We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
HELP- Pripi
Comments
-
It's not my program although I am acquainted with the person who developed it and admire his expertise greatly.countwiththecount wrote: »pchelpman's ComboFix ....
As recommended above you really should start your own new topic in this forum and post the log report there.countwiththecount wrote: »pch - I can send you ComboFix.txt if required, but is there a better way to get this to you than posting it on the forum?
I don't fix PC trouble via PM or any other way than open forum.
You needn't worry about the content of CF's scan report. Many, many people all over the world post CF logs in open forum.
PCH0 -
Not sure if this is 'jumping on the back' but it's the same problem, which all started a few days ago with, what is apparently a Windows XP Service Pack 2 update that they are trying to fix. The result is that your sound goes and IE changes from modern to classic, willy-nilly. (I'm still trying to fix that.)
Generic Host Process for Win32 Services has encountered a problem and needs to close.
\DOCUME~1\BRYAN~1.SN0\LOCALS~1\Temp\WERd552.dir00\svchost.exe.mdmp
\DOCUME~1\BRYAN~1.SN0\LOCALS~1\Temp\WERd552.dir00\appcompat.txt
Anyone else had that?
This has led to the other current prolem mentioned above - this is the ComboFix report I got - any ideas? Apologies if this is in the wrong place.
ComboFix 07-12-08.1 - bryan 2007-12-08 12:53:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2337 [GMT 0:00]
Running from:
\Documents and Settings\bryan.SN049653520569\Local Settings\Temporary Internet Files\Content.IE5\6F8ZGN0V\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\Quarantine
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\!!!!!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
\LEGACY_IPRIP
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.
2007-12-08 11:45 . 2007-12-08 11:45 0 --a
C:\WINDOWS\system32\SDRemoveDB.db
2007-12-08 11:42 . 2007-12-08 12:58 <DIR> d
C:\Program Files\SpywareDetector
2007-12-08 11:42 . 2007-03-19 12:39 270,336 --a
C:\WINDOWS\system32\CheckDll.dll
2007-12-08 11:42 . 2007-09-29 14:04 11,728 --a
C:\WINDOWS\system32\SDEarlyDelete.exe
2007-12-08 11:42 . 2005-02-06 09:02 104 --a
C:\WINDOWS\system32\ProxySettings.ini
2007-12-07 22:57 . 2007-12-07 22:58 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\Virgin Broadband
2007-12-07 22:22 . 2004-08-10 14:00 22,528 --a
C:\WINDOWS\system32\lpdsvc.dll
2007-12-07 22:22 . 2004-08-10 14:00 22,528 --a
C:\WINDOWS\system32\dllcache\lpdsvc.dll
2007-12-07 22:14 . 2007-12-07 22:14 <DIR> d
\Documents and Settings\NetworkService.NT AUTHORITY.001\Application Data\DivX
2007-12-07 22:02 . 2007-12-07 22:02 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\TuneUp Software
2007-12-07 22:01 . 2007-05-16 09:41 29,704 --a
C:\WINDOWS\system32\uxtuneup.dll
2007-12-07 20:30 . 2007-12-07 20:30 <DIR> d
\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-07 16:26 . 2007-12-07 16:35 97 --a
C:\WINDOWS\system32\mhncache.dat
2007-12-07 14:04 . 2007-12-07 14:04 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\Lavasoft
2007-12-07 13:15 . 2007-12-07 14:39 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\MEGAUPLOADTOOLBAR
2007-12-07 13:05 . 2007-12-07 13:05 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\Nero
2007-12-07 13:03 . 2007-03-09 14:47 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\You've Got Pictures Screensaver
2007-12-07 13:03 . 2007-03-09 14:49 <DIR> d
\Documents and Settings\bryan.SN049653520569\Application Data\Symantec
2007-12-06 09:51 . 2007-12-06 09:51 <DIR> d
\Documents and Settings\bryan\Application Data\Yahoo!
2007-12-05 13:49 . 2007-12-05 13:49 <DIR> d
\Documents and Settings\bryan\Application Data\ieSpell
2007-12-02 10:11 . 2007-12-02 11:20 552 --a
C:\WINDOWS\system32\DO_NOT_DELETE.backupSetID
2007-11-29 10:43 . 2007-11-29 10:43 <DIR> d
C:\Program Files\Swf2Avi
2007-11-29 09:02 . 2007-11-29 09:02 <DIR> d
C:\Program Files\ACW
2007-11-25 15:16 . 2007-11-25 15:16 <DIR> d
\Documents and Settings\All Users\Application Data\Nero
2007-11-25 15:16 . 2007-11-25 15:16 <DIR> d
C:\Program Files\Nero
2007-11-25 15:16 . 2007-11-25 15:17 <DIR> d
C:\Program Files\Common Files\Nero
2007-11-24 11:31 . 2007-12-07 13:24 <DIR> d
\Documents and Settings\All Users\Application Data\Google Updater
2007-11-23 14:22 . 2007-12-08 11:42 123 --a
C:\WINDOWS\system\SysSD.dll
2007-11-23 09:39 . 2007-11-23 09:39 <DIR> d
C:\Program Files\AviSynth 2.5
2007-11-23 09:39 . 2006-10-07 17:43 502,784 --a
C:\WINDOWS\x2.64.exe
2007-11-23 09:39 . 2007-05-14 15:24 394,240 --a
C:\WINDOWS\system32\Smab.dll
2007-11-23 09:39 . 2005-02-28 13:16 240,128 --a
C:\WINDOWS\system32\x.264.exe
2007-11-23 09:39 . 2006-04-12 09:47 217,073 --a
C:\WINDOWS\meta4.exe
2007-11-23 09:39 . 2004-01-25 00:00 70,656 --a
C:\WINDOWS\system32\yv12vfw.dll
2007-11-23 09:39 . 2004-01-25 00:00 70,656 --a
C:\WINDOWS\system32\i420vfw.dll
2007-11-23 09:39 . 2006-04-05 08:09 66,560 --a
C:\WINDOWS\MOTA113.exe
2007-11-23 09:12 . 2007-11-23 09:12 20,336 --a
C:\WINDOWS\system32\OEMINFO.PNF
2007-11-22 21:29 . 2007-11-22 21:29 <DIR> d
\Documents and Settings\LocalService.NT AUTHORITY\Application Data\PeerNetworking
2007-11-22 21:25 . 2007-11-22 21:25 <DIR> d
C:\WINDOWS\system32\bits
2007-11-22 21:24 . 2007-03-29 12:56 409,600
C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-22 21:24 . 2007-03-29 12:56 18,944
C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-22 21:24 . 2007-03-29 12:56 8,192
C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-22 21:24 . 2007-03-29 12:56 7,168
C:\WINDOWS\system32\dllcache\bitsprx4.dll
2007-11-22 21:24 . 2007-03-29 12:56 7,168
C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-22 21:24 . 2007-03-29 12:56 7,168
C:\WINDOWS\system32\bitsprx4.dll
2007-11-21 11:14 . 2007-11-22 21:03 <DIR> d
C:\Program Files\Windows Live Toolbar
2007-11-21 11:12 . 2007-11-21 11:12 <DIR> d
C:\Program Files\Microsoft SQL Server Compact Edition
2007-11-21 11:09 . 2007-11-21 11:10 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-21 11:08 . 2007-11-21 11:08 <DIR> d
\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-21 11:08 . 2007-11-22 21:07 <DIR> d
C:\Program Files\Windows Live
2007-11-18 19:53 . 2007-11-18 19:53 <DIR> d
C:\Program Files\NETGEAR
2007-11-18 19:53 . 2005-05-29 18:00 346,432 --a
C:\WINDOWS\system32\drivers\WPN111.sys
2007-11-18 19:53 . 2006-02-23 15:30 149,544 --a
C:\WINDOWS\system32\drivers\ar5523.bin
2007-11-18 19:53 . 2005-10-06 11:28 15,819 --a
C:\WINDOWS\system32\drivers\netwpn11.inf
2007-11-18 19:53 . 2005-10-19 05:03 8,263 --a
C:\WINDOWS\system32\drivers\WPN111.cat
2007-11-12 21:18 . 2007-11-12 21:18 <DIR> d
C:\Program Files\Trend Micro
2007-11-11 21:49 . 2007-11-11 21:49 109 --a
C:\WINDOWS\PControl.ini
2007-11-11 21:34 . 2004-03-09 00:00 124,688 --a
C:\WINDOWS\system32\mswinsck.ocx
2007-11-11 13:17 . 2007-11-13 08:30 <DIR> d
\Documents and Settings\All Users\Application Data\STOPzilla!
2007-11-10 11:00 . 2007-12-08 11:47 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-11-09 13:44 . 2006-09-25 02:53 2,518,779 --a
C:\WINDOWS\system32\erdmpg-enc.dll
2007-11-09 13:44 . 2006-09-25 02:53 268,242 --a
C:\WINDOWS\system32\erdmpg-parse.dll
2007-11-09 13:44 . 2006-11-13 22:20 237,568 --a
C:\WINDOWS\system32\erdmpg-5.2.dll
2007-11-09 13:44 . 2006-07-05 01:47 196,608 --a
C:\WINDOWS\system32\StudioProProp.ax
2007-11-09 13:44 . 2006-11-13 22:23 159,744 --a
C:\WINDOWS\system32\DirectEncode.dll
2007-11-09 13:44 . 2007-01-05 21:18 120,320 --a
C:\WINDOWS\system32\drivers\StudioPro.sys
2007-11-09 13:44 . 2007-04-22 19:27 38,784 --a
C:\WINDOWS\system32\drivers\vrtaucbl.sys
2007-11-09 13:44 . 2006-09-25 02:52 30,693 --a
C:\WINDOWS\system32\erdmpg-int.dll
2007-11-09 13:44 . 2007-11-09 13:52 31 --a
C:\WINDOWS\e2eSoft.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 23:39
d
w C:\Program Files\Common Files\Command Software
2007-12-07 23:02
d
w C:\Program Files\Common Files\PestPatrol
2007-12-07 22:00
d
w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 16:32
d
w C:\Program Files\Intel
2007-12-07 16:31
d--h--w C:\Program Files\InstallShield Installation Information
2007-12-07 09:18
d
w
\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 18:40
d
w
\Documents and Settings\bryan\Application Data\uTorrent
2007-12-06 18:40
d
w
\Documents and Settings\bryan\Application Data\BitTorrent
2007-12-04 15:29
d
w
\Documents and Settings\bryan\Application Data\Audacity
2007-12-01 11:32
d
w C:\Program Files\Seagate
2007-11-25 15:47
d
w C:\Program Files\Common Files\LightScribe
2007-11-25 13:15
d
w C:\Program Files\Common Files\Ahead
2007-11-24 11:31
d
w C:\Program Files\Google
2007-11-22 12:13
d
w
\Documents and Settings\bryan\Application Data\muvee Technologies
2007-11-20 16:05
d
w
\Documents and Settings\bryan\Application Data\dvdcss
2007-11-13 08:37
d
w C:\Program Files\Freecorder
2007-11-11 13:01
d
w
\Documents and Settings\bryan\Application Data\MegauploadToolbar
2007-11-10 10:48
d
w
\Documents and Settings\All Users\Application Data\avg7
2007-11-06 08:00
d
w
\Documents and Settings\bryan\Application Data\AVG7
2007-11-03 11:51 20 ---h--w
\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-11-01 12:27 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-11-01 12:27
d
w
\Documents and Settings\bryan\Application Data\GetRightToGo
2007-11-01 12:27
d
w C:\Program Files\Replay Converter
2007-10-31 17:40
d
w
\Documents and Settings\bryan\Application Data\IE7Pro
2007-10-30 21:46
d
w
\Documents and Settings\bryan\Application Data\SlimBrowser
2007-10-30 08:23
d
w C:\Program Files\MegauploadToolbar
2007-10-23 17:06 585,728 ----a-w C:\WINDOWS\WLXPGSS.SCR
2007-10-23 14:20 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-10-22 08:51 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-09-22 13:46 282,624 ----a-r C:\WINDOWS\Setup1.exe
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-04-29 09:14 10,856 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_!!79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 14:18]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 10:31]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-08 15:55]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 C:\WINDOWS\RTHDCPL.EXE]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\Rps.exe" [2007-01-24 18:53]
"Broadbandadvisor.exe"="C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-01-24 14:12]
"SystemTraySD"="C:\Program Files\SpywareDetector\SDSystemTray.exe" [2007-09-17 13:40]
"SDAutoLiveupdate"="C:\Program Files\SpywareDetector\LiveUpdateSD.exe" [2007-09-17 13:39]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 14:00]
\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [2007-11-18 19:53:31]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PWRISOVM.EXE"="D:\Program Files\PowerISO\PWRISOVM.EXE"
"TotalRecorderScheduler"="D:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
"NvCplDaemon"="RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" -atboottime
"ehTray"=C:\WINDOWS\ehome\ehtray.exe
"UVS10 Preload"=C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
R3 Bonifay;Bonifay;C:\WINDOWS\system32\DRIVERS\Bonifay.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys
S2 StudioPro;StudioPro webcam;C:\WINDOWS\system32\DRIVERS\StudioPro.sys
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 EuMusDesignVirtualAudioCableWdm;StudioPro audio (WDM);C:\WINDOWS\system32\DRIVERS\vrtaucbl.sys
S3 Gonzales;Gonzales;C:\WINDOWS\system32\DRIVERS\Gonzales.sys
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe -k p2psvc
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 22:02:03 C:\WINDOWS\Tasks\1-Click Maintenance.job"
-
\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
DLLs Loaded Under Running Processes
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
->
\DOCUME~1\BRYAN~1.SN0\LOCALS~1\Temp\ihvlgvxp520569.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 12:59:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 13:01:42
.
--- E O F ---
aspnet_regiis.exe has encountered a problem and needs to close0 -
"aspnet_regiis.exe has encountered a problem and needs to close" was not part of the report that was an error from Windows update0
-
@just-popped-in > you suspected right. Please don't piggy back on someone else's thread. Although your problems may be similar they will never be exactly the same and answering two poster's logs in one thread can't be done efficiently.
Two things therefore ...
1. please start you own thread then post HijackThis & logs with details of the problems you are having and ....
2. please advise ... did you receive advice/directions from anyone on using Combofix (apart from what you have read here)? If so ... where did you get the advice?
PCH0 -
I use vigin as my ISP and suddenly got messages from their anti spywatre that the pripi spyware was on my system.
I followed the instructions here using the combofix and all is now well. many thanks0 -
Use Combofix That Will Clear It0
-
REMEMBER >>> ONLY use Combofix if you are ABSOLUTELY CERTAIN you have this pripi infection SPECIFICALLY.Use Combofix That Will Clear It
You must NEVER use CF ad lib, willy nilly. It is very powerful and could wreck your machine if used incorrectly.
If in any doubt ... do NOT use Combofix but scan your system with HijackThis instead.
Post the resulting HJT scan report to a new thread in this forum (with a brief explanation of your problem) and someone will guide you on what to do next.
PCH0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 352.3K Banking & Borrowing
- 253.7K Reduce Debt & Boost Income
- 454.4K Spending & Discounts
- 245.4K Work, Benefits & Business
- 601.1K Mortgages, Homes & Bills
- 177.6K Life & Family
- 259.2K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards
