid=Inbox&.rand=1945023217&da=0|http://www.virtualhorseranch.com/ledger.php|http://www.virtualhorseranch.com/|http://www.virtualhorseranch.com/phpbb3/search.php?search_id=newposts|http://www.google.co.uk/[/FONT]
    [FONT=&quot]FF - component: c:\program files\Mozilla Firefox\components\nsgkff30_meter1.dll[/FONT]
    [FONT=&quot]FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll[/FONT]
    [FONT=&quot]FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll[/FONT]
    [FONT=&quot]FF - plugin: c:\program files\Mozilla Firefox\plugins\npArtistScope42.dll[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]---- FIREFOX POLICIES ----[/FONT]
    [FONT=&quot]FF - user.js: yahoo.homepage.dontask - true.[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]**************************************************************************[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net[/FONT]
    [FONT=&quot]Rootkit scan 2009-04-18 21:31[/FONT]
    [FONT=&quot]Windows 5.1.2600 Service Pack 3 NTFS[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]scanning hidden processes ... [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]scanning hidden autostart entries ... [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]scanning hidden files ... [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]scan completed successfully[/FONT]
    [FONT=&quot]hidden files: 0[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]**************************************************************************[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]
    DLLs Loaded Under Running Processes
    [/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]- - - - - - - > 'winlogon.exe'(724)[/FONT]
    [FONT=&quot]c:\windows\system32\sfc_os.dll[/FONT]
    [FONT=&quot]c:\windows\system32\Ati2evxx.dll[/FONT]
    [FONT=&quot]c:\windows\system32\COMRes.dll[/FONT]
    [FONT=&quot]c:\windows\system32\cscui.dll[/FONT]
    [FONT=&quot].[/FONT]
    [FONT=&quot]Completion time: 2009-04-18 21:32[/FONT]
    [FONT=&quot]ComboFix-quarantined-files.txt 2009-04-18 20:32[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]Pre-Run: 200,035,360,768 bytes free[/FONT]
    [FONT=&quot]Post-Run: 200,036,278,272 bytes free[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe[/FONT]
    [FONT=&quot][boot loader][/FONT]
    [FONT=&quot]timeout=2[/FONT]
    [FONT=&quot]default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS[/FONT]
    [FONT=&quot][operating systems][/FONT]
    [FONT=&quot]c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons[/FONT]
    [FONT=&quot]multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect[/FONT]
    [FONT=&quot] [/FONT]
    [FONT=&quot]233[/FONT]

    [FONT=&quot][/FONT]
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Download CCLEANER (Make sure you click 'DOWNLOAD LATEST VERSION' ~ make sure YAHOO TOOLBAR is unticked on installation)
    http://www.filehippo.com/download_ccleaner/
    Run the CLEANER scan (UNTICK 'cookies')
    Then run the REGISTRY scan (Backup the registry when it asks)

    Then run a KASPERSKY ONLINE SCAN (click to scan 'MY COMPUTER')
    http://www.kaspersky.co.uk/kos_trialpay_offer
    Please post the complete log it creates
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.9K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.