This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] removing stopsign software

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My kid uploaded the stopsign software. I tried removing it with adaware and also malwarebytes, but no luck. I followed the initial instructions. Here is a copy of my hijack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:00:20 PM, on 9/17/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16890)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\SpiralFrog\Spiralfrog.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\ProgramData\59f35a4\WP59f3.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Windows PC Defender] "C:\ProgramData\59f35a4\WP59f3.exe" /s /d
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 8880 bytes

here also is a copy of the malwarebytes scan log

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6000

9/17/2009 9:58:04 PM
mbam-log-2009-09-17 (21-58-04).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 231722
Time elapsed: 1 hour(s), 12 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 21

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Common Files\PersonalAntiSpy (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\PersonalAntiSpy Free\Activate.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\AsAgents.xml (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\atl71.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\bnlink.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\lapv.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\license.rtf (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\mfc71.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\msvcp71.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\msvcr71.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\pas.ini (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\pas.xml (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\pv.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\readme.rtf (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\shellext.xml (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\sr.log (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\unins000.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\unins000.exe (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\up.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\updater.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\PersonalAntiSpy Free\updaterdb.dat (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Program Files\SAV\sav.ooo (Rogue.SystemAntiVirus) -> Quarantined and deleted successfully.


I hope you studs can help. :)
Hi,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
here's the dds. txt file DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 4:57:05.68 on Fri 09/18/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_15 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2036.1088 [GMT -7:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\Windows\system32\taskeng.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Windows\system32\lxblcoms.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\SpiralFrog\Spiralfrog.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Dell Network Assistant\ezi_hnm2.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Mike\Documents\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213 uWindow Title = Internet Explorer provided by Dell uDefault_Page_URL = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [dscactivate] c:\program files\dell support center\gs_agent\custom\dsca.exe mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SpiralFrog] c:\program files\spiralfrog\Spiralfrog.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL,avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\mike\appdata\roaming\mozilla\firefox\profiles\oxmnlibu.default\ FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll FF - plugin: c:\program files\spiralfrog\NPSFDMGR.dll FF - plugin: c:\program files\spiralfrog\wmp\np-mswmp.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-12 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-12 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-12 297752] R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376] R2 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe -service –> c:\windows\system32\lxblcoms.exe -service [?] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-9-10 1153368] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-12-13 29744] ============== File Associations =============== regfile=regedit.exe "%1" %* scrfile="%1" %* =============== Created Last 30 ================ 2009-09-18 03:19 –d—– C:\PerfLogs 2009-09-17 20:00 –d—– c:\program files\Trend Micro 2009-09-17 14:33 –dsh— c:\users\mike\appdata\roaming\Windows PC Defender 2009-09-17 14:33 –dsh— c:\programdata\WPCDSys 2009-09-17 14:33 –dsh— c:\progra~2\WPCDSys 2009-09-17 14:33 –dsh— c:\programdata\59f35a4 2009-09-17 14:33 –dsh— c:\progra~2\59f35a4 2009-09-09 01:24 897,608 a——- c:\windows\system32\drivers\tcpip.sys 2009-09-09 01:24 104,960 a——- c:\windows\system32\netiohlp.dll 2009-09-09 01:24 27,136 a——- c:\windows\system32\NETSTAT.EXE 2009-09-09 01:24 19,968 a——- c:\windows\system32\ARP.EXE 2009-09-09 01:24 17,920 a——- c:\windows\system32\ROUTE.EXE 2009-09-09 01:24 17,920 a——- c:\windows\system32\netevent.dll 2009-09-09 01:24 11,264 a——- c:\windows\system32\MRINFO.EXE 2009-09-09 01:24 10,240 a——- c:\windows\system32\finger.exe 2009-09-09 01:24 9,728 a——- c:\windows\system32\TCPSVCS.EXE 2009-09-09 01:24 8,704 a——- c:\windows\system32\HOSTNAME.EXE 2009-09-09 01:23 2,501,921 a——- c:\windows\system32\wlan.tmf 2009-09-09 01:23 513,024 a——- c:\windows\system32\wlansvc.dll 2009-09-09 01:23 302,592 a——- c:\windows\system32\wlansec.dll 2009-09-09 01:23 293,376 a——- c:\windows\system32\wlanmsm.dll 2009-09-09 01:23 127,488 a——- c:\windows\system32\L2SecHC.dll 2009-09-09 01:23 68,096 a——- c:\windows\system32\wlanhlp.dll 2009-09-09 01:23 64,512 a——- c:\windows\system32\wlanapi.dll 2009-09-09 01:23 15,181 a——- c:\windows\system32\gatherWirelessInfo.vbs 2009-09-09 01:23 2,334 a——- c:\windows\system32\wbem\L2SecHC.mof 2009-09-09 01:23 2,868,224 a——- c:\windows\system32\mf.dll 2009-09-02 12:42 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-09-02 12:42 28,672 a——- c:\windows\system32\Apphlpdm.dll 2009-08-26 03:00 2,048 a——- c:\windows\system32\tzres.dll 2009-08-19 05:38 1,256,448 a——- c:\windows\system32\lsasrv.dll 2009-08-19 05:38 499,712 a——- c:\windows\system32\kerberos.dll 2009-08-19 05:38 270,848 a——- c:\windows\system32\schannel.dll 2009-08-19 05:38 213,504 a——- c:\windows\system32\msv1_0.dll 2009-08-19 05:38 175,104 a——- c:\windows\system32\wdigest.dll 2009-08-19 05:38 439,896 a——- c:\windows\system32\drivers\ksecdd.sys 2009-08-19 05:38 72,704 a——- c:\windows\system32\secur32.dll 2009-08-19 05:38 9,728 a——- c:\windows\system32\lsass.exe ==================== Find3M ==================== 2009-09-18 03:37 174 a–sh— c:\program files\desktop.ini 2009-09-18 03:36 143,360 a——- c:\windows\inf\infstrng.dat 2009-09-18 03:36 86,016 a——- c:\windows\inf\infstor.dat 2009-09-18 03:36 51,200 a——- c:\windows\inf\infpub.dat 2009-09-18 03:19 665,600 a——- c:\windows\inf\drvindex.dat 2009-09-17 22:54 101,888 a——- c:\windows\system32\ifxcardm.dll 2009-09-17 22:54 82,432 a——- c:\windows\system32\axaltocm.dll 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-08-28 05:39 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2009-08-28 05:38 2,153,984 a——- c:\windows\apppatch\AcGenral.dll 2009-08-28 05:38 541,696 a——- c:\windows\apppatch\AcLayers.dll 2009-08-28 05:38 459,776 a——- c:\windows\apppatch\AcSpecfc.dll 2009-08-26 09:52 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-08-26 09:52 335,240 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2009-07-18 09:06 827,904 a——- c:\windows\system32\wininet.dll 2009-07-18 09:01 78,336 a——- c:\windows\system32\ieencode.dll 2009-07-18 02:46 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-07-17 07:35 71,680 a——- c:\windows\system32\atl.dll 2009-07-14 06:00 313,344 a——- c:\windows\system32\wmpdxm.dll 2009-07-14 05:59 4,096 a——- c:\windows\system32\dxmasf.dll 2009-07-14 05:58 7,680 a——- c:\windows\system32\spwmp.dll 2009-07-14 03:59 8,147,456 a——- c:\windows\system32\wmploc.DLL 2008-07-31 21:53 0 a——- c:\users\mike\jagex_runescape_preferences.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2004-07-22 10:51 3,432,656 a——- c:\program files\ManagedDX.CAB 2004-07-19 22:58 1,156,363 a——- c:\program files\BDANT.cab 2004-07-19 22:53 976,020 a——- c:\program files\BDAXP.cab 2004-07-09 14:17 13,265,040 a——- c:\program files\dxnt.cab 2004-07-09 09:13 15,493,481 a——- c:\program files\DirectX.cab 2004-07-09 09:13 703,080 a——- c:\program files\BDA.cab 2004-07-09 04:08 472,576 a——- c:\program files\dxsetup.exe 2004-07-09 04:08 2,242,560 a——- c:\program files\dsetup32.dll 2004-07-09 03:03 62,976 a——- c:\program files\DSETUP.dll 2007-12-24 22:31 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2007-12-24 22:31 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2007-12-24 22:31 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat 2007-12-13 11:05 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 4:57:33.66 =============== I tried to download gmer.exe and I rec'd a message that some parts were missing, so it would not load. "the open offfice xlm gmer.zip cannot be opened because there are problems with the contents" Details "The file is corrupt and cannot be opened"
Hi,

Please try this scanner instead:

  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
I'm having a hard time extracting the zip file for root repeal. Do I need to buy zip extracting software? Sorry, I'm not the sharpest tool when it comes to this stuff. :P
No, Vista comes with a built in zip utility you should just be able to save the file to your desktop double click on the icon then the utility will kick in and ask where you want to extract the files to. (extract to your desktop) You should be logged in as the Administrator…or right click and run as Administrator What happens when you try to download/click the downloaded file?
I download the zip file and it ends up in documents. When I attempt to open it from there. The default program is Microsoft word. It tells me that it can't open the file because it's corrupt.
OK

you need to change the location of where you are saving it to



  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


change the location to "desktop"


then when you go to open the file on your desktop…it will ask you what to open it with and the Zip archiver should be the first option for you to choose
Ok, so I downloaded rootrepeal to my desktop. When I try to open it, the system tries to use ie to open it. This causes the system to go crazy with ie flashing on and off. Do I need to associate a program to open rootrepeal? I looked at the list of programs and zip archiver was not there.
Can you please tell me what options you do have available?


Please try the following scan instead

Please download Sysprot Antirootkit from >>>HERE<<<

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select ALL ITEMS
  • Look near the bottom left, and Check Hidden Objects Only
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
The error message I get is. "windows cannot find c:\users\mike\desktop\rootrepeal.zip" when it tries to open in word. It appears to be not finding the compressed files program. The programs that are in the "open with" box include ie, word and irfanview, the other options are adobe,zune, microsoft media center,paint,windows media, wordpad,itunes,micrsoft picture manager,notepad,windows calendar and windows photo gallery. A while back I think I remember downloading a program for rar programs. When I try to right click the icons and hit extract files I get this error message. "windows cannot find winrar.exe, make sure you typed the name correctly.

The programs that are in the "open with" box include ie, word and irfanview, the other options are adobe,zune, microsoft media center,paint,windows media, wordpad,itunes,micrsoft picture manager,notepad,windows calendar and windows photo gallery.


Do you get a "browse" option?

browse your program files till you find the zip program.

If you can't find it…move on to the Sysprot program
Hi,

just going back to extracting zipped files for a moment>>>

when you right click the zipped file do you see the following:

[external image: Posted Image]


In the popup menu, click on Extract All….

An Extract Compressed (Zipped) folders window appears.
Click on Browse…, then browse your hard drive to search for the destination folder and extract your file.

[external image: Posted Image]

The Select a destination window appears.
Select the destination folder, such as Desktop, then click on OK.

[external image: Posted Image]

The Extract Compressed (Zipped) folders window appears again.
The path for the destination folder now appears.
Click on Extract.
The file is uncompressed and you may now access its content.

Does that work for you?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI