This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Luddite returns with slew of issues

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Oh man….. :blush: Ok..so Problems I am having include: 1. slow startup 2. Get constant notification that "Windows has blocked some startup programs" 3. When I go to shut down, I am told that windows needs to update some programs, but it never does…I get the same story the next day. When I go to check on what those updates are and try again, I get an "error" 4. Closing down some windows can take up to 30 seconds….and the browser never seems to close down properly so much as it "crashes very slowly"….I am using Google Chrome 5. Motor is revving…this is something I have never experienced before….when I happens, I find I can stop it, by closing all widows and the browser for a minute. While the revving happens randomly ..it does seem to occur more frequently when I'm watching a video…from youtube for example. 6. I've got Microsoft Security Essentials, which was suggested the last time I was here….short and long scans reveal nothing. So what's the point of security essentials if it gives you a clean bill when obbviously there are problems? I'm not sayin' anything, I'm just sayin". :angry: 7. Getting the odd pop up….from "netflix"…a service I don't use. 8. I've got a wicked toothache and have to go to the dentist tomorrow. So those are my issues. Please remember that I am a Luddite….a real cyberidiot, who really should not be left alone with this machine and no adult supervision. I need descriptive instuctions….speak to me really slow, and I beg your patience. I ran one of the Tool thingys as suggested….um…I was not given the option to "run as administrator" and when it told me to disable script things…I don't know what a script is, or how or where to go to disable it…..so, if there is a problem with what I post below, that is probably it… Ok..so here are the DDS things. I see that it says "don't post this log unless requested…but quite frankly I am afraid of losing it, because I don't where to put it to find it again, if I need to. Sorry. :blush: Ya'll may take a swig of whiskey now….. I'm grateful for any assistance. _____________________________________________________________________ UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 14/12/2007 12:26:17 PM System Uptime: 07/07/2011 1:07:32 PM (8 hours ago) . Motherboard: Acer | | F672CR Processor: Intel® Pentium® D CPU 3.00GHz | Socket 775 | 2400/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 72 GiB total, 28.351 GiB free. D: is FIXED (NTFS) - 72 GiB total, 70.737 GiB free. E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1226: 05/07/2011 9:07:26 AM - Windows Update RP1227: 05/07/2011 7:59:32 PM - Windows Update RP1228: 06/07/2011 12:06:43 AM - Device Driver Package Install: Apple, Inc. Universal Serial Bus controllers RP1229: 06/07/2011 12:08:16 AM - Device Driver Package Install: Apple Network adapters RP1230: 06/07/2011 12:24:40 AM - Windows Update RP1231: 06/07/2011 3:00:16 AM - Windows Update RP1232: 07/07/2011 3:00:16 AM - Windows Update RP1233: 07/07/2011 11:46:46 AM - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Acer Arcade Live Main Page Acer Assist Acer DV Magician Acer DVDivine Acer eDataSecurity Management Acer Empowering Technology Acer ePerformance Management Acer HomeMedia Acer HomeMedia Connect Acer Registration Acer ScreenSaver Acer SlideShow DVD Acer Tour Acer VideoMagician Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.3.0 APC PowerChute Personal Edition Apple Application Support Apple Mobile Device Support Apple Software Update AVG 2011 Bonjour CCleaner (remove only) DivX Setup Google Chrome Google Desktop Google Earth Google Gmail Notifier Google Photos Screensaver Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Google Updater Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) iPhone Configuration Utility iTunes Java Auto Updater Java™ 6 Update 26 LightScribe 1.4.142.1 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Antimalware Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Security Client Microsoft Security Essentials Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works MobileMe Control Panel Mozilla Firefox (3.0.8) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Picasa 2 QuickTime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 Revo Uninstaller 1.90 Safari SAMSUNG Dr. Printer Samsung SCX-4x21 Series Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) SiS VGA Utilities Skype Toolbars Skype™ 5.3 SmarThru 4 SmarThru PC Fax Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VC80CRTRedist - 8.0.50727.4053 Windows Media Player Firefox Plugin . ==== Event Viewer Messages From Past Week ======== . 07/07/2011 3:05:35 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008 x86 (KB2478663). 07/07/2011 3:02:04 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008 x86 (KB2446708). 07/07/2011 11:37:41 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.3.190:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.159.110:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.143.213:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.143.213:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.134.160:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.130.140:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.93.59:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.89.123:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.88.19:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.88.128:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.8.97:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.4.39:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.28.74:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.28.127:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.24.93:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.21.157:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.20.181:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.20.106:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.2.207:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.2.156:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.18.123:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.16.213:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.16.197:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.12.109:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 24.138.60.150:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.98.3:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.100.11:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.100.11:6331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 169.254.192.218:63331. The error status code is contained within the returned data. 07/07/2011 11:35:29 AM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 169.254.192.218:6331. The error status code is contained within the returned data. 06/07/2011 12:18:31 AM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer SmarThru PC Fax with shared resource name SmarThru PC Fax. Error 2114. The printer cannot be used by others on the network. 06/07/2011 12:08:47 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 06/07/2011 12:06:27 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 06/07/2011 10:55:59 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 05/07/2011 9:04:15 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 04/07/2011 9:40:14 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 03/07/2011 11:01:10 AM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer Send To OneNote 2007 with shared resource name Send To OneNote 2007. Error 2114. The printer cannot be used by others on the network. 03/07/2011 11:01:10 AM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer Samsung SCX-4x21 Series with shared resource name Samsung SCX-4x21 Series. Error 2114. The printer cannot be used by others on the network. 02/07/2011 9:55:41 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 01/07/2011 7:09:39 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. . ==== End Of File =========================== DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 21:22:07.55 on 07/07/2011 Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_26 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.895.204 [GMT -3:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Acer\Empowering Technology\SysMonitor.exe C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\RtHDVCpl.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe C:\Acer\Empowering Technology\ePerformance\MemCheck.exe C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\ehome\ehmsas.exe C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wuauclt.exe c:\program files\real\realplayer\update\realsched.exe C:\Windows\system32\WUDFHost.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Owner\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7 mStart Page = hxxp://en.ca.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uURLSearchHooks: H - No File mURLSearchHooks: H - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [Acer Empowering Technology Monitor] c:\acer\empowering technology\SysMonitor.exe mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe mRun: [Acer Product Registration] "c:\program files\acer registration\ACE1.exe" /startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [WHITNEY_S2P] c:\program files\samsung\samsung scx-4x21 series\psu\Scan2pc.exe mRun: [PCMMediaSharing] c:\program files\acer arcade live\acer homemedia connect\kernel\dms\PCMMediaSharing.exe mRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe mRun: [Acer Assist Launcher] c:\program files\acer assist\launcher.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\acerpr~1.lnk - c:\program files\acer registration\ACE1.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Yahtzee/Images/stg_drm.ocx DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\progra~1\google\google~4\GoogleDesktopNetwork3.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl;=0&ptb;=3MvANHFNQxb.yvOnb3UHZg&url;=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st;=kwd&searchfor;= FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\picasa2\npPicasa2.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\owner\appdata\local\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\mozilla\firefox extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264] R1 MpKsl37bb6114;MpKsl37bb6114;c:\programdata\microsoft\microsoft antimalware\definition updates\{9bd16c22-05b8-4345-9606-743a83b5933e}\MpKsl37bb6114.sys [2011-7-7 28752] R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\acer arcade live\acer homemedia connect\kernel\dms\CLMSServer.exe [2007-9-14 269448] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-5 21504] R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.SYS [2007-12-26 5120] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360] R3 SiS6350;SiS6350;c:\windows\system32\drivers\SISGRKMD.sys [2007-9-13 454520] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2007-9-13 46592] S2 gupdate1c9c6d11bff959c;Google Update Service (gupdate1c9c6d11bff959c);c:\program files\google\update\GoogleUpdate.exe [2009-4-26 133104] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-3-25 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-4-26 133104] . =============== Created Last 30 ================ . 2011-07-07 14:52:50 28752 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{9bd16c22-05b8-4345-9606-743a83b5933e}\MpKsl37bb6114.sys 2011-07-07 14:49:19 7074640 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{9bd16c22-05b8-4345-9606-743a83b5933e}\mpengine.dll 2011-07-06 03:13:26 ——– d—–w- c:\program files\iPod 2011-07-06 03:13:21 ——– d—–w- c:\program files\iTunes 2011-06-29 12:06:09 276992 —-a-w- c:\windows\system32\schannel.dll 2011-06-17 13:28:58 758784 —-a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll 2011-06-17 13:28:49 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat . ==================== Find3M ==================== . 2011-05-28 06:08:58 916480 —-a-w- c:\windows\system32\wininet.dll 2011-05-28 06:04:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-05-28 06:04:17 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-05-28 06:04:03 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-05-28 06:04:03 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-05-28 05:10:26 385024 —-a-w- c:\windows\system32\html.iec 2011-05-28 04:33:03 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-05-28 04:31:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-05-04 07:52:22 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-05-02 17:16:14 739328 —-a-w- c:\windows\system32\inetcomm.dll . ============= FINISH: 21:24:09.76 ===============
Welcome back Baruga2,

I trust everything got resolved ok with the dentist?

If not… I can't help so… let's move on to your computer.

The revving you are hearing is your cooling fan… trying to keep your machine cool. The reason it slows down when you shut everything off for awhile is because… when it isn't working so hard - it doesn't need as much cooling. There's a good chance that you need to clean the dust bunnies our of it so it can cool better. This can be done by getting a can of compressed air, taking the side off the box, and using the canned air to blow all of the dust out. Care must be taken not to knock connections loose, ruin something with static electricity, or shock yourself. Some reccomendations on how to go about this process can be found here: http://www.d-a-l.com/help/general-hardware…eaning-esd.html. This "guide" is written by one of our most respected Tech Team members. If it is all too confusing, once we are done with malware, you could return to your earlier thread in the windows forum once we are done here, and I'm sure a member of the Tech Team can provide more guidance.

Not, I'm just seeing a little adware in your log, but I suspect there is more going on.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Well. Myself, my dentist, and all of my teeth convened a meeting on Friday to discuss what to do about this one rebel Molar. Rebel Molar is not happy being with other Teeth anymore, and insists that there is a whole world out there for an independent Rebel Tooth like hisself. Seems he's got a superiority complex, too good for to be with lesser "conformist chompers". The other Teeth have had quite enough abuse from Rebel Molar, and I too am tired of all the infighting. So we came to the conclusion that we would all feel a lot better if we let Rebel Molar strike out on his own. We're going to have a going away party for Rebel Molar at the Dentist office tomorrow. Then the rest of us can get back to our lives, happily munching popcorn and bustin' chops with friends and family, without having to deal with that Toothacher anymore.

Now on to the computer issues.

I forgot to add to my list of comp troubles, that SKYPE worked for about a week after I was here last time…but then began to drop calls immediately after they were connected. Gmail voicechat and 'callphone have continued to work well, though.

I did the combofix thingy. NOTE: once again, I was not offered the option to "run as administrator" at any time. But it seems to have run as administrator anyway. Um…maybe everything has been "run as administrator" since the last time I was here a few months back? Is that possible, and if so, is that an issue?

Here is the combofix log thingy:


omboFix 11-07-11.02 - Owner 11/07/2011 14:09:44.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.895.288 [GMT -3:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-11 to 2011-07-11 )))))))))))))))))))))))))))))))
.
.
2011-07-11 17:19 . 2011-07-11 17:19 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-07-11 17:19 . 2011-07-11 17:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-11 13:10 . 2011-07-11 13:10 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\MpKsl04b1e2c5.sys
2011-07-10 14:24 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\mpengine.dll
2011-07-06 03:15 . 2011-07-06 03:15 ——– d—–w- c:\program files\Apple Software Update
2011-07-06 03:13 . 2011-07-06 03:13 ——– d—–w- c:\program files\iPod
2011-07-06 03:13 . 2011-07-06 03:14 ——– d—–w- c:\program files\iTunes
2011-06-29 12:06 . 2011-04-29 15:59 276992 —-a-w- c:\windows\system32\schannel.dll
2011-06-21 12:03 . 2011-06-21 12:03 ——– d—–w- c:\program files\Common Files\Java
2011-06-17 13:28 . 2011-04-30 06:09 758784 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-06-17 13:28 . 2011-05-02 12:02 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-16 23:53 . 2011-06-16 23:53 ——– d—–w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-07 15:55 . 2011-03-22 01:06 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-04 07:52 . 2010-05-05 18:41 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-18 18:42 . 2008-08-12 04:37 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-26 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-04-18 15146376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-05-31 326440]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2007-02-02 3383296]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"WHITNEY_S2P"="c:\program files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe" [2007-01-08 274432]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2007-02-02 1261568]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-18 30192]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"TkBellExe"="c:\program files\Real\realplayer\update\realsched.exe" [2010-11-26 274608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-20 4493312]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
.
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Acer Product Registration.lnk - c:\program files\Acer Registration\ACE1.exe [2007-2-2 3383296]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2008-1-12 221247]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-9-14 535336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl0b0f202e;MpKsl0b0f202e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FE9E7E98-D076-4C0D-AAE6-CC9B1C36AF9C}\MpKsl0b0f202e.sys [x]
R1 MpKsl2b491d10;MpKsl2b491d10;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5A68E96-DB1E-4C92-B9C1-2FD374A7EE8B}\MpKsl2b491d10.sys [x]
R1 MpKsl4aa86cdc;MpKsl4aa86cdc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F1AF91CC-D5D0-4C47-8723-6DC6521FE971}\MpKsl4aa86cdc.sys [x]
R1 MpKsl561f14c6;MpKsl561f14c6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6DCDAAE8-1B49-4F96-BCC5-CFFAAFD914FA}\MpKsl561f14c6.sys [x]
R1 MpKsl66679eb0;MpKsl66679eb0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{61925367-0F5F-4F4D-9A09-F71852440D2F}\MpKsl66679eb0.sys [x]
R1 MpKsla42c726e;MpKsla42c726e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28A9EFDC-7F31-4673-98C4-790E01AB367C}\MpKsla42c726e.sys [x]
R1 MpKslbcf7ada5;MpKslbcf7ada5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C506A0AB-01DD-42FD-9CC4-FDE49052FAFE}\MpKslbcf7ada5.sys [x]
R1 MpKslc1560120;MpKslc1560120;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BDB536F9-AA53-4E85-934A-9A31E433D262}\MpKslc1560120.sys [x]
R1 MpKsld22b642d;MpKsld22b642d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8309DD46-7973-4E25-BEF9-A7A57703F3FE}\MpKsld22b642d.sys [x]
R1 MpKsle83df001;MpKsle83df001;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ACCF658-BA33-4DEE-B4AE-68B8A061BCC8}\MpKsle83df001.sys [x]
R1 MpKsled8c8d50;MpKsled8c8d50;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1BD0056A-7D15-4AAD-B477-31D8FC6C4F19}\MpKsled8c8d50.sys [x]
R2 gupdate1c9c6d11bff959c;Google Update Service (gupdate1c9c6d11bff959c);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 133104]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-18 30192]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 133104]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S1 MpKsl04b1e2c5;MpKsl04b1e2c5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\MpKsl04b1e2c5.sys [2011-07-11 28752]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-01-08 5120]
S3 SiS6350;SiS6350;c:\windows\system32\DRIVERS\SISGRKMD.sys [2007-06-05 454520]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSGB6.sys [2007-01-22 46592]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL04B1E2C5
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 00:42]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 00:42]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4230733952-2736013862-825621023-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-19 00:45]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4230733952-2736013862-825621023-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-19 00:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\r1yjv0iq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=3MvANHFNQxb.yvOnb3UHZg&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-11 14:19
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(1412)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Completion time: 2011-07-11 14:24:44
ComboFix-quarantined-files.txt 2011-07-11 17:24
.
Pre-Run: 31,861,673,984 bytes free
Post-Run: 32,342,548,480 bytes free
.
- - End Of File - - D9E1C365AC5A7C9E53B92D4784D7F58E
Well. Myself, my dentist, and all of my teeth convened a meeting on Friday to discuss what to do about this one rebel Molar. Rebel Molar is not happy being with other Teeth anymore, and insists that there is a whole world out there for an independent Rebel Tooth like hisself. Seems he's got a superiority complex, too good for to be with lesser "conformist chompers". The other Teeth have had quite enough abuse from Rebel Molar, and I too am tired of all the infighting. So we came to the conclusion that we would all feel a lot better if we let Rebel Molar strike out on his own. We're going to have a going away party for Rebel Molar at the Dentist office tomorrow. Then the rest of us can get back to our lives, happily munching popcorn and bustin' chops with friends and family, without having to deal with that Toothacher anymore.

Now on to the computer issues.

I forgot to add to my list of comp troubles, that SKYPE worked for about a week after I was here last time…but then began to drop calls immediately after they were connected. Gmail voicechat and 'callphone have continued to work well, though.

I did the combofix thingy. NOTE: once again, I was not offered the option to "run as administrator" at any time. But it seems to have run as administrator anyway. Um…maybe everything has been "run as administrator" since the last time I was here a few months back? Is that possible, and if so, is that an issue?

Here is the combofix log thingy:


omboFix 11-07-11.02 - Owner 11/07/2011 14:09:44.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.895.288 [GMT -3:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-11 to 2011-07-11 )))))))))))))))))))))))))))))))
.
.
2011-07-11 17:19 . 2011-07-11 17:19 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-07-11 17:19 . 2011-07-11 17:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-11 13:10 . 2011-07-11 13:10 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\MpKsl04b1e2c5.sys
2011-07-10 14:24 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\mpengine.dll
2011-07-06 03:15 . 2011-07-06 03:15 ——– d—–w- c:\program files\Apple Software Update
2011-07-06 03:13 . 2011-07-06 03:13 ——– d—–w- c:\program files\iPod
2011-07-06 03:13 . 2011-07-06 03:14 ——– d—–w- c:\program files\iTunes
2011-06-29 12:06 . 2011-04-29 15:59 276992 —-a-w- c:\windows\system32\schannel.dll
2011-06-21 12:03 . 2011-06-21 12:03 ——– d—–w- c:\program files\Common Files\Java
2011-06-17 13:28 . 2011-04-30 06:09 758784 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-06-17 13:28 . 2011-05-02 12:02 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-16 23:53 . 2011-06-16 23:53 ——– d—–w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-07 15:55 . 2011-03-22 01:06 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-04 07:52 . 2010-05-05 18:41 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-18 18:42 . 2008-08-12 04:37 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-26 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-04-18 15146376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-05-31 326440]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2007-02-02 3383296]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"WHITNEY_S2P"="c:\program files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe" [2007-01-08 274432]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2007-02-02 1261568]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-18 30192]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"TkBellExe"="c:\program files\Real\realplayer\update\realsched.exe" [2010-11-26 274608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-20 4493312]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
.
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Acer Product Registration.lnk - c:\program files\Acer Registration\ACE1.exe [2007-2-2 3383296]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2008-1-12 221247]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-9-14 535336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl0b0f202e;MpKsl0b0f202e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FE9E7E98-D076-4C0D-AAE6-CC9B1C36AF9C}\MpKsl0b0f202e.sys [x]
R1 MpKsl2b491d10;MpKsl2b491d10;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5A68E96-DB1E-4C92-B9C1-2FD374A7EE8B}\MpKsl2b491d10.sys [x]
R1 MpKsl4aa86cdc;MpKsl4aa86cdc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F1AF91CC-D5D0-4C47-8723-6DC6521FE971}\MpKsl4aa86cdc.sys [x]
R1 MpKsl561f14c6;MpKsl561f14c6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6DCDAAE8-1B49-4F96-BCC5-CFFAAFD914FA}\MpKsl561f14c6.sys [x]
R1 MpKsl66679eb0;MpKsl66679eb0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{61925367-0F5F-4F4D-9A09-F71852440D2F}\MpKsl66679eb0.sys [x]
R1 MpKsla42c726e;MpKsla42c726e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28A9EFDC-7F31-4673-98C4-790E01AB367C}\MpKsla42c726e.sys [x]
R1 MpKslbcf7ada5;MpKslbcf7ada5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C506A0AB-01DD-42FD-9CC4-FDE49052FAFE}\MpKslbcf7ada5.sys [x]
R1 MpKslc1560120;MpKslc1560120;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BDB536F9-AA53-4E85-934A-9A31E433D262}\MpKslc1560120.sys [x]
R1 MpKsld22b642d;MpKsld22b642d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8309DD46-7973-4E25-BEF9-A7A57703F3FE}\MpKsld22b642d.sys [x]
R1 MpKsle83df001;MpKsle83df001;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ACCF658-BA33-4DEE-B4AE-68B8A061BCC8}\MpKsle83df001.sys [x]
R1 MpKsled8c8d50;MpKsled8c8d50;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1BD0056A-7D15-4AAD-B477-31D8FC6C4F19}\MpKsled8c8d50.sys [x]
R2 gupdate1c9c6d11bff959c;Google Update Service (gupdate1c9c6d11bff959c);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 133104]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-18 30192]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 133104]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S1 MpKsl04b1e2c5;MpKsl04b1e2c5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07F043B4-6D0F-4E1C-ACC4-E599F9717003}\MpKsl04b1e2c5.sys [2011-07-11 28752]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-01-08 5120]
S3 SiS6350;SiS6350;c:\windows\system32\DRIVERS\SISGRKMD.sys [2007-06-05 454520]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSGB6.sys [2007-01-22 46592]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL04B1E2C5
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 00:42]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 00:42]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4230733952-2736013862-825621023-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-19 00:45]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4230733952-2736013862-825621023-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-19 00:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\r1yjv0iq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=3MvANHFNQxb.yvOnb3UHZg&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-11 14:19
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(1412)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Completion time: 2011-07-11 14:24:44
ComboFix-quarantined-files.txt 2011-07-11 17:24
.
Pre-Run: 31,861,673,984 bytes free
Post-Run: 32,342,548,480 bytes free
.
- - End Of File - - D9E1C365AC5A7C9E53B92D4784D7F58E
Baruga2,

It appears that you have UAC turned off, so you don't have to run as administrator. This is "less hassle", but not as "safe".

But, I'm still not seeing any sign of malware. Your best bet is to return to your earlier thread in the Windows Forum and let the Tech Team put you through their paces.

But first, let's clean up behind ourselves.

  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Good riddance to that tooth that has been giving you a "smart" mouth, and good luck with the Tech Team.

If you have any questions, let me know. Otherwise I'll close this thread.
Certainly things were much easier..and there seemed to be less hoops to jump through this time… But what is "UAC"? Um….if it's ok, I'd like to deal with the cleanup tomorrow night or Wednesday….I am not thinking clearly as I'm on some heavy painkillers….on account of Rebel Molar… Meanwhile, I have turned my security back on…. It things can't sit like this (combofix cleanup and ininstall not done, security turned back on) for 48 hrs let me know, and I will slog though it..
Life is better with Rebel Molar!!! :woot: But now, I am having trouble getting rid of Rebel Combofix…. When I click "start" there is nowhere that the word "run" appears. So I tried typing "combofix/uninstall in the search box, and that just ended up running the whole combofix process again. So, I went into the control center place, and clicked on "uninstall a program"…but could not locate combofix, to uninstall it….. Any ideas????
There is no "run" box….there is a "search box" only..and when I type in combofix, it just reruns the program automatically….when I search for it to uninstall it, it does not show in the programs list.
Interesting. I've never seen a windows machine of any flavor that didn't bring up the run box when the Windows key is held and then the R key is pressed (while still holding the windows key).

Anyhow… let's do it this way then.

Pres Ctrl, Alt and Del keys all at the same time. This will bring up the task manager. At the top click on File and then select New Task (Run…). This will bring up the run box. In the box put : Combofix /Uninstall Combofix will run… but it won't do a scan. It will run through it's uninstall routine and then delete the icon from your desktop.
Holy bafoonary! My Bad Triple T! I was pressing the windows button on the screen on the bottom left corner…..not the windows key on my keyboard!!! Gufawwwww….. :smack: . :blush: I gotta stop thinking of my mouse as a detonator, and things on the screen as targets to blast out of the universe. :wacko: Geez…. Alrighty, Combofix is gone. I also turned the UAC thingy on again, and my security is all back on. Now, if you could throw me a rope (blue link to click on) to guide me to where I need to go, to get my Skype, updating and startup issues sorted out I would be much obliged. Fanks so much Treasure Tech Tom! :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI