We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Avira sound??

2»

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Im under the impression youve had trojans since January 2007! Im going to leave them for now though as im not 100% on them



    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\bridf07a.dat


    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.


    run a KASPERSKY ONLINE SCAN (click to scan 'MY COMPUTER')
    http://www.kaspersky.com/kos/eng/partner/default/pages/default/check.html?n=1245225406761
    Please post the complete log it creates (This only SCANS it DOESNT delete anything, so we'd need to see anything it finds)
    The scan will likely take anywhere from 5 to 12 hours to complete!
    :idea:
  • chrissyfp1
    chrissyfp1 Posts: 74 Forumite
    Thanks very much, i'll start it when i get back. I reformatted my C drive about a month ago, so if there is anything, am I right in thinking that it's coming from the D drive that hasn't been formatted?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Well not that I can see ~ all references are to C drive
    How did you reinstall XP? Did you start with a complete disc reload or did you use a 'disc image' (ie ~ a backup)
    You even have references to 2004 so im guessing you ran a backup?
    :idea:
  • chrissyfp1
    chrissyfp1 Posts: 74 Forumite
    aliEnRIK wrote: »
    Well not that I can see ~ all references are to C drive
    How did you reinstall XP? Did you start with a complete disc reload or did you use a 'disc image' (ie ~ a backup)
    You even have references to 2004 so im guessing you ran a backup?

    The plot thickens!! I definately did a complete reinstallation rather than a back up. It's a pc we put together ourselves in '04 and it's our own xp disc that we bought at the same time as motherbosrd etc, but i think the C drive is newer than that? I am currently more than happy to format it again though!!! Everything was put onto the D drive when i did it and it's mostly still there.

    Second combo fix log, I'll start the online scan this evening...... thank you again. :D

    ComboFix 09-07-21.05 - Me 22/07/2009 17:12.2.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.477 [GMT 1:00]
    Running from: c:\program files\qwerty.exe
    Command switches used :: c:\documents and settings\Me\Desktop\CFScript.txt
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    FILE ::
    "c:\windows\system32\bridf07a.dat"
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\windows\system32\bridf07a.dat
    .
    ((((((((((((((((((((((((( Files Created from 2009-06-22 to 2009-07-22 )))))))))))))))))))))))))))))))
    .
    2009-07-22 06:12 . 2009-07-22 16:10 3148873 ----a-r- c:\program files\qwerty.exe
    2009-07-21 11:40 . 2009-07-21 11:40
    d
    w- c:\documents and settings\Me\Local Settings\Application Data\Scansoft
    2009-07-21 11:38 . 2007-01-26 15:13 54784 ----a-w- c:\windows\system32\brinsstr.dll
    2009-07-21 11:38 . 2007-01-15 20:54 12288
    r- c:\windows\system32\BrDctF2S.dll
    2009-07-21 11:38 . 2007-01-15 15:09 12288
    r- c:\windows\system32\BrDctF2L.dll
    2009-07-21 11:38 . 2007-01-25 16:16 94208
    r- c:\windows\system32\BrDctF2.dll
    2009-07-21 11:38 . 2006-12-28 12:39 176128
    w- c:\windows\system32\BroSNMP.dll
    2009-07-21 11:38 . 2009-07-21 11:38
    d
    w- c:\program files\Brother
    2009-07-21 11:38 . 2007-02-15 12:54 131072
    w- c:\windows\brunin03.dll
    2009-07-21 11:38 . 2007-01-18 12:51 163840
    w- c:\windows\system32\NSSearch.dll
    2009-07-21 11:37 . 2009-07-21 11:37
    d
    w- c:\documents and settings\Me\Application Data\InstallShield
    2009-07-21 11:37 . 2009-07-21 11:37
    d
    w- c:\program files\Nuance
    2009-07-21 11:36 . 2009-07-21 11:36
    d
    w- c:\documents and settings\All Users\Application Data\InstallShield
    2009-07-21 11:36 . 2009-07-21 11:36
    d
    w- c:\program files\Common Files\ScanSoft Shared
    2009-07-21 11:36 . 2009-07-21 11:36
    d
    w- c:\documents and settings\All Users\Application Data\ScanSoft
    2009-07-21 11:36 . 2009-07-21 11:36
    d
    w- c:\program files\ScanSoft
    2009-07-21 11:35 . 2009-07-21 11:35
    d
    w- c:\documents and settings\All Users\Application Data\Brother
    2009-07-21 10:41 . 2009-07-21 10:41
    d
    w- c:\documents and settings\Me\Local Settings\Application Data\Help
    2009-07-18 10:16 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2009-07-18 10:16 . 2009-03-24 15:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2009-07-18 10:16 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
    2009-07-18 10:16 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
    2009-07-18 10:16 . 2009-07-18 10:16
    d
    w- c:\program files\Avira
    2009-07-18 10:16 . 2009-07-18 10:16
    d
    w- c:\documents and settings\All Users\Application Data\Avira
    2009-07-18 09:24 . 2009-07-22 15:57 117760 ----a-w- c:\documents and settings\Me\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-07-18 09:23 . 2009-07-18 09:23
    d
    w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-07-18 09:23 . 2009-07-18 09:23
    d
    w- c:\program files\SUPERAntiSpyware
    2009-07-18 09:23 . 2009-07-18 09:23
    d
    w- c:\documents and settings\Me\Application Data\SUPERAntiSpyware.com
    2009-07-18 09:22 . 2009-07-18 09:22
    d
    w- c:\program files\Common Files\Wise Installation Wizard
    2009-07-18 08:26 . 2009-07-18 08:26
    d
    w- c:\documents and settings\Me\Application Data\Malwarebytes
    2009-07-18 08:26 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-18 08:26 . 2009-07-18 08:26
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2009-07-18 08:26 . 2009-07-18 08:26
    d
    w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-07-18 08:26 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-17 19:04 . 2009-07-17 19:04
    d
    w- c:\program files\Common Files\DVDVideoSoft
    2009-07-17 19:04 . 2009-07-17 19:04
    d
    w- c:\program files\DVDVideoSoft
    2009-07-17 18:51 . 2009-07-17 18:51 118784 ----a-w- c:\windows\dsdxirmv.exe
    2009-07-17 18:51 . 2009-07-17 18:53
    d
    w- C:\Cakewalk Projects
    2009-07-17 18:51 . 2009-07-17 18:51
    d
    w- c:\program files\Cakewalk
    2009-07-17 18:51 . 2003-07-15 00:00 180224 ----a-w- c:\windows\system32\ReWire.dll
    2009-07-16 08:43 . 2009-07-18 15:57
    d
    w- c:\documents and settings\Me\Local Settings\Application Data\WMTools Downloaded Files
    2009-07-14 20:12 . 2009-07-14 20:12
    d
    w- c:\program files\TightVNC
    2009-07-07 21:31 . 2009-07-07 21:31
    d
    w- c:\program files\WinPcap
    2009-07-06 19:23 . 2009-07-06 19:23
    d
    w- C:\cs_files
    2009-07-06 19:19 . 2009-07-07 21:37
    d
    w- c:\program files\webinterface
    2009-07-06 19:19 . 2009-07-06 19:19
    d
    w- c:\windows\Card Sharing Control Centar
    2009-07-05 06:38 . 2009-07-05 06:40
    d
    w- c:\documents and settings\Me\Application Data\vlc
    2009-07-05 06:36 . 2009-07-05 06:36
    d
    w- c:\program files\VideoLAN
    2009-07-05 06:30 . 2009-07-05 06:30
    d
    w- c:\documents and settings\Me\Local Settings\Application Data\Deployment
    2009-07-01 17:41 . 2009-07-01 19:10
    d
    w- C:\VideoOutput
    2009-07-01 07:39 . 2009-07-01 07:39
    d
    w- c:\program files\uTorrent
    2009-07-01 07:39 . 2009-07-01 16:43
    d
    w- c:\documents and settings\Me\Application Data\uTorrent
    2009-06-29 18:18 . 2009-06-29 18:18
    d
    w- c:\program files\Common Files\xing shared
    2009-06-29 18:18 . 2009-06-29 18:18
    d
    w- c:\program files\Real
    2009-06-29 18:18 . 2009-06-29 18:18
    d
    w- c:\program files\Common Files\Real
    2009-06-29 15:02 . 2007-04-12 13:19 129024 ----a-w- c:\windows\system32\AVERM.dll
    2009-06-29 15:02 . 2006-09-26 12:57 28672 ----a-w- c:\windows\system32\AVEQT.dll
    2009-06-29 15:02 . 2009-06-29 15:03
    d
    w- c:\program files\Ultra Video Converter
    2009-06-29 14:46 . 2009-07-05 11:50
    d
    w- C:\Share
    2009-06-29 12:34 . 2009-06-29 12:34
    d
    w- c:\program files\ExtractNow
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-07-21 11:37 . 2009-06-12 16:08
    d--h--w- c:\program files\InstallShield Installation Information
    2009-07-21 11:36 . 2009-06-12 16:08
    d
    w- c:\program files\Common Files\InstallShield
    2009-07-18 07:10 . 2009-06-12 16:28
    d
    w- c:\documents and settings\All Users\Application Data\Symantec
    2009-07-18 07:10 . 2009-06-12 16:29
    d
    w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
    2009-07-18 07:09 . 2009-06-12 16:27
    d
    w- c:\documents and settings\All Users\Application Data\NortonInstaller
    2009-06-19 19:42 . 2009-06-14 14:51
    d
    w- c:\documents and settings\Me\Application Data\K-Meleon
    2009-06-19 05:54 . 2009-06-13 08:32
    d
    w- c:\documents and settings\All Users\Application Data\NOS
    2009-06-19 05:53 . 2009-06-13 08:33
    d
    w- c:\program files\Common Files\Adobe
    2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-15 21:56 . 2009-06-15 21:56
    d
    w- c:\program files\MSXML 4.0
    2009-06-14 14:50 . 2009-06-14 14:50
    d
    w- c:\program files\K-Meleon
    2009-06-14 14:12 . 2009-06-14 14:12
    d
    w- c:\program files\Bushman Solutions
    2009-06-14 11:10 . 2009-06-14 11:10
    d
    w- c:\documents and settings\Me\Application Data\Apple Computer
    2009-06-14 11:06 . 2009-06-14 11:06
    d
    w- c:\program files\QuickTime
    2009-06-14 11:06 . 2009-06-14 11:06
    d
    w- c:\documents and settings\All Users\Application Data\Apple Computer
    2009-06-14 11:05 . 2009-06-14 11:05
    d
    w- c:\program files\Apple Software Update
    2009-06-14 11:05 . 2009-06-14 11:05
    d
    w- c:\documents and settings\All Users\Application Data\Apple
    2009-06-14 10:50 . 2009-06-14 10:50
    d
    w- c:\documents and settings\Me\Application Data\Teleca
    2009-06-14 10:49 . 2009-06-14 10:48
    d
    w- c:\program files\Common Files\Teleca Shared
    2009-06-14 10:48 . 2009-06-14 10:48
    d
    w- c:\documents and settings\Me\Application Data\Sony Ericsson
    2009-06-14 10:48 . 2009-06-14 10:47
    d
    w- c:\documents and settings\All Users\Application Data\Teleca
    2009-06-14 10:48 . 2009-06-14 10:47
    d
    w- c:\documents and settings\All Users\Application Data\Sony Ericsson
    2009-06-14 10:48 . 2009-06-14 10:48
    d
    w- c:\program files\Common Files\Sony Ericsson Shared
    2009-06-14 10:48 . 2009-06-14 10:48
    d
    w- c:\program files\Sony Ericsson
    2009-06-14 07:12 . 2009-06-14 07:12
    d
    w- c:\program files\NOS
    2009-06-13 08:39 . 2009-06-13 08:39 13104 ----a-w- c:\documents and settings\Me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-06-13 08:33 . 2009-06-13 08:33
    d
    w- c:\program files\Common Files\Adobe AIR
    2009-06-13 08:32 . 2009-06-13 08:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
    2009-06-12 18:21 . 2009-06-12 18:21 0 ----a-w- c:\windows\nsreg.dat
    2009-06-12 16:29 . 2009-06-12 16:28
    d
    w- c:\documents and settings\All Users\Application Data\Norton
    2009-06-12 16:17 . 2009-06-12 16:17
    d
    w- c:\program files\directx
    2009-06-12 16:16 . 2009-06-12 16:16
    d
    w- c:\program files\SiS Compatible VGA V3.07
    2009-06-12 16:14 . 2009-06-12 16:14
    d
    w- c:\program files\WinFast
    2009-06-12 16:12 . 2009-06-12 16:12
    d
    w- c:\program files\SiSLan
    2009-06-12 16:09 . 2009-06-12 16:09
    d
    w- c:\program files\Realtek Sound Manager
    2009-06-12 16:09 . 2009-06-12 16:09
    d
    w- c:\program files\AvRack
    2009-06-12 15:31 . 2009-06-12 15:31
    d
    w- c:\program files\MSBuild
    2009-06-12 15:31 . 2009-06-12 15:31
    d
    w- c:\program files\Reference Assemblies
    2009-06-12 15:27 . 2009-06-12 15:27
    d
    w- c:\program files\Windows Media Connect 2
    2009-06-12 15:09 . 2009-06-12 14:20 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-06-12 14:21 . 2009-06-12 14:21
    d
    w- c:\program files\microsoft frontpage
    2009-06-12 14:18 . 2009-06-12 14:18 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-06-03 19:09 . 2004-08-04 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
    2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
    2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
    2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-06-03 04:24 . 2009-06-12 18:21 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
    "SiS KHooker"="c:\windows\system32\khooker.exe" [2002-11-01 286720]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-29 198160]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
    "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
    "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
    "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
    "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
    "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
    "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-02-26 65024]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    c:\documents and settings\Me\Start Menu\Programs\Startup\
    K-Meleon Loader.lnk - c:\program files\K-Meleon\loader.exe [2007-4-15 32768]
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-8-19 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-8-19 51984]
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\TightVNC\\WinVNC.exe"=
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 11:01 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 11:01 72944]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [18/07/2009 11:16 108289]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 11:01 7408]
    S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [13/06/2009 09:32 66048]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [23/12/2008 16:35 50704]
    S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [23/04/2007 13:54 83208]
    S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [23/04/2007 13:54 15112]
    S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [23/04/2007 13:54 108680]
    S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [23/04/2007 13:54 100488]
    S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [23/04/2007 13:54 98568]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.virginmedia.com/account/sign-in.php?bounceto=http%3A%2F%2Fwww.virginmedia.com%2Ffiles%2Fntl%2Fredir.php%3Fto%3Dwebmail
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    FF - ProfilePath - c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\hbr4v9ni.default\
    FF - prefs.js: browser.search.selectedEngine - Ask
    FF - prefs.js: browser.startup.homepage - hxxp://today.ask.com/dvdvideosoft?o=13162&l=dis
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13161&gct=&gc=1&q=
    FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-22 17:15
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'winlogon.exe'(564)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    Completion time: 2009-07-22 17:16
    ComboFix-quarantined-files.txt 2009-07-22 16:16
    ComboFix2.txt 2009-07-22 06:22
    Pre-Run: 108,218,216,448 bytes free
    Post-Run: 108,240,388,096 bytes free
    210 --- E O F --- 2009-07-18 08:24


  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Im at a complete loss as to how it has 2004 as a date for several files then (And 2007 for some others)
    See how the kaspersky scan goes first
    :idea:
  • chrissyfp1
    chrissyfp1 Posts: 74 Forumite
    Sorry for the delay, i thought i should finish my work on here before i started to mess around with it, lol! :D

    I did the Kapersky scan but it said it was all clean.

    The pc is acting rather oddly now though. When i start up it's asking me if I want to boot up with the windows recovery console or just windows? It's also stopped going to the screen saver when i've left it for a while (not very eco friendly, pc on all day!!).

    Yesterday when i logged in to my other halfs bank account, it changed the icon of my bank in my favourites, to the icon of his bank. It's back to my icon now but it was still there after i'd shut down and rebooted twice yesterday??? :confused:

    Kapersky scan log............


    Thursday, July 23, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Wednesday, July 22, 2009 22:27:28
    Records in database: 2515442

    Scan settingsScan using the following databaseextendedScan archivesyesScan mail databasesyesScan areaMy ComputerC:\
    D:\
    E:\
    F:\
    G:\ Scan statisticsFiles scanned52111Threat name0Infected objects0Suspicious objects0Duration of the scan02:21:09


    No malware has been detected. The scan area is clean.The selected area was scanned.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Have you tried to reset the screensaver to get it working again?
    Icon ~ dont worry about that

    viruses ~ I could do with you running combofix again just so I have a fresh log to check
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.7K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.