This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Combo Fix Not available

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste

copy C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys c:\

Press enter

you should see 1 file copied on the screen

type exit to close the command window.

(if you do not see 1 file copied do not continue, but instead post back and let me know.)


=========

You will need to print out the following instructions.

Now we need to boot into the Recovery Environment:

Tap F8 on startup and select Repair your computer from the list of startup options.

If Repair your computer is not an option on the Advanced Startup menu, insert your Windows Vista dvd and restart the computer, then when prompted, select Repair your computer

  • select your keyboard layout
  • enter your username and password (if you use one)
  • then the System Recovery Options menu comes up
  • select Command Prompt

It will open to an x:\sources> prompt

(this may vary depending if you boot from cd or an installed RE)


at the X:\sources prompt type the following


ren c:\windows\system32\drivers\atapi.sys atapi.old
copy c:\atapi.sys c:\windows\system32\drivers\atapi.sys
exit


You should receive a message that "1 file" has been copied.

{if you do not receive a message that 1 file has been copied, the file will need to be renamed back - type
ren c:\windows\system32\drivers\atapi.old atapi.sys press enter
then type exit, reboot the system normally and report this to me.)


Reboot Normally.
Hi Raktor: Ok, heres what i did…followed your instructions, but the only difference was upon getting the command prompt in the System Recovery Option menu it gave me the prompt X:\windows\system32> and that is where i ran the commands you gave me. Also i made a small error and hit enter when typing the second command after i reached "windows" but i redid the comand and it copied the file. Upon reboot my HP Health check and Advisor came back (dont know if they are running correctly) and i stopped getting windows errors pop ups for that and other programs. I also did a few searches and seems the redirects have stopped, at least based on my small test. Please advise how to proceed and thanks again for your help. Tom
Hi Raktor:

I ran Combofix with a fresh copy downloaded. After running, i again was unable to access most icons on my desktop. If i click them i got the message "illegal operation attempted on registry key marked for deletion". So i rebooted the computer. Upon reboot, i got a new message saying i had "blocked startup programs". I will put the list after the combo fix log.
I'm not sure if i should let these run or not. Please advise.

Here is the combofix log and listing of "blocked startup programs" from System Configuration Utility. (I am unable to copy this listing from the System Config. Utility) Please advise how to proceed. thanks again for your help.


ComboFix 09-12-27.04 - THOMAS 12/28/2009 21:46:55.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1747 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-29 05:52 . 2009-12-29 05:52 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-29 05:52 . 2009-12-29 05:52 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-12-29 05:05 . 2009-12-29 05:06 ——– d—–w- c:\program files\Microsoft Money
2009-12-29 04:48 . 2009-12-29 04:48 ——– d—–w- c:\program files\Microsoft Works Suite 2002
2009-12-26 17:03 . 2009-06-22 17:14 4194304 —-a-w- c:\windows\system32\cdintf400.dll
2009-12-26 16:19 . 2009-04-11 06:32 19944 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-26 16:17 . 2009-04-11 06:32 19944 —-a-w- c:\windows\atapi.sys
2009-12-26 16:05 . 2009-04-11 06:32 19944 —-a-w- C:\atapi.sys
2009-12-22 16:18 . 2009-12-19 04:45 294656 —-a-w- c:\programdata\avg9\update\backup\avglngx.dll
2009-12-22 16:18 . 2009-12-11 16:40 4043032 —-a-w- c:\programdata\avg9\update\backup\avgui.exe
2009-12-22 16:18 . 2009-12-11 16:40 3776280 —-a-w- c:\programdata\avg9\update\backup\setup.exe
2009-12-22 16:18 . 2009-12-11 16:40 3967256 —-a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-12-19 15:57 . 2009-12-19 15:57 ——– d—–w- c:\program files\ESET
2009-12-19 15:46 . 2009-12-19 15:46 ——– d—–w- c:\users\THOMAS\AppData\Roaming\Malwarebytes
2009-12-19 15:46 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 15:46 . 2009-12-19 15:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-19 15:46 . 2009-12-19 15:46 ——– d—–w- c:\programdata\Malwarebytes
2009-12-19 15:46 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-19 04:45 . 2009-12-11 16:40 2352920 —-a-w- c:\programdata\avg9\update\backup\avgresf.dll
2009-12-13 03:00 . 2009-12-13 04:54 680 —-a-w- c:\users\THOMAS\AppData\Local\d3d9caps.dat
2009-12-13 03:00 . 2009-12-13 03:00 ——– d—–w- c:\windows\Sun
2009-12-12 15:31 . 2009-11-09 12:31 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-12 15:31 . 2009-11-09 10:36 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-12 15:31 . 2009-11-09 12:30 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-12-10 02:00 . 2009-12-10 02:01 ——– d—–w- c:\program files\ERUNT
2009-12-02 20:09 . 2009-12-02 20:09 ——– d—–w- c:\programdata\Office Genuine Advantage
2009-12-02 20:09 . 2009-12-02 20:09 ——– d—–w- c:\users\THOMAS\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 05:03 . 2009-04-22 14:45 ——– d—–w- c:\program files\Microsoft Works
2009-12-29 02:05 . 2009-04-22 14:57 ——– d—–w- c:\programdata\Microsoft Help
2009-12-28 23:42 . 2009-07-02 03:32 3207 —-a-w- c:\programdata\Intuit\QuickBooks 2009\qbbackup.sys
2009-12-26 00:24 . 2009-11-07 17:06 ——– d—–w- c:\programdata\avg9
2009-12-24 14:52 . 2009-08-08 03:21 ——– d—–w- c:\program files\Google
2009-12-19 04:26 . 2009-07-02 03:41 869664 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\qbpatch.exe
2009-12-12 15:43 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-04 04:05 . 2009-07-02 03:50 536 —-a-w- c:\users\THOMAS\AppData\Roaming\wklnhst.dat
2009-11-29 06:28 . 2009-04-22 15:14 ——– d—–w- c:\program files\Java
2009-11-25 15:17 . 2009-08-12 13:35 852784 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\dblgen11.dll
2009-11-25 15:17 . 2009-08-12 13:35 2168112 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\iAnywhere.Data.SQLAnywhere.dll
2009-11-25 15:17 . 2009-07-02 03:41 205576 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe
2009-11-25 15:17 . 2009-07-02 03:41 1087752 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe
2009-11-21 06:40 . 2009-12-10 01:55 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 01:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-10 01:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-10 01:55 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-20 05:20 . 2009-11-20 05:20 ——– d—–w- c:\users\THOMAS\AppData\Roaming\CyberLink
2009-11-20 05:20 . 2009-11-20 05:20 3063561 —-a-w- c:\programdata\MobileTV.exe
2009-11-20 05:20 . 2009-11-20 05:20 3063561 —-a-w- c:\programdata\MobileTV.exe
2009-11-20 05:20 . 2009-11-20 05:20 2989660 —-a-w- c:\programdata\DVD.exe
2009-11-20 05:20 . 2009-11-20 05:20 2989660 —-a-w- c:\programdata\DVD.exe
2009-11-20 05:20 . 2009-11-20 05:20 2864396 —-a-w- c:\programdata\MPV.exe
2009-11-20 05:20 . 2009-11-20 05:20 2864396 —-a-w- c:\programdata\MPV.exe
2009-11-20 05:20 . 2009-11-20 05:20 2331174 —-a-w- c:\programdata\Karaoke.exe
2009-11-20 05:20 . 2009-11-20 05:20 2331174 —-a-w- c:\programdata\Karaoke.exe
2009-11-20 05:20 . 2009-11-20 05:20 2231606 —-a-w- c:\programdata\Games.exe
2009-11-20 05:20 . 2009-11-20 05:20 2231606 —-a-w- c:\programdata\Games.exe
2009-11-20 05:20 . 2009-11-20 05:20 ——– d—–w- c:\programdata\ENU
2009-11-18 16:01 . 2009-11-18 16:01 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 16:01 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 16:01 . 2009-11-18 16:01 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-09 17:21 . 2009-06-29 03:50 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-07 17:06 . 2009-06-29 03:50 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-07 17:06 . 2009-06-29 03:50 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-07 17:06 . 2009-06-29 03:50 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-07 17:06 . 2009-06-29 03:50 ——– d—–w- c:\program files\AVG
2009-11-06 15:59 . 2009-08-12 13:35 496944 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlrsa10.dll
2009-11-06 15:59 . 2009-08-12 13:35 570672 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlhttps10.dll
2009-11-06 15:59 . 2009-08-12 13:35 296240 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlsock10.dll
2009-11-06 15:59 . 2009-08-12 13:35 263472 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlcrsa10.dll
2009-11-06 15:59 . 2009-08-12 13:35 1152304 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbtool10.dll
2009-11-06 15:59 . 2009-08-12 13:35 787760 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblgen10.dll
2009-11-06 15:59 . 2009-08-12 13:35 763184 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblib10.dll
2009-11-06 15:59 . 2009-08-12 13:35 423216 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbmlsync.exe
2009-11-06 15:59 . 2009-08-12 13:35 398640 —-a-w- c:\programdata\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbcon10.dll
2009-11-03 04:42 . 2009-10-03 14:35 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-26 17:09 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-11 12:17 . 2009-10-10 15:39 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-18 15:24 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-18 15:24 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-18 15:24 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-07 11:36 . 2009-12-10 01:55 243712 —-a-w- c:\windows\system32\rastls.dll
2009-10-01 01:02 . 2009-11-18 15:25 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-18 15:26 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-18 15:25 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-18 15:25 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-18 15:26 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-18 15:25 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-18 15:25 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-18 15:25 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-18 15:25 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-18 15:25 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-11-18 15:25 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-18 15:26 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-04-22 14:18 . 2009-04-22 14:09 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot_2009-12-18_02.36.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-29 01:21 51748 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-29 01:21 88428 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-06-29 04:14 . 2009-12-29 01:21 12970 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-269143086-4138566716-204987309-1000_UserData.bin
+ 2001-08-07 23:06 . 2001-08-07 23:06 76288 c:\windows\System32\Pubole32.dll
+ 2001-08-07 23:07 . 2001-08-07 23:07 37888 c:\windows\System32\ochlp30e.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 91136 c:\windows\System32\msls2.dll
+ 2009-07-04 17:34 . 2009-12-27 14:51 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
- 2009-07-04 17:34 . 2009-10-28 14:37 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2000-05-10 11:34 . 2000-05-10 11:34 59392 c:\windows\System32\lfwmf11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 27648 c:\windows\System32\lftga11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 56320 c:\windows\System32\lfpsd11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 33280 c:\windows\System32\lfpcx11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 26112 c:\windows\System32\lfpcd11n.dll
+ 2000-05-09 18:41 . 2000-05-09 18:41 41472 c:\windows\System32\lfgif11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 81408 c:\windows\System32\lffax11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 31232 c:\windows\System32\lfeps11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 36864 c:\windows\System32\lfbmp11n.dll
+ 2009-06-29 10:22 . 2009-12-29 05:06 98304 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-24 05:34 . 2009-12-24 05:16 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009122320091224\index.dat
+ 2009-12-23 00:08 . 2009-12-23 00:03 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009122220091223\index.dat
+ 2009-12-23 00:08 . 2009-12-23 00:03 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009121420091221\index.dat
+ 2009-06-29 10:22 . 2009-12-29 05:06 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-19 01:08 . 2009-12-25 21:23 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
- 2009-11-28 00:53 . 2009-12-13 15:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-28 00:53 . 2009-12-26 15:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-28 00:53 . 2009-12-26 15:57 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-28 00:53 . 2009-12-13 15:26 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-28 00:53 . 2009-12-26 15:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-11-28 00:53 . 2009-12-13 15:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-06-29 14:59 . 2009-06-29 14:59 20480 c:\windows\Installer\{E7298FD5-1386-11D5-8D6C-0050DAD32D95}\MnyIco.exe
+ 2009-12-29 05:06 . 2009-12-29 05:06 20480 c:\windows\Installer\{E7298FD5-1386-11D5-8D6C-0050DAD32D95}\MnyIco.exe
- 2009-06-29 14:57 . 2009-06-29 14:57 20480 c:\windows\Installer\{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}\MnyIco.exe
+ 2009-12-29 05:04 . 2009-12-29 05:04 20480 c:\windows\Installer\{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}\MnyIco.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-24 14:52 . 2009-12-24 14:52 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ARPPRODUCTICON.exe
+ 2009-12-29 05:02 . 2009-12-29 05:02 28672 c:\windows\Installer\{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}\cagicon.76D90421_D2BE_11D2_99FF_0060B0EC3D2E.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut6_1B72F66FEC97454396CC50F63093FE70_1.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut6_1B72F66FEC97454396CC50F63093FE70_1.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut30_7AE715922BD74E0E938522AC3FDACFB1.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut30_7AE715922BD74E0E938522AC3FDACFB1.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut2.CB4E6205_F99A_4C51_ADD4_184506EFAB87.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 45056 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut2.CB4E6205_F99A_4C51_ADD4_184506EFAB87.exe
- 2009-08-01 22:16 . 2009-12-10 14:57 34304 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-08-01 22:16 . 2009-12-26 17:04 34304 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2001-07-25 18:00 . 2001-07-25 18:00 77878 c:\windows\Installer\$PatchCache$\Managed\7F3915FC73B65D117B2D00AA002A401F\10.0.80\msvcirt.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 73784 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5968_msworks.exe
+ 2001-08-08 06:07 . 2001-08-08 06:07 73785 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5832_wkwpquil.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 61494 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5761_WksWP.exe
+ 2001-08-08 06:06 . 2001-08-08 06:06 28672 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5643_wkgdips.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 57401 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5642_wkgdcach.exe
+ 2001-08-08 06:06 . 2001-08-08 06:06 53323 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5260_wksabimp.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 20549 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5258_wksab.exe
+ 2001-08-08 06:07 . 2001-08-08 06:07 22288 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F4586_comcat.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 61523 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F19689_WkImgSrv.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 69692 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F16822_wkssfrm.dll
+ 2001-08-07 22:59 . 2001-08-07 22:59 5632 c:\windows\System32\mfcuia32.dll
- 2009-12-18 02:17 . 2009-12-18 02:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-29 01:20 . 2009-12-29 01:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-29 01:20 . 2009-12-29 01:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-12-18 02:17 . 2009-12-18 02:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-10-24 18:55 . 2008-10-24 18:55 7168 c:\windows\Help\OEM\scripts\HPHS_Launcher.exe
+ 2008-12-03 17:24 . 2008-12-03 17:24 7168 c:\windows\Help\OEM\scripts\HPHS_Launcher.exe
+ 2009-07-06 18:17 . 2009-12-28 05:59 277174 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-12-26 17:03 . 2009-06-22 17:14 414437 c:\windows\System32\spool\drivers\w32x86\acpdfui400.dll
+ 2009-12-26 17:03 . 2009-06-22 17:14 728227 c:\windows\System32\spool\drivers\w32x86\acpdf400.dll
+ 2009-12-26 17:03 . 2009-06-22 17:14 414437 c:\windows\System32\spool\drivers\w32x86\3\acpdfui400.dll
+ 2009-12-26 17:03 . 2009-06-22 17:14 728227 c:\windows\System32\spool\drivers\w32x86\3\acpdf400.dll
+ 2006-11-02 10:33 . 2009-12-29 01:25 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-18 02:24 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-18 02:24 101350 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-29 01:25 101350 c:\windows\System32\perfc009.dat
+ 2000-02-18 19:45 . 2000-02-18 19:45 565760 c:\windows\System32\msvcp50.dll
+ 2001-08-07 22:59 . 2001-08-07 22:59 133904 c:\windows\System32\mfcans32.dll
+ 2009-10-28 03:40 . 2009-10-28 03:40 257440 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2000-05-10 11:34 . 2000-05-10 11:34 716288 c:\windows\System32\Ltwvc11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 392192 c:\windows\System32\ltkrn11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 127488 c:\windows\System32\ltimg11n.dll
+ 2000-05-09 18:41 . 2000-05-09 18:41 118784 c:\windows\System32\ltfil11n.DLL
+ 2000-05-10 11:34 . 2000-05-10 11:34 262656 c:\windows\System32\LTDIS11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 152064 c:\windows\System32\lftif11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 172032 c:\windows\System32\Lfpng11n.dll
+ 2000-05-10 11:34 . 2000-05-10 11:34 285184 c:\windows\System32\LFCMP11n.DLL
+ 2009-06-29 14:50 . 2009-12-26 15:55 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-06-29 14:50 . 2009-12-18 02:16 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-29 10:22 . 2009-12-29 05:06 491520 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-29 04:10 . 2009-12-29 01:18 121168 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-12-29 05:04 . 2009-12-29 05:04 387584 c:\windows\Installer\b3c27f.msi
+ 2009-12-29 05:03 . 2009-12-29 05:03 942080 c:\windows\Installer\b3c279.msi
+ 2009-12-29 04:57 . 2009-12-29 04:57 877568 c:\windows\Installer\b3c189.msi
+ 2009-12-29 05:02 . 2009-12-29 05:02 188416 c:\windows\Installer\{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}\_41BECA2.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut91_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut91_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut9_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut9_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut81_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut81_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut8_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut8_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut71_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut71_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut7_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut7_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut51_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut51_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut5_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut5_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut41_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut41_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut4_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut4_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut31_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut31_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut3_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut3_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut28_6C2287199EDD4CAA8285D3095F51E522.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut28_6C2287199EDD4CAA8285D3095F51E522.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut27_6C2287199EDD4CAA8285D3095F51E522.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut27_6C2287199EDD4CAA8285D3095F51E522.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut26_6C2287199EDD4CAA8285D3095F51E522.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut26_6C2287199EDD4CAA8285D3095F51E522.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut25_6C2287199EDD4CAA8285D3095F51E522.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut25_6C2287199EDD4CAA8285D3095F51E522.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut241_7AE715922BD74E0E938522AC3FDACFB1.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut241_7AE715922BD74E0E938522AC3FDACFB1.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut24_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut24_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut21_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut21_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut201_7AE715922BD74E0E938522AC3FDACFB1.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut201_7AE715922BD74E0E938522AC3FDACFB1.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut20_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut20_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut2_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut2_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut181_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut181_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut18_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut18_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut171_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut171_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut17_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut17_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut161_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut161_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut16_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut16_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut151_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut151_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut15_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut15_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut131_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut131_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut13_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut13_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut121_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut121_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut12_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut12_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut111_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut111_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut11_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut11_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut101_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut101_1B72F66FEC97454396CC50F63093FE70.exe
- 2009-07-02 03:26 . 2009-08-11 03:55 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut10_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-07-02 03:26 . 2009-12-26 17:03 335872 c:\windows\Installer\{9A2F0810-369F-4E86-9072-973FBE1679C5}\NewShortcut10_1B72F66FEC97454396CC50F63093FE70.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-04-22 14:59 . 2009-12-29 02:05 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-04-22 14:34 . 2009-07-06 14:45 327680 c:\windows\Installer\{0054A0F6-00C9-4498-B821-B5C9578F433E}\NewShortcut1_25FA95A8A87846FD8452981B34D3557D.exe
+ 2009-04-22 14:34 . 2009-12-26 16:29 327680 c:\windows\Installer\{0054A0F6-00C9-4498-B821-B5C9578F433E}\NewShortcut1_25FA95A8A87846FD8452981B34D3557D.exe
+ 2009-04-22 14:34 . 2009-12-26 16:29 217088 c:\windows\Installer\{0054A0F6-00C9-4498-B821-B5C9578F433E}\ARPPRODUCTICON.exe
- 2009-04-22 14:34 . 2009-07-06 14:45 217088 c:\windows\Installer\{0054A0F6-00C9-4498-B821-B5C9578F433E}\ARPPRODUCTICON.exe
+ 2001-07-25 18:00 . 2001-07-25 18:00 278581 c:\windows\Installer\$PatchCache$\Managed\7F3915FC73B65D117B2D00AA002A401F\10.0.80\msvcrt.dll
+ 2001-07-25 18:00 . 2001-07-25 18:00 995383 c:\windows\Installer\$PatchCache$\Managed\7F3915FC73B65D117B2D00AA002A401F\10.0.80\mfc42.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 852023 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5864_wkwpqd.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 122950 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5825_wkwpqrtf.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 155920 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5438_msls31.dll
+ 2001-08-08 06:07 . 2001-08-08 06:07 200768 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F19372_WkThemes.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 159744 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F19108_wkssole.dll
+ 2001-08-24 04:54 . 2001-08-24 04:54 127059 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F17323_wkshbsvc.dll
+ 2001-08-08 06:06 . 2001-08-08 06:06 180279 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F15485_wksbdp.dll
+ 2008-11-18 22:01 . 2008-11-18 22:01 623880 c:\windows\Installer\$PatchCache$\Managed\0180F2A9F96368E4092779F3EB61975C\19.0.4005\intuitsyncmanager.exe
+ 2008-07-27 19:16 . 2008-07-27 19:16 206128 c:\windows\Installer\$PatchCache$\Managed\0180F2A9F96368E4092779F3EB61975C\19.0.4005\dbmlsynccom.dll
+ 2009-12-26 17:03 . 2009-06-22 17:14 4194304 c:\windows\System32\spool\drivers\w32x86\cdintf400.dll
+ 2009-10-28 03:40 . 2009-10-28 03:40 3885984 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-12-29 05:06 . 2009-12-29 05:06 1389568 c:\windows\Installer\b3c285.msi
+ 2009-12-29 05:02 . 2009-12-29 05:02 3062272 c:\windows\Installer\b3c273.msi
+ 2009-12-26 16:29 . 2009-12-26 16:29 1170944 c:\windows\Installer\8c51c.msi
+ 2009-12-24 14:52 . 2009-12-24 14:52 1262080 c:\windows\Installer\29d14e.msi
+ 2009-04-22 14:59 . 2009-12-29 02:05 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-04-22 14:59 . 2009-12-10 14:56 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2001-08-08 06:07 . 2001-08-08 06:07 1114167 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F5762_wkwpac.dll
+ 2001-08-24 04:54 . 2001-08-24 04:54 1896502 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F19099_wksss.exe
+ 2001-08-24 04:49 . 2001-08-24 04:49 2166838 c:\windows\Installer\$PatchCache$\Managed\3B9B7B1A2D1EAC14B9A41FD82C177040\6.0.0\F16975_wksdb.exe
+ 2009-12-19 04:26 . 2009-12-19 04:26 37264896 c:\windows\Installer\1fc6e.msp
+ 2009-12-19 04:26 . 2009-12-19 04:26 21841920 c:\windows\Installer\1fc6d.msp
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-01-28 2387968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-09-30 972080]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [2001-07-25 184376]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-10 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-10 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-10 145944]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-11-15 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-10-28 1085704]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2009-03-11 468264]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-11 2033432]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2007-06-21 1099104]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-12-10 984352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ac,a8,59,9e,3f,18,ca,01

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [6/28/2009 7:50 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [6/28/2009 7:50 PM 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/7/2009 9:06 AM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/7/2009 9:06 AM 285392]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [4/22/2009 6:01 AM 115560]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [4/22/2009 7:17 AM 365952]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [4/22/2009 6:14 AM 193840]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [6/29/2008 6:52 AM 112128]
S2 gupdate1ca17d77c1ff8b0;Google Update Service (gupdate1ca17d77c1ff8b0);c:\program files\Google\Update\GoogleUpdate.exe [8/7/2009 7:22 PM 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 6:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [7/4/2009 8:00 AM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-01-28 05:28 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=91&bd;=Pavilion&pf;=cnnb
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\THOMAS\AppData\Roaming\Mozilla\Firefox\Profiles\sdzeh1nz.default\
FF - prefs.js: browser.startup.homepage - WWW.YAHOO.COM
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-28 21:53
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-12-28 21:55:04
ComboFix-quarantined-files.txt 2009-12-29 05:55
ComboFix2.txt 2009-12-23 14:44
ComboFix3.txt 2009-12-18 02:39
ComboFix4.txt 2009-12-10 15:19

Pre-Run: 260,813,123,584 bytes free
Post-Run: 260,813,651,968 bytes free

- - End Of File - - 1104E5F15C47DADE672AB7BA61D1F213
None of the blocked startup programs are bad - you can reenable them. Last thing to do! Open MBAM, update it, run a full system scan and post the log.
Hi Raktor… Here is the Malwarebytes Log… Malwarebytes' Anti-Malware 1.43 Database version: 3461 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18865 12/30/2009 9:28:08 PM mbam-log-2009-12-30 (21-28-08).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 282114 Time elapsed: 55 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
We've made it!!

The following will implement some cleanup procedures as well as reset System Restore points:

  • Please press the Windows Key and R on your keyboard. This will bring up the Run… command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    🖼Click to load external image (Posted Image)
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.

Open OTL.exe and click the Cleanup button, and remove any other leftover tools.

How to reduce your chances of infection in the future

Web Browsers
Internet Explorer does come pre-installed with all Windows machines - but this doesn't necessarily mean you have to use it! Because it is the most widely used browser, it is targeted by more malware writers, making you more susceptible to infection. There are many other free alternatives out there that offer better security, take one of these for a spin and see if it takes your fancy.
Mozilla Firefox
Google Chrome
Opera

WOT - Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for Firefox, Google Chrome and Internet Explorer.

If you would prefer to keep using Internet Explorer, follow these additional steps to make the browser more secure.
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Additional Security Measures
Keep your software up-to-date - You should be manually performing updates of your software once a week to ensure that you are current with anti-virus definitions and patched for any security vulnerabilities. This does not just apply to your anti-virus/anti-malware software; malware authors rely on exploiting commonly used software such as Java and Adobe Reader, which need to be kept up to date as well.

Keep Windows up-to-date - Use Windows Update regularly to stay current with security patches and service packs.

MVPS Hosts File - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.

Firewalls - Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient - but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.

What Not To Do
The Perils of P2P File Sharing - Even if a P2P application is on the 'safe' list, malware can still be downloaded through infected files - executables, zip files and even MP3s. It is just not worth the risk.

Fake Security/Optimization Software - Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Additional Reading
How to prevent Malware - I strongly recommend that you read Miekiemoses' good advice

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hi Raktor…. Did all the cleanup you suggested and just have 2 quick questions about files produced from our work. I have a file "settings.dat" on my desktop in a txt file and a icon "NTREGOPT" also. Are these items that i need to keep? Otherwise the computer is running well and i appreciate all your help. Thank you again. Tom
Thank you Raktor for your help again…. Happy New Year to you and all the people here at WhattheTech and know that their help is very much appreciated.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI