We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Hijack this, please

Options
2

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Please open malwarebytes, goto LOGS and post the WHOLE of the last log
    :idea:
  • lesley1966
    lesley1966 Posts: 113 Forumite
    aliEnRIK wrote: »
    Please open malwarebytes, goto LOGS and post the WHOLE of the last log


    Malwarebytes' Anti-Malware 1.44
    Database version: 3787
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    20/03/2010 15:58:08
    mbam-log-2010-03-20 (15-58-08).txt

    Scan type: Full Scan (C:\|D:\|E:\|)
    Objects scanned: 218308
    Time elapsed: 58 minute(s), 14 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Its a tad out of date, latest database version is 3888, id recommend UPDATING and running another full scan
    :idea:
  • lesley1966
    lesley1966 Posts: 113 Forumite
    aliEnRIK wrote: »
    Its a tad out of date, latest database version is 3888, id recommend UPDATING and running another full scan

    I'm trying to - but the "Check for updates online" button doesn't do anything...
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Please run COMBOFIX
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Shut down your anti virus
    Follow the simple instructions it gives
    Post the COMPLETE log it creates here (Split into sections if need be) ~ if there are loads of 'SNAPSHOT' pages then leave them out

    If it comes up with a RENAMING error then RIGHT click the exe file and RENAME and call it QWERTY (Making the complete file name 'QWERTY.exe') Or SAVE as 'QWERTY' on download
    :idea:
  • lesley1966
    lesley1966 Posts: 113 Forumite
    aliEnRIK wrote: »
    Please run COMBOFIX
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Shut down your anti virus
    Follow the simple instructions it gives
    Post the COMPLETE log it creates here (Split into sections if need be) ~ if there are loads of 'SNAPSHOT' pages then leave them out

    Ok, part 1

    ComboFix 10-03-20.01 - Administrator 21/03/2010 1:31.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.459 [GMT 0:00]
    Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\recycler\S-1-5-21-1708537768-602609370-725345543-500
    c:\recycler\S-1-5-21-171454706-334636932-2827031566-500
    E:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2010-02-21 to 2010-03-21 )))))))))))))))))))))))))))))))
    .

    2010-03-21 01:39 . 2010-03-21 01:39 114688 ----a-w- c:\windows\system32\chg.exe
    2010-03-20 16:47 . 2010-02-12 10:03 293376
    w- c:\windows\system32\browserchoice.exe
    2010-03-20 16:41 . 2010-03-20 16:41
    d-sh--w- c:\documents and settings\Administrator\IECompatCache
    2010-03-20 16:40 . 2010-03-20 16:40
    d-sh--w- c:\documents and settings\Administrator\PrivacIE
    2010-03-20 16:39 . 2010-03-20 16:39
    d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2010-03-20 16:39 . 2010-03-20 16:39
    d-sh--w- c:\documents and settings\Administrator\IETldCache
    2010-03-20 16:32 . 2010-03-20 16:32
    d
    w- c:\windows\ie8updates
    2010-03-20 16:29 . 2010-03-20 16:30
    dc-h--w- c:\windows\ie8
    2010-03-20 16:26 . 2009-12-11 08:38 69120
    w- c:\windows\system32\dllcache\iecompat.dll
    2010-03-20 16:26 . 2009-12-21 19:14 594432
    w- c:\windows\system32\dllcache\msfeeds.dll
    2010-03-20 16:26 . 2009-12-21 19:14 55296
    w- c:\windows\system32\dllcache\msfeedsbs.dll
    2010-03-20 16:26 . 2009-12-21 19:14 12800
    w- c:\windows\system32\dllcache\xpshims.dll
    2010-03-20 16:26 . 2009-12-21 19:14 246272
    w- c:\windows\system32\dllcache\ieproxy.dll
    2010-03-20 16:26 . 2009-12-21 19:14 1985536
    w- c:\windows\system32\dllcache\iertutil.dll
    2010-03-20 16:26 . 2009-12-21 19:14 11070464
    w- c:\windows\system32\dllcache\ieframe.dll
    2010-03-20 14:40 . 2010-03-20 14:40
    d
    w- c:\program files\TrendMicro
    2010-03-16 18:34 . 2010-03-16 18:34
    d
    w- c:\program files\Trend Micro
    2010-03-16 14:27 . 2010-02-25 09:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
    2010-03-16 14:23 . 2010-02-25 10:03 30536 ----a-w- c:\windows\system32\TURegOpt.exe
    2010-03-16 14:23 . 2010-03-16 14:23
    d
    w- c:\documents and settings\Administrator\Application Data\TuneUp Software
    2010-03-16 14:22 . 2010-03-16 14:27
    d
    w- c:\program files\TuneUp Utilities 2010
    2010-03-16 14:22 . 2010-03-16 14:22
    d
    w- c:\documents and settings\All Users\Application Data\TuneUp Software
    2010-03-16 14:21 . 2010-03-16 14:21
    d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
    2010-03-16 13:48 . 2010-03-16 13:48
    d
    w- c:\program files\Uniblue
    2010-03-16 00:42 . 2010-03-16 00:42
    d
    w- c:\program files\iPod
    2010-03-16 00:38 . 2010-03-16 00:39
    d
    w- c:\program files\QuickTime
    2010-03-14 18:34 . 2010-03-14 18:34
    d
    w- c:\documents and settings\Administrator\Local Settings\Application Data\Real
    2010-03-14 18:32 . 2010-03-14 18:32
    d
    w- c:\program files\Common Files\xing shared
    2010-03-14 15:17 . 2010-03-14 15:17 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-03-12 18:51 . 2010-03-12 18:51
    d
    w- c:\program files\JRE
    2010-03-10 17:35 . 2010-03-15 19:29 256 ----a-w- c:\windows\system32\pool.bin
    2010-03-10 17:35 . 2010-03-10 17:35
    d
    w- c:\documents and settings\Administrator\Application Data\Research In Motion
    2010-03-10 17:33 . 2009-01-09 16:18 27136 ----a-r- c:\windows\system32\drivers\RimSerial.sys
    2010-03-10 17:31 . 2010-03-16 17:38
    d
    w- c:\documents and settings\All Users\Application Data\Research In Motion
    2010-03-10 17:31 . 2010-03-10 17:31
    d
    w- c:\program files\Common Files\Research In Motion
    2010-03-10 17:31 . 2010-03-10 17:33
    d
    w- c:\program files\Research In Motion
    2010-03-09 22:17 . 2009-10-23 15:28 3558912
    w- c:\windows\system32\dllcache\moviemk.exe
    2010-02-21 17:41 . 2010-02-21 17:41 552 ----a-w- c:\windows\system32\d3d8caps.dat
  • lesley1966
    lesley1966 Posts: 113 Forumite
    Part 2

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-20 16:40 . 2009-11-03 09:12
    d
    w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
    2010-03-20 14:40 . 2010-03-20 14:40 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
    2010-03-19 02:55 . 2009-11-25 16:08 1 ----a-w- c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-03-19 02:49 . 2009-11-09 00:12 86308 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-03-16 13:48 . 2010-02-17 19:09
    d
    w- c:\documents and settings\Administrator\Application Data\Uniblue
    2010-03-16 00:43 . 2009-07-23 13:31
    d
    w- c:\program files\iTunes
    2010-03-16 00:42 . 2009-01-17 12:39
    d
    w- c:\program files\Common Files\Apple
    2010-03-16 00:33 . 2010-03-16 00:33 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
    2010-03-16 00:29 . 2009-01-19 23:26
    d
    w- c:\program files\Safari
    2010-03-16 00:25 . 2010-03-16 00:25 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
    2010-03-15 02:51 . 2010-01-28 23:19
    d
    w- c:\program files\CCleaner
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
    2010-03-14 18:32 . 2010-03-14 18:32 300616 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
    2010-03-14 18:32 . 2010-03-14 18:32 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
    2010-03-14 18:32 . 2010-03-14 18:32 329312 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    2010-03-14 18:32 . 2008-06-09 15:44
    d
    w- c:\program files\Common Files\Real
    2010-03-14 18:32 . 2009-09-16 22:56
    d
    w- c:\program files\real
    2010-03-14 18:31 . 2003-03-19 03:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
    2010-03-14 18:31 . 2003-02-21 11:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2010-03-14 15:17 . 2010-03-14 15:17 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
    2010-03-14 15:17 . 2010-03-14 15:17 28424 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
    2010-03-14 15:17 . 2010-03-14 15:17 333192 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
    2010-03-14 15:17 . 2009-03-25 18:09 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-03-14 15:17 . 2008-06-04 10:55 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2010-03-14 15:16 . 2008-06-04 10:55 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-03-13 11:52 . 2008-06-04 20:57 106296 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-03-12 18:51 . 2009-11-25 16:03
    d
    w- c:\program files\OpenOffice.org 3
    2010-03-12 18:00 . 2008-06-09 15:59
    d
    w- c:\documents and settings\Administrator\Application Data\U3
    2010-02-25 03:25 . 2008-06-13 10:54
    d
    w- c:\documents and settings\Administrator\Application Data\Skype
    2010-02-25 00:06 . 2008-06-18 11:32
    d
    w- c:\documents and settings\Administrator\Application Data\skypePM
    2010-02-17 20:01 . 2010-02-17 20:01
    d
    w- c:\program files\Windows Defender
    2010-02-17 19:44 . 2010-02-17 19:41
    d
    w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-02-17 19:44 . 2010-02-17 19:44 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-02-17 19:23 . 2010-02-17 19:22
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2010-02-17 19:23 . 2010-02-17 19:23 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2010-02-17 19:22 . 2010-02-17 19:22
    d
    w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2010-02-17 19:22 . 2010-02-17 19:22
    d
    w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-02-04 01:11 . 2008-09-02 01:44
    d
    w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-02-01 23:54 . 2010-01-28 23:19
    d
    w- c:\program files\Yahoo!
    2010-01-28 23:19 . 2010-01-28 23:19
    d
    w- c:\documents and settings\Administrator\Application Data\Yahoo!
    2010-01-28 23:03 . 2007-07-27 07:46
    d
    w- c:\program files\Java
    2010-01-28 18:50 . 2010-01-28 18:50 348160 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-394db3e3-n\msvcr71.dll
    2010-01-28 18:50 . 2010-01-28 18:50 503808 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-394db3e3-n\msvcp71.dll
    2010-01-28 18:50 . 2010-01-28 18:50 499712 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-394db3e3-n\jmc.dll
    2010-01-28 18:50 . 2010-01-28 18:50 61440 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-334fd694-n\decora-sse.dll
    2010-01-28 18:50 . 2010-01-28 18:50 12800 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-334fd694-n\decora-d3d.dll
    2010-01-28 18:50 . 2007-07-27 07:46
    d
    w- c:\program files\Common Files\Java
    2010-01-26 20:32 . 2009-02-22 21:34
    d
    w- c:\program files\Common Files\Adobe
    2010-01-14 11:12 . 2010-02-17 20:04 181120
    w- c:\windows\system32\MpSigStub.exe
    2010-01-07 16:07 . 2010-02-17 19:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-01-07 16:07 . 2010-02-17 19:22 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-12-31 16:50 . 2004-08-04 08:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    2009-12-21 19:14 . 2004-08-04 08:00 916480 ----a-w- c:\windows\system32\wininet.dll
    .
  • lesley1966
    lesley1966 Posts: 113 Forumite
    Part 3


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    2009-11-25 13:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
    "PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2007-01-09 145184]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 827392]
    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-11-06 177456]
    "CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 17920]
    "Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840]
    "Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-10 806912]
    "Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-10-09 697976]
    "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-05-03 57344]
    "WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2007-05-23 192512]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
    "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-19 623960]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2008-6-4 192512]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
    2007-02-07 01:30 74240 ----a-r- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\system32\APSHook.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ SbHpNp scecli

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
    path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
    backup=c:\windows\pss\BBC iPlayer Desktop.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
    path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
    backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
    backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2009-12-11 15:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2009-12-22 01:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-02-15 18:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
    2007-04-19 20:26 484904 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-11-10 23:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 20:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2010-03-14 18:31 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
  • lesley1966
    lesley1966 Posts: 113 Forumite
    Part 4

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mqsvc.exe"=
    "c:\\WINDOWS\\SMINST\\Scheduler.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [07/02/2007 18:22 100495]
    R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [09/10/2006 20:31 44720]
    R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [29/03/2007 23:54 13696]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [04/06/2008 10:55 216200]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [25/03/2009 18:09 242696]
    R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [07/02/2007 18:23 5808]
    R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [04/08/2004 08:00 14336]
    R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [04/08/2004 08:00 14336]
    R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [14/03/2010 15:16 916760]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [14/03/2010 15:16 308064]
    R2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [30/03/2007 00:50 221184]
    R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [25/02/2010 09:59 1047880]
    R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 07:24 10064]
    S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
    S3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [19/09/2006 16:58 36608]
    S3 INQ1usbser;INQ1 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\INQ1usbser.sys [06/01/2009 22:09 103680]
    S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    Cognizance REG_MULTI_SZ ASBroker ASChannel

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2007-04-19 20:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-15 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

    2010-03-21 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-970466924-1080031110-2498218558-500.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 22:09]

    2010-03-19 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-970466924-1080031110-2498218558-500.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 22:09]
    .
    .
  • lesley1966
    lesley1966 Posts: 113 Forumite
    Part 5

    Supplementary Scan
    .
    uStart Page = hxxp://www.hp.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
    uInternet Settings,ProxyOverride = <local>
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\dxcz4mpe.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
    FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_uk&p=
    FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
    FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: nglayout.initialpaint.delay - 600
    FF - user.js: content.notify.interval - 600000
    FF - user.js: content.max.tokenizing.time - 1800000
    FF - user.js: content.switch.threshold - 600000
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    ActiveSetup-ccc-core-static - msiexec
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.