This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Windows Firewall Turns Off

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I can unlock those keys with ComboFix:

Please allow ComboFix to update if it asks to do so:

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Hopefully that will resolve the issue and you will be able to install adobe reader
It worked! My only other issue is that Javascript pop-ups are not working correctly. I don't know if you can do anything about that, I am using Mozilla Firefox. Thanks, Katie
Hi,

Please do the following:

Open Firefox

Go to Tools >Options > Web Features.

Make sure the boxes for Enable Java and Enable Javascript are checked

Hit OK

Please post a fresh DDS log so i can ensure you are clean, then we can begin the final tool clean-up,

also advise how your computer is running now and if there are any more outstanding issues.
Both were already checked, but it has made no difference in terms of being able to get the pop-ups working. That is my only current issue. Thanks, Katie DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 12:12:11.29 on Fri 06/19/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.267 [GMT -4:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\HPQ\IAM\bin\asghost.exe svchost.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\svchost.exe -k Cognizance C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Download Manager\DLM.exe C:\Documents and Settings\Katie\Desktop\dds.pif ============== Pseudo HJT Report =============== uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto: uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [CognizanceTS] rundll32.exe c:\progra~1\hpq\iam\bin\AsTsVcc.dll,RegisterModule mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\80'sar~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Arcade.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\fishy.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Fishy.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\memoni~1.lnk - c:\program files\verizon wireless\v cast music manager\MEMonitor.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calculator.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~2.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calendar.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si190d~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica CPU meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~3.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Dictionary Search.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sic552~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Drive Meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sie814~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Memory Meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si1a09~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Search.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sid033~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Volume Control.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~4.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Weather.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\stickies.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Sticky Notes.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_2cd672ae.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://0-site.ebrary.com.helin.uri.edu/lib/rwu/support/plugins/ebraryRdr.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://www.shockwave.com/content/dinerdash2/sis/DinerDash2.1.0.0.67.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1148585042580 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148585593546 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} - hxxp://www.shockwave.com/content/davincicode/sis/DVC%20Download%20Control.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Notification Packages = scecli AsWlnPkg ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\katie\applic~1\mozilla\firefox\profiles\5ytejixw.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/index.html FF - plugin: c:\documents and settings\katie\application data\mozilla\firefox\profiles\5ytejixw.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-7 64160] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896] R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-12-21 186016] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-12-21 177824] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-5-27 1757936] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-7 101936] R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-5-25 87936] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090612.003\naveng.sys [2009-6-12 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090612.003\navex15.sys [2009-6-12 876144] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-12-21 83616] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-5-27 169200] =============== Created Last 30 ================ 2009-06-19 12:02 –d—– c:\program files\Download Manager 2009-06-08 23:41 –d—– c:\program files\ESET 2009-06-08 10:05 –d—– c:\docume~1\katie\applic~1\Malwarebytes 2009-06-08 10:05 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-08 10:05 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-08 10:05 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-08 10:05 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-07 18:41 a-dshr– C:\cmdcons 2009-06-07 18:36 161,792 a——- c:\windows\SWREG.exe 2009-06-07 18:36 155,136 a——- c:\windows\PEV.exe 2009-06-07 18:36 98,816 a——- c:\windows\sed.exe 2009-06-07 10:56 –d—– c:\program files\Trend Micro 2009-06-07 10:51 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-07 09:39 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-07 09:22 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-05 20:09 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-06-05 20:09 –d—– c:\program files\SUPERAntiSpyware 2009-06-05 20:09 –d—– c:\docume~1\katie\applic~1\SUPERAntiSpyware.com 2009-06-05 20:08 –d—– c:\program files\common files\Wise Installation Wizard 2009-06-05 14:46 –d—– c:\program files\common files\DivX Shared 2009-06-05 14:46 –d—– c:\program files\DivX 2009-06-04 12:24 –d—– c:\program files\iPod 2009-06-03 23:21 –d—– c:\docume~1\katie\applic~1\OpenOffice.org 2009-06-03 22:29 –d—– c:\program files\JRE 2009-06-03 22:29 –d—– c:\program files\OpenOffice.org 3 2009-06-02 23:12 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-02 23:12 73,728 a——- c:\windows\system32\javacpl.cpl 2009-05-31 15:18 –d—– c:\program files\CueCard 2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx 2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts ==================== Find3M ==================== 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-29 00:46 666,624 a——- c:\windows\system32\wininet.dll 2009-04-29 00:46 81,920 a——- c:\windows\system32\ieencode.dll 2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-15 10:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2008-04-10 21:18 90,009 a——- c:\program files\fzuninstv6.5.6.log 2007-11-06 18:51 91,765 a——- c:\program files\setuplog.txt 2007-11-06 18:51 88,692 a——- c:\program files\fzuninstv6.5.1.log ============= FINISH: 12:13:16.89 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/19/2006 1:57:00 AM System Uptime: 6/18/2009 9:40:45 AM (27 hours ago) Motherboard: Hewlett-Packard | | 30A3 Processor: Genuine Intel® CPU T2600 @ 2.16GHz | U10 | 994/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 93 GiB total, 20.826 GiB free. D: is CDROM (CDFS) E: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 6/7/2009 6:36:30 PM - System Checkpoint RP2: 6/8/2009 6:39:44 PM - System Checkpoint RP3: 6/9/2009 9:36:21 PM - System Checkpoint RP4: 6/9/2009 11:00:51 PM - Removed J2SE Runtime Environment 5.0 Update 6 RP5: 6/9/2009 11:09:49 PM - Installed Java™ 6 Update 14 RP6: 6/9/2009 11:23:53 PM - Removed Adobe Reader 7.1.0 RP7: 6/9/2009 11:25:35 PM - Installed Adobe Reader 9.1. RP8: 6/9/2009 11:29:12 PM - Installed Adobe Reader 9.1. RP9: 6/10/2009 8:18:51 AM - Installed Adobe Reader 9.1. RP10: 6/10/2009 8:55:31 AM - Installed Adobe Reader 9.1. RP11: 6/11/2009 6:33:43 PM - System Checkpoint RP12: 6/12/2009 3:01:50 AM - Software Distribution Service 3.0 RP13: 6/13/2009 9:34:25 AM - Software Distribution Service 3.0 RP14: 6/14/2009 12:47:08 PM - Software Distribution Service 3.0 RP15: 6/15/2009 4:54:44 PM - Software Distribution Service 3.0 RP16: 6/16/2009 12:10:13 AM - Installed Adobe Reader 9.1. RP17: 6/16/2009 9:13:02 AM - Software Distribution Service 3.0 RP18: 6/16/2009 9:50:56 AM - Software Distribution Service 3.0 RP19: 6/16/2009 10:00:49 AM - Installed Adobe Reader 9.1. RP20: 6/16/2009 11:12:10 PM - Installed Adobe Reader 9.1. RP21: 6/17/2009 9:04:02 AM - Software Distribution Service 3.0 RP22: 6/18/2009 9:51:56 AM - Software Distribution Service 3.0 RP23: 6/19/2009 12:03:23 AM - Installed Adobe Reader 9.1. RP24: 6/19/2009 10:03:16 AM - Software Distribution Service 3.0 ==== Installed Programs ====================== Ad-Aware Ad-Aware SE Plus Adobe Flash Player 10 Plugin Adobe Photoshop 7.0 Adobe Reader 9.1 Agere Systems HDA Modem AIM 6 AiO_Scan AOL Instant Messenger Apple Mobile Device Support Apple Software Update ArcSoft Magic-i 3 ArcSoft PhotoStudio 5.5 ArcSoft VideoImpression 2 ArcSoft WebCam Companion 2 ATI Catalyst Control Center ATI Display Driver AutoCAD 2007 - English Autodesk DirectConnect 2009 R1 Autodesk DWF Viewer Autodesk License Manager 1.0.31 AviSynth 2.5 Bonjour Bonjour Core for Windows Broadcom 440x 10/100 Integrated Controller Broadcom 802.11 Wireless LAN Adapter Broadcom NetXtreme Ethernet Controller Camera Access Library Camera Support Core Library Camera Window DS Camera Window DVC Camera Window MC Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window DSLR 5 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX (E) Compatibility Pack for the 2007 Office system CueCard (remove only) DivX Web Player Download Manager 2.3.9 DVD Decrypter (Remove Only) Enterprise ESET Online Scanner v3 Finale NotePad 2007 Fingerprint Sensor Minimum Install formZ RenderZone Plus v6.5.1 formZ RenderZone Plus v6.5.6 Google Earth Google SketchUp Google SketchUp 6 HDAUDIO Soft Data Fax Modem with SmartCP High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB952287) HP Button Manager HP Credential Manager for ProtectTools HP Integrated Module with Bluetooth wireless technology HP ProtectTools Security Manager 2.00 C3 HP PSC & Officejet 4.2 Corporate Edition HP Quick Launch Buttons 6.00 D2 HP Webcam User’s Guide HP Wireless Assistant 2.00 E1 Intel Matrix Storage Manager Intel® Graphics Media Accelerator Driver InterActual Player InterVideo DVD Check InterVideo WinDVD iTunes Java™ 6 Update 14 LG USB Modem driver LightScribe 1.4.74.1 LiveUpdate 2.6 (Symantec Corporation) Macromedia Flash Player 8 Macromedia Shockwave Player Malwarebytes' Anti-Malware Maple 10 Maya 2009 Maya 2009 Documentation (en_US) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MovieEdit Task Mozilla Firefox (3.0.11) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Multiframe 11 Demo Octoshape add-in for Adobe Flash Player OpenOffice.org 3.1 PhotoStitch QFolder QuickTime RAW Image Task 2.2 RollerCoaster Tycoon 3 Ruckus Player Scan Security Update for CAPICOM (KB931906) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) SimCity 2000® Special Edition Skype™ 3.8 Sonic Audio Module Sonic Copy Module Sonic Data Module Sonic Express Labeler Sonic Update Manager SoundMAX SUPERAntiSpyware Free Edition Symantec AntiVirus Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. The Sims 2 The Sims 2 Family Fun Stuff The Sims 2 Glamour Life Stuff The Sims 2 Nightlife The Sims 2 Open For Business The Sims™ 2 Bon Voyage The Sims™ 2 FreeTime The Sims™ 2 H&M® Fashion Stuff The Sims™ 2 Seasons The Sims™ 2 Teen Style Stuff TIPCI U3Launcher Uninstall 1.0.0.1 Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) V CAST Music Manager VC80CRTRedist - 8.0.50727.762 Virtual Earth 3D (Beta) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Media Connect Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 10 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 6/18/2009 7:45:34 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 6/12/2009 8:05:55 PM, error: SAVRT [20] - Unable to initialize the virus scanning engine database files. 6/12/2009 3:17:36 AM, error: SCardSvr [602] - WDM Reader driver initialization cannot open reader device: The system cannot find the path specified. 6/12/2009 3:10:12 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office Excel 2003 (KB969681). ==== End Of File ===========================
hi,

There are a number of settings that could be the issue.

Please visit this web site:

http://support.mozilla.com/en-US/kb/Using+…in+with+Firefox

Mozilla support walks you through the troubleshooting steps better than I could describe them.

See if their recommendations assist in resolving the issue. - post back if it does not.

In the meantime, your log is clean of malware so lets clean up the tools.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


Should you wish to contribute to the ongoing development of ComboFix, donations are being accepted via PayPal.



Next


Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

Next


Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • For Firefox, I highly recommend this additional add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Please read these useful guides How did I get infected in the first place?
  • PC Safety and Security–What Do I Need?

miekiemoes' Prevention topic.


Thank you for your patience, and performing all of the procedures requested.
I have not done the clean up yet, but it is not Java that is giving me a problem, it is Javascript pop-ups and I cannot even get Mozilla help chat to load because of this problem. Let me know if you have any suggestions.
Hi,

Do the clean-up then head over to our SOFTWARE forum - I'm sure one of our expert tech's will know what's causing the issue and be able to help you.

Please link back to this topic so they can see you are clean of malware.

Sometimes when removing malware, an essential service or setting is altered along with it
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI