Hi,
I can unlock those keys with ComboFix:
Please allow ComboFix to update if it asks to do so:
Please do the following:
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:
Here's how to do that:
Click
Start > Run type
Notepad click
OK.
This will open an empty notepad file:
Copy all the text
inside of the code box -
Press Ctrl+C (or right click on the highlighted section and choose 'copy')
RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
Now
paste the copied text into the open notepad - press
CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click
File ;
2.Click
Save As … Change the directory to your
desktop ;
3.Change the
Save as type to
"All Files";
4.Type in the file name:
CFScript
5.Click
Save …
[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hopefully that will resolve the issue and you will be able to install adobe reader
It worked!
My only other issue is that Javascript pop-ups are not working correctly. I don't know if you can do anything about that, I am using Mozilla Firefox.
Thanks, Katie
Hi,
Please do the following:
Open Firefox
Go to Tools >Options > Web Features .
Make sure the boxes for Enable Java and Enable Javascript are checked
Hit OK
Please post a fresh DDS log so i can ensure you are clean, then we can begin the final tool clean-up,
also advise how your computer is running now and if there are any more outstanding issues.
Both were already checked, but it has made no difference in terms of being able to get the pop-ups working. That is my only current issue.
Thanks, Katie
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 12:12:11.29 on Fri 06/19/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.267 [GMT -4:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Download Manager\DLM.exe
C:\Documents and Settings\Katie\Desktop\dds.pif
============== Pseudo HJT Report ===============
uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto:
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hpq\iam\bin\AsTsVcc.dll,RegisterModule
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\80'sar~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Arcade.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\fishy.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Fishy.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\memoni~1.lnk - c:\program files\verizon wireless\v cast music manager\MEMonitor.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calculator.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~2.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calendar.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si190d~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica CPU meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~3.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Dictionary Search.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sic552~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Drive Meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sie814~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Memory Meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si1a09~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Search.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sid033~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Volume Control.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~4.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Weather.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\stickies.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Sticky Notes.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_2cd672ae.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://0-site.ebrary.com.helin.uri.edu/lib/rwu/support/plugins/ebraryRdr.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://www.shockwave.com/content/dinerdash2/sis/DinerDash2.1.0.0.67.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1148585042580
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148585593546
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} - hxxp://www.shockwave.com/content/davincicode/sis/DVC%20Download%20Control.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli AsWlnPkg
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\katie\applic~1\mozilla\firefox\profiles\5ytejixw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/index.html
FF - plugin: c:\documents and settings\katie\application data\mozilla\firefox\profiles\5ytejixw.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-7 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-12-21 186016]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-12-21 177824]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-5-27 1757936]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-7 101936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-5-25 87936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090612.003\naveng.sys [2009-6-12 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090612.003\navex15.sys [2009-6-12 876144]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-12-21 83616]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-5-27 169200]
=============== Created Last 30 ================
2009-06-19 12:02 –d—– c:\program files\Download Manager
2009-06-08 23:41 –d—– c:\program files\ESET
2009-06-08 10:05 –d—– c:\docume~1\katie\applic~1\Malwarebytes
2009-06-08 10:05 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 10:05 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-08 10:05 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-08 10:05 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-07 18:41 a-dshr– C:\cmdcons
2009-06-07 18:36 161,792 a——- c:\windows\SWREG.exe
2009-06-07 18:36 155,136 a——- c:\windows\PEV.exe
2009-06-07 18:36 98,816 a——- c:\windows\sed.exe
2009-06-07 10:56 –d—– c:\program files\Trend Micro
2009-06-07 10:51 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-07 09:39 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-07 09:22 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-05 20:09 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-05 20:09 –d—– c:\program files\SUPERAntiSpyware
2009-06-05 20:09 –d—– c:\docume~1\katie\applic~1\SUPERAntiSpyware.com
2009-06-05 20:08 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-05 14:46 –d—– c:\program files\common files\DivX Shared
2009-06-05 14:46 –d—– c:\program files\DivX
2009-06-04 12:24 –d—– c:\program files\iPod
2009-06-03 23:21 –d—– c:\docume~1\katie\applic~1\OpenOffice.org
2009-06-03 22:29 –d—– c:\program files\JRE
2009-06-03 22:29 –d—– c:\program files\OpenOffice.org 3
2009-06-02 23:12 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-02 23:12 73,728 a——- c:\windows\system32\javacpl.cpl
2009-05-31 15:18 –d—– c:\program files\CueCard
2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts
==================== Find3M ====================
2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll
2009-04-29 00:46 666,624 a——- c:\windows\system32\wininet.dll
2009-04-29 00:46 81,920 a——- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a——- c:\windows\system32\rpcrt4.dll
2008-04-10 21:18 90,009 a——- c:\program files\fzuninstv6.5.6.log
2007-11-06 18:51 91,765 a——- c:\program files\setuplog.txt
2007-11-06 18:51 88,692 a——- c:\program files\fzuninstv6.5.1.log
============= FINISH: 12:13:16.89 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/19/2006 1:57:00 AM
System Uptime: 6/18/2009 9:40:45 AM (27 hours ago)
Motherboard: Hewlett-Packard | | 30A3
Processor: Genuine Intel® CPU T2600 @ 2.16GHz | U10 | 994/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 93 GiB total, 20.826 GiB free.
D: is CDROM (CDFS)
E: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 6/7/2009 6:36:30 PM - System Checkpoint
RP2: 6/8/2009 6:39:44 PM - System Checkpoint
RP3: 6/9/2009 9:36:21 PM - System Checkpoint
RP4: 6/9/2009 11:00:51 PM - Removed J2SE Runtime Environment 5.0 Update 6
RP5: 6/9/2009 11:09:49 PM - Installed Java™ 6 Update 14
RP6: 6/9/2009 11:23:53 PM - Removed Adobe Reader 7.1.0
RP7: 6/9/2009 11:25:35 PM - Installed Adobe Reader 9.1.
RP8: 6/9/2009 11:29:12 PM - Installed Adobe Reader 9.1.
RP9: 6/10/2009 8:18:51 AM - Installed Adobe Reader 9.1.
RP10: 6/10/2009 8:55:31 AM - Installed Adobe Reader 9.1.
RP11: 6/11/2009 6:33:43 PM - System Checkpoint
RP12: 6/12/2009 3:01:50 AM - Software Distribution Service 3.0
RP13: 6/13/2009 9:34:25 AM - Software Distribution Service 3.0
RP14: 6/14/2009 12:47:08 PM - Software Distribution Service 3.0
RP15: 6/15/2009 4:54:44 PM - Software Distribution Service 3.0
RP16: 6/16/2009 12:10:13 AM - Installed Adobe Reader 9.1.
RP17: 6/16/2009 9:13:02 AM - Software Distribution Service 3.0
RP18: 6/16/2009 9:50:56 AM - Software Distribution Service 3.0
RP19: 6/16/2009 10:00:49 AM - Installed Adobe Reader 9.1.
RP20: 6/16/2009 11:12:10 PM - Installed Adobe Reader 9.1.
RP21: 6/17/2009 9:04:02 AM - Software Distribution Service 3.0
RP22: 6/18/2009 9:51:56 AM - Software Distribution Service 3.0
RP23: 6/19/2009 12:03:23 AM - Installed Adobe Reader 9.1.
RP24: 6/19/2009 10:03:16 AM - Software Distribution Service 3.0
==== Installed Programs ======================
Ad-Aware
Ad-Aware SE Plus
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Adobe Reader 9.1
Agere Systems HDA Modem
AIM 6
AiO_Scan
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
ArcSoft Magic-i 3
ArcSoft PhotoStudio 5.5
ArcSoft VideoImpression 2
ArcSoft WebCam Companion 2
ATI Catalyst Control Center
ATI Display Driver
AutoCAD 2007 - English
Autodesk DirectConnect 2009 R1
Autodesk DWF Viewer
Autodesk License Manager 1.0.31
AviSynth 2.5
Bonjour
Bonjour Core for Windows
Broadcom 440x 10/100 Integrated Controller
Broadcom 802.11 Wireless LAN Adapter
Broadcom NetXtreme Ethernet Controller
Camera Access Library
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX (E)
Compatibility Pack for the 2007 Office system
CueCard (remove only)
DivX Web Player
Download Manager 2.3.9
DVD Decrypter (Remove Only)
Enterprise
ESET Online Scanner v3
Finale NotePad 2007
Fingerprint Sensor Minimum Install
formZ RenderZone Plus v6.5.1
formZ RenderZone Plus v6.5.6
Google Earth
Google SketchUp
Google SketchUp 6
HDAUDIO Soft Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB952287)
HP Button Manager
HP Credential Manager for ProtectTools
HP Integrated Module with Bluetooth wireless technology
HP ProtectTools Security Manager 2.00 C3
HP PSC & Officejet 4.2 Corporate Edition
HP Quick Launch Buttons 6.00 D2
HP Webcam User’s Guide
HP Wireless Assistant 2.00 E1
Intel Matrix Storage Manager
Intel® Graphics Media Accelerator Driver
InterActual Player
InterVideo DVD Check
InterVideo WinDVD
iTunes
Java™ 6 Update 14
LG USB Modem driver
LightScribe 1.4.74.1
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Maple 10
Maya 2009
Maya 2009 Documentation (en_US)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MovieEdit Task
Mozilla Firefox (3.0.11)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Multiframe 11 Demo
Octoshape add-in for Adobe Flash Player
OpenOffice.org 3.1
PhotoStitch
QFolder
QuickTime
RAW Image Task 2.2
RollerCoaster Tycoon 3
Ruckus Player
Scan
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
SimCity 2000® Special Edition
Skype™ 3.8
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic Update Manager
SoundMAX
SUPERAntiSpyware Free Edition
Symantec AntiVirus
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
The Sims 2
The Sims 2 Family Fun Stuff
The Sims 2 Glamour Life Stuff
The Sims 2 Nightlife
The Sims 2 Open For Business
The Sims™ 2 Bon Voyage
The Sims™ 2 FreeTime
The Sims™ 2 H&M® Fashion Stuff
The Sims™ 2 Seasons
The Sims™ 2 Teen Style Stuff
TIPCI
U3Launcher
Uninstall 1.0.0.1
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
V CAST Music Manager
VC80CRTRedist - 8.0.50727.762
Virtual Earth 3D (Beta)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 10
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
6/18/2009 7:45:34 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
6/12/2009 8:05:55 PM, error: SAVRT [20] - Unable to initialize the virus scanning engine database files.
6/12/2009 3:17:36 AM, error: SCardSvr [602] - WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
6/12/2009 3:10:12 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office Excel 2003 (KB969681).
==== End Of File ===========================
hi,
There are a number of settings that could be the issue.
Please visit this web site:
http://support.mozilla.com/en-US/kb/Using+…in+with+Firefox
Mozilla support walks you through the troubleshooting steps better than I could describe them.
See if their recommendations assist in resolving the issue. - post back if it does not.
In the meantime, your log is clean of malware so lets clean up the tools.
Please do the following:
Follow these steps to uninstall Combofix
Click START then RUN Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U , it needs to be there.
[external image: Posted Image]
Should you wish to contribute to the ongoing development of ComboFix, donations are being accepted via
PayPal.
Next
Download
ToolsCleaner2 to your desktop and run it
( by de A.Rothstein & Dj Quiou )
Click the Pt. Restauration button and press OK to the prompts. Click the Corbeille button and press OK to the prompt. Click the Fichiers temp button and press OK to the prompt. Click the Recherche button and let it run ( it may look like it freezes but let it continue ) Once it is done click the Suppression button and let it remove anything it finds. Close the program
Next
Below I have included a number of recommendations for how to protect your computer against malware infections.
Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.Make Internet Explorer more secure
Click Start > Run Type Inetcpl.cpl & click OK Click on the Security tab Click Reset all zones to default level Make sure the Internet Zone is selected & Click Custom level In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable". Next Click OK , then Apply button and then OK to exit the Internet Properties page. ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go Yellow for caution Red to stop WOT has an addon available for both Firefox and IE
For Firefox, I highly recommend this additional add-on to keep your PC even more secure.
NoScript - for blocking ads and other potential website attacks Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
Please read these useful guides How did I get infected in the first place? PC Safety and Security–What Do I Need?
miekiemoes' Prevention topic.
Thank you for your patience, and performing all of the procedures requested.
I have not done the clean up yet, but it is not Java that is giving me a problem, it is Javascript pop-ups and I cannot even get Mozilla help chat to load because of this problem. Let me know if you have any suggestions.
Hi,
Do the clean-up then head over to our
SOFTWARE forum - I'm sure one of our expert tech's will know what's causing the issue and be able to help you.
Please link back to this topic so they can see you are clean of malware.
Sometimes when removing malware, an essential service or setting is altered along with it
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.