We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

HELP - how do I get rid of "Cyber Security"?

13

Comments

  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    1. Download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:

      Malwarebytes' Anti-Malware Download Link
    2. Once downloaded, close all programs and Windows on your computer, including this one.
    3. Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MBAM onto your computer.
    4. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.
    5. MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.

      mbam.jpg
    6. On the Scanner tab, make sure the the Perform quick scan option is selected and then click on the Scan button to start scanning your computer for Cyber Security related files.
    7. MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. When MBAM is scanning it will look like the image below.

      scanning.jpg
    8. When the scan is finished a message box will appear as shown in the image below.

      scan-finished.jpg
      You should click on the OK button to close the message box and continue with the CyberSecurity removal process.
    Ex forum ambassador

    Long term forum member
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    1. You will now be back at the main Scanner screen. At this point you should click on the Show Results button.
    2. A screen displaying all the malware that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.

      mbam-cyber-security.jpg

      You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine. When removing the files, MBAM may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot, please allow it to do so. Once your computer has rebooted, and you are logged in, please continue with the rest of the steps.
    3. When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.
    4. You can now exit the MBAM program.
    Your computer should now be free of the CyberSecurity program

    complete text from here and full credits to

    http://www.bleepingcomputer.com/virus-removal/remove-cyber-security
    Ex forum ambassador

    Long term forum member
  • Ticklemouse
    Ticklemouse Posts: 5,030 Forumite
    1,000 Posts Combo Breaker
    Hi Browntoa

    I've all that as mentioned above. The only thing that was different was that when I click on the rkill icon, it loads for a fraction of a second and closes so I can't read what it says. When I did the iexplore process, I couldn't see any tsc.exe which made me think that rkill had aready done its job. When I ran the malwarebytes prog, it did exactly as it showed it should have done except at the end it said nothing had been found and only gave me the option of going back to the main menu.

    I've also been via task manager and got rid of tsc.exe in the processes - run quick and full scans with malwarebytes and still nothing shows up. Is it worth uninstalling all the above and reinstalling them and trying again?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Did you UPDATE malwarebytes first?
    :idea:
  • Ticklemouse
    Ticklemouse Posts: 5,030 Forumite
    1,000 Posts Combo Breaker
    I thought I had everything updated, but it appears not. All updated now and running abother scan. 30 seconds in and already found 2 infected objects .... maybe there is light at the end of the tunnel :)

    I'll keep you informed .....
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    I would really suggest a FULL scan personally
    :idea:
  • Ticklemouse
    Ticklemouse Posts: 5,030 Forumite
    1,000 Posts Combo Breaker
    Whoop whoop, it's gone :) :T

    Thank you all so, so much for all your help. :A Now I just need to sort out all my anti virus etc, but that should be a piece of cake compared to getting rid of Cyber Security.

    Cyber drinks all round methinks :beer:

    Peace and tranquility should now be restored at Chez TM and I won't have to sell my son for medical research :rotfl:

    Cheers
    TM xx
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    if you can post the malwarebytes log for us to check ....ta
    Ex forum ambassador

    Long term forum member
  • Ticklemouse
    Ticklemouse Posts: 5,030 Forumite
    1,000 Posts Combo Breaker
    This is the last log I have, where it found the problems. Is this what you wanted to see?

    Malwarebytes' Anti-Malware 1.30
    Database version: 1306
    Windows 5.1.2600 Service Pack 2
    18/11/2008 14:32:04
    mbam-log-2008-11-18 (14-32-04).txt
    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 144260
    Time elapsed: 43 minute(s), 13 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 8
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
  • I have had, and am still having exactly the same issue and cannot get rid of it....
    We have followed the posts and did everything we could, we couldn't find the shield / padlock when we were looking for it, so we carried on, muddled on more like, and ran it. the log says

    ComboFix 09-10-20.03 - VALERIE 21/10/2009 18:09.1.2 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2037.962 [GMT 1:00]
    Running from: c:\users\VALERIE\Desktop\ComboFix.exe
    AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
    FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
    FW: Outpost Firewall *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
    SP: Norton 360 *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
    SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\$recycle.bin\S-1-5-21-1861470252-1969878247-719980794-500
    c:\$recycle.bin\S-1-5-21-2312294832-2679160596-2828777181-500
    c:\windows\Installer\63ecd.msi
    c:\windows\system32\41-v5.exe
    c:\windows\system32\KBL.LOG
    .
    ((((((((((((((((((((((((( Files Created from 2009-09-21 to 2009-10-21 )))))))))))))))))))))))))))))))
    .
    2009-10-21 17:18 . 2009-10-21 17:18
    d
    w- c:\users\Default\AppData\Local\temp
    2009-10-21 16:59 . 2009-10-01 09:29 195440
    w- c:\windows\system32\MpSigStub.exe
    2009-10-20 14:09 . 2009-10-20 14:09
    d
    w- c:\users\VALERIE\AppData\Roaming\Malwarebytes
    2009-10-20 14:09 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-10-20 14:09 . 2009-10-20 14:09
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2009-10-20 14:09 . 2009-10-20 14:09
    d
    w- c:\programdata\Malwarebytes
    2009-10-20 14:09 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-10-17 13:05 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
    2009-10-17 13:05 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
    2009-10-17 13:05 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
    2009-10-14 12:47 . 2009-10-14 12:49
    d
    w- c:\windows\system32\ca-ES
    2009-10-14 12:47 . 2009-10-14 12:49
    d
    w- c:\windows\system32\eu-ES
    2009-10-14 12:47 . 2009-10-14 12:49
    d
    w- c:\windows\system32\vi-VN
    2009-10-14 12:33 . 2009-10-14 12:33
    d
    w- c:\windows\system32\EventProviders
    2009-10-13 14:43 . 2009-10-13 14:43
    d
    w- c:\program files\Common Files\CSUninstall
    2009-10-13 14:42 . 2009-10-13 14:43
    d
    w- c:\program files\CS
    2009-10-09 20:17 . 2009-04-11 06:28 758784 ----a-w- c:\windows\system32\qmgr.dll
    2009-10-09 20:16 . 2009-04-11 06:28 876032 ----a-w- c:\windows\system32\wer.dll
    2009-10-09 20:15 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
    2009-10-06 10:08 . 2009-10-06 10:08
    d
    w- c:\program files\Microsoft
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-18 16:20 . 2008-05-23 16:47 680 ----a-w- c:\users\VALERIE\AppData\Local\d3d9caps.dat
    2009-10-18 16:17 . 2006-11-02 11:18
    d
    w- c:\program files\Windows Mail
    2009-10-18 16:05 . 2007-11-12 08:38
    d
    w- c:\programdata\Microsoft Help
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Calendar
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Sidebar
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Journal
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Collaboration
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Photo Gallery
    2009-10-14 12:50 . 2006-11-02 12:37
    d
    w- c:\program files\Windows Defender
    2009-10-11 21:14 . 2008-05-23 16:07 76568 ----a-w- c:\users\VALERIE\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-10-06 09:18 . 2008-12-11 20:10
    d
    w- c:\program files\Common Files\Adobe AIR
    2009-09-10 16:48 . 2009-10-17 13:06 218624 ----a-w- c:\windows\system32\msv1_0.dll
    2009-08-29 00:27 . 2009-09-04 15:26 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2009-08-29 00:14 . 2009-09-04 15:26 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2009-08-27 13:29 . 2009-10-17 13:06 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-08-27 12:40 . 2009-10-17 13:06 834048 ----a-w- c:\windows\system32\wininet.dll
    2009-08-24 14:42 . 2009-05-21 18:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-08-24 14:42 . 2009-05-21 18:23 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-08-24 14:42 . 2009-05-21 18:23 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-14 16:27 . 2009-09-10 20:59 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2009-08-14 15:53 . 2009-09-10 20:59 17920 ----a-w- c:\windows\system32\netevent.dll
    2009-08-14 13:49 . 2009-09-10 20:59 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 17920 ----a-w- c:\windows\system32\ROUTE.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 11264 ----a-w- c:\windows\system32\MRINFO.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 19968 ----a-w- c:\windows\system32\ARP.EXE
    2009-08-14 13:49 . 2009-09-10 20:59 10240 ----a-w- c:\windows\system32\finger.exe
    2009-08-14 13:48 . 2009-09-10 20:59 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
    2009-08-14 13:48 . 2009-09-10 20:59 105984 ----a-w- c:\windows\system32\netiohlp.dll
    2009-08-12 15:32 . 2008-12-11 18:16 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-08-04 12:34 . 2009-10-17 13:06 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 12:34 . 2009-10-17 13:06 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2009-07-26 15:44 . 2009-07-26 15:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
    [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    2009-09-02 10:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-10-22 2363392]
    "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-09-24 1685816]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-21 217088]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-28 202032]
    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-14 222504]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-17 2025752]
    "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-12 149280]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook.dll c:\windows\System32\avgrsstx.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=""
    "FirewallOverride"=""
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2"=hex(b):6b,8d,7a,cd,cd,4c,ca,01
    R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\afw.sys [21/05/2009 19:10 29208]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [21/05/2009 19:23 335240]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [21/05/2009 19:23 108552]
    R1 SandBox;SandBox;c:\windows\System32\drivers\SandBox.sys [21/05/2009 19:13 704384]
    R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [21/05/2009 19:10 1195008]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [21/05/2009 19:23 908056]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [21/05/2009 19:23 297752]
    R3 afwcore;afwcore;c:\windows\System32\drivers\afwcore.sys [21/05/2009 19:13 307224]
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder
    2009-10-21 c:\windows\Tasks\CS.job
    - c:\program files\CS\cs.exe [2009-10-13 14:43]
    2009-10-21 c:\windows\Tasks\User_Feed_Synchronization-{A26B9307-3DCA-4974-8211-0069E6E0CFB2}.job
    - c:\windows\system32\msfeedssync.exe [2008-10-09 07:33]
    .
    .
    Supplementary Scan
    .
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=81&bd=HP&pf=laptop
    IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    .
    - - - - ORPHANS REMOVED - - - -
    HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
    HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-21 18:19
    Windows 6.0.6002 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msiserver]
    "ImagePath"="%systemroot%\system32\msiexec /V"
    .
    LOCKED REGISTRY KEYS
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2009-10-21 18:21
    ComboFix-quarantined-files.txt 2009-10-21 17:21
    Pre-Run: 111,072,006,144 bytes free
    Post-Run: 111,012,728,832 bytes free
    - - End Of File - - A16303F823D3BD932151CA21FD94D139



    can someone help please as it's driving me mad.....

    thank you


    A_S x
    ** Getting back in the swing of saving again.... **

    :T :T :T :T :T
    Trying to find the best deals to save as much as we can..........
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.