This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TR/Crypt/ZPACK Gen virus on my PC [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi ,

System is running better.

No current warnings.

thanks


:thumbup:

OTL logfile created on: 19/05/2012 8:39:51 AM - Run 2
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Documents and Settings\Jeff\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 64.85% Memory free
3.84 Gb Paging File | 2.70 Gb Available in Paging File | 70.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 59.90 Gb Total Space | 12.87 Gb Free Space | 21.49% Space Free | Partition Type: NTFS
Drive D: | 411.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TAYLOR | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/04/29 11:38:15 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeff\Desktop\OTL.exe
PRC - [2011/11/12 12:04:12 | 000,268,640 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2011/11/12 11:21:58 | 006,141,792 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2011/08/19 17:26:50 | 000,450,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/12 12:19:40 | 000,680,984 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2011/08/12 12:18:42 | 000,205,336 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/08/12 12:18:30 | 000,265,240 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2011/07/06 07:26:51 | 000,269,480 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/04/28 07:32:56 | 000,136,360 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/01/13 10:01:28 | 006,129,496 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Vid HD\Vid.exe
PRC - [2010/08/02 16:09:55 | 000,281,768 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/02/12 16:34:26 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark 5000 Series\lxdmamon.exe
PRC - [2010/02/12 16:34:22 | 000,455,336 | —- | M] () – C:\Program Files\Lexmark 5000 Series\lxdmmon.exe
PRC - [2010/01/14 22:11:00 | 000,076,968 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/06/30 19:54:13 | 000,068,592 | —- | M] (Google Inc.) – C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2008/04/14 02:42:30 | 000,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Outlook Express\msimn.exe
PRC - [2008/04/14 02:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/06/07 21:05:52 | 000,598,960 | —- | M] ( ) – C:\WINDOWS\system32\lxdmcoms.exe
PRC - [2007/05/04 10:26:38 | 001,662,976 | —- | M] (D-Link) – C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
PRC - [2007/01/19 11:49:04 | 000,049,152 | —- | M] (Wireless Service) – C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/12 07:19:02 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012/05/11 23:27:32 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012/05/11 23:27:28 | 012,430,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\995fcf39ead2c2a53e084505c2c67d49\System.Windows.Forms.ni.dll
MOD - [2012/05/11 23:27:18 | 001,591,808 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\8ca00132a08c69697adf1cda32ebd835\System.Drawing.ni.dll
MOD - [2012/05/11 23:26:08 | 007,953,408 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/11 23:25:58 | 011,492,352 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2011/11/15 11:50:05 | 000,103,424 | —- | M] () – C:\Program Files\Google\Quick Search Box\bin\1.2.1151.245\rlz.dll
MOD - [2011/09/14 09:19:06 | 008,500,224 | —- | M] () – C:\Program Files\LeapFrog\LeapFrog Connect\QtGui4.dll
MOD - [2011/09/14 09:19:06 | 002,348,544 | —- | M] () – C:\Program Files\LeapFrog\LeapFrog Connect\QtCore4.dll
MOD - [2011/08/22 15:47:44 | 000,336,408 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2011/08/19 17:26:16 | 000,183,320 | —- | M] () – C:\Program Files\Common Files\LogiShrd\SharedBin\LvApi11.dll
MOD - [2011/08/12 12:19:40 | 000,680,984 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2011/08/12 12:18:30 | 000,265,240 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/10/30 04:02:38 | 000,751,616 | —- | M] () – C:\Program Files\Logitech\Vid HD\vpxmd.dll
MOD - [2010/10/30 04:01:30 | 000,027,472 | —- | M] () – C:\Program Files\Logitech\Vid HD\SDL.dll
MOD - [2010/06/17 15:27:22 | 000,355,688 | —- | M] () – C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2010/05/07 18:37:40 | 000,126,808 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010/05/07 18:37:40 | 000,027,480 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010/05/07 18:36:54 | 000,340,824 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010/05/07 18:35:56 | 007,954,776 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010/05/07 18:35:44 | 002,143,576 | —- | M] () – C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2010/02/12 16:34:26 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark 5000 Series\lxdmamon.exe
MOD - [2010/02/12 16:34:22 | 000,455,336 | —- | M] () – C:\Program Files\Lexmark 5000 Series\lxdmmon.exe
MOD - [2010/02/09 07:41:50 | 000,036,864 | —- | M] () – C:\Program Files\Lexmark 5000 Series\app4r.monitor.core.dll
MOD - [2010/02/09 07:41:50 | 000,028,672 | —- | M] () – C:\Program Files\Lexmark 5000 Series\app4r.monitor.common.dll
MOD - [2010/02/09 07:40:56 | 000,057,344 | —- | M] () – C:\Program Files\Lexmark 5000 Series\app4r.devmons.mcmdevmon.dll
MOD - [2009/04/23 05:53:56 | 000,969,040 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtNetwork4.dll
MOD - [2009/04/17 09:16:16 | 000,045,056 | —- | M] () – C:\WINDOWS\system32\LXDMPMON.DLL
MOD - [2009/04/17 09:15:08 | 000,032,768 | —- | M] () – C:\Program Files\Lexmark 5000 Series\ipcmt.dll
MOD - [2009/04/10 07:04:56 | 002,141,008 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtCore4.dll
MOD - [2009/03/04 06:18:08 | 000,138,064 | —- | M] () – C:\Program Files\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll
MOD - [2009/03/04 06:18:06 | 000,035,152 | —- | M] () – C:\Program Files\Logitech\Vid HD\plugins\imageformats\qico4.dll
MOD - [2009/03/04 06:18:06 | 000,029,008 | —- | M] () – C:\Program Files\Logitech\Vid HD\plugins\imageformats\qgif4.dll
MOD - [2009/03/04 06:17:46 | 011,311,952 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtWebKit4.dll
MOD - [2009/03/04 06:17:46 | 000,363,856 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtXml4.dll
MOD - [2009/03/04 06:17:44 | 000,200,016 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtSql4.dll
MOD - [2009/03/04 06:17:40 | 000,475,472 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtOpenGL4.dll
MOD - [2009/03/04 06:17:38 | 007,704,400 | —- | M] () – C:\Program Files\Logitech\Vid HD\QtGui4.dll
MOD - [2009/03/04 06:17:32 | 000,291,664 | —- | M] () – C:\Program Files\Logitech\Vid HD\phonon4.dll
MOD - [2009/01/30 05:30:02 | 000,190,464 | —- | M] () – C:\WINDOWS\system32\WgaLogon.dll
MOD - [2008/06/06 06:45:50 | 000,011,776 | —- | M] () – C:\Program Files\Lexmark 5000 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2008/04/14 02:42:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 02:41:52 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2007/05/22 18:59:38 | 000,692,224 | —- | M] () – C:\WINDOWS\system32\lxdmdrs.dll
MOD - [2007/05/22 18:57:24 | 000,278,528 | —- | M] () – C:\Program Files\Lexmark 5000 Series\lxdmscw.dll
MOD - [2007/05/22 10:10:12 | 000,065,536 | —- | M] () – C:\WINDOWS\system32\lxdmcaps.dll
MOD - [2007/05/03 11:39:32 | 000,589,824 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdmdatr.dll
MOD - [2007/05/02 23:38:36 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdmdrpp.dll
MOD - [2007/04/17 10:17:06 | 000,069,632 | —- | M] () – C:\WINDOWS\system32\lxdmcnv4.dll
MOD - [2007/04/09 09:59:30 | 000,069,632 | —- | M] () – C:\WINDOWS\system32\lxdmoem.dll
MOD - [2006/12/28 11:47:42 | 000,073,728 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdmcats.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\DOCUME~1\Jeff\LOCALS~1\Temp\DX9\SessionLauncher.exe – (SessionLauncher)
SRV - [2012/05/05 17:39:28 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/29 08:50:48 | 000,158,856 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2011/11/12 11:21:58 | 006,141,792 | —- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2011/08/19 17:26:50 | 000,450,848 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe – (UMVPFSrv)
SRV - [2011/07/06 07:26:51 | 000,269,480 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2011/04/28 07:32:56 | 000,136,360 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2009/05/25 00:32:52 | 000,619,000 | —- | M] (Acronis) [Disabled | Stopped] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2007/08/24 15:53:16 | 000,362,992 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe – (Roxio Upnp Server 10)
SRV - [2007/08/24 15:53:14 | 000,072,176 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe – (Roxio UPnP Renderer 10)
SRV - [2007/08/24 15:52:48 | 000,309,744 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe – (RoxLiveShare10)
SRV - [2007/08/24 15:52:46 | 000,166,384 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe – (RoxWatch10)
SRV - [2007/08/24 15:52:38 | 001,083,888 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe – (RoxMediaDB10)
SRV - [2007/06/07 21:05:52 | 000,598,960 | —- | M] ( ) [Auto | Running] – C:\WINDOWS\system32\lxdmcoms.exe – (lxdm_device)
SRV - [2007/06/07 21:05:44 | 000,099,248 | —- | M] () [Disabled | Stopped] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdmserv.exe – (lxdmCATSCustConnectService)
SRV - [2007/01/19 11:49:26 | 000,049,152 | —- | M] (Wireless Service) [Auto | Stopped] – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe – (ANIWZCSdService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\Jeff\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys – (cpuz132)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ComboFix\catchme.sys – (catchme)
DRV - [2011/08/19 17:26:50 | 004,334,624 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\lvuvc.sys – (LVUVC) Logitech HD Webcam C510(UVC)
DRV - [2011/08/19 17:26:46 | 000,315,808 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS)
DRV - [2011/08/19 17:26:34 | 000,022,176 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\lvbusflt.sys – (CompFilter)
DRV - [2011/07/06 07:26:53 | 000,138,192 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2011/07/06 07:26:53 | 000,066,616 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2010/06/17 15:27:22 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2010/06/17 15:27:12 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2010/06/02 11:33:42 | 000,049,904 | R— | M] (Avanquest Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5)
DRV - [2010/05/07 18:43:30 | 000,025,824 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/06/19 22:39:16 | 000,717,296 | —- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\drivers\sptd.sys – (sptd)
DRV - [2009/06/19 22:31:13 | 000,902,592 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\tdrpm228.sys – (tdrpman228) Acronis Try&Decide; and Restore Points filter (build 228)
DRV - [2009/06/19 22:31:08 | 000,540,000 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\timntr.sys – (timounter)
DRV - [2009/06/19 22:31:08 | 000,044,704 | —- | M] (Acronis) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\tifsfilt.sys – (tifsfilter)
DRV - [2009/06/19 22:31:05 | 000,138,208 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\snapman.sys – (snapman)
DRV - [2009/06/19 22:24:15 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\gdrv.sys – (gdrv)
DRV - [2009/05/25 16:01:00 | 000,069,098 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\jl2005c.sys – (JL2005C)
DRV - [2009/01/13 19:10:08 | 005,015,040 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/07/09 11:30:16 | 000,040,368 | —- | M] (Paragon Software Group) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\hotcore3.sys – (hotcore3)
DRV - [2008/04/14 00:11:00 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\changer.sys – (Changer)
DRV - [2008/04/14 00:10:28 | 000,034,688 | —- | M] (Toshiba Corp.) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\lbrtfdc.sys – (lbrtfdc)
DRV - [2007/11/22 15:55:52 | 000,105,088 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2007/08/18 03:09:04 | 000,057,328 | —- | M] (Sonic Solutions) [File_System | Disabled | Stopped] – C:\WINDOWS\system32\drivers\RxFilter.sys – (RxFilter)
DRV - [2006/12/21 04:25:20 | 000,429,440 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Dr71WU.sys – (RT73)
DRV - [2005/12/11 11:55:38 | 000,028,195 | —- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\ANIO.sys – (ANIO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com.au/ [binary data]
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 50 4C 5C 99 31 CD 01 [binary data]
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\SearchScopes\{597b1823-7ff0-4cd3-8095-9d8cba514992}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\SearchScopes\{F5D773B1-D457-4FA7-AFDD-9AEA1E792578}: "URL" = http://websearch.ask.com/redirect?client=i…F7-AE4566E5F653
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\SearchScopes\{FD63BF63-BFFF-4B8F-9D26-4267DF7F17DD}: "URL" =
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2009/10/22 11:59:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jeff\Application Data\Mozilla\Extensions
[2009/10/22 11:59:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jeff\Application Data\Mozilla\Extensions\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Jeff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\WeatherBlink\bar\1.bin\NPgcStub.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Skype Click to Call = C:\Documents and Settings\Jeff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\Jeff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\

O1 HOSTS File: ([2012/05/13 22:27:59 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (TranslatorBar 1.2 Toolbar) - {548f6736-8fe4-4680-82f2-170d6c07e1d2} - C:\Program Files\TranslatorBar_1.2\prxtbTra0.dll (Conduit Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (TranslatorBar 1.2 Toolbar) - {548f6736-8fe4-4680-82f2-170d6c07e1d2} - C:\Program Files\TranslatorBar_1.2\prxtbTra0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\..\Toolbar\WebBrowser: (TranslatorBar 1.2 Toolbar) - {548F6736-8FE4-4680-82F2-170D6C07E1D2} - C:\Program Files\TranslatorBar_1.2\prxtbTra0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe (D-Link)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Lexmark 5000 Series Fax Server] C:\Program Files\Lexmark 5000 Series\fm3032.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [lxdmamon] C:\Program Files\Lexmark 5000 Series\lxdmamon.exe ()
O4 - HKLM..\Run: [lxdmmon.exe] C:\Program Files\Lexmark 5000 Series\lxdmmon.exe ()
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab (Image Uploader Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8A45B53-A42E-4FB9-9B06-85B19BA56CDD}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/19 18:48:19 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/05/20 00:19:30 | 000,000,052 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2003/08/18 19:29:46 | 000,253,952 | R— | M] () - D:\autorun.exe – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/05/16 22:27:25 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/05/16 22:00:36 | 001,263,344 | —- | C] (ESET) – C:\Documents and Settings\Jeff\Desktop\eset_smart_security_live_installer.exe
[2012/05/11 11:46:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2012/05/11 11:46:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2012/05/10 16:06:59 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/05/10 16:06:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/05/08 22:51:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2012/05/08 22:50:04 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/29 11:38:06 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jeff\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/05/19 08:39:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/19 08:33:09 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME{B8A45B53-A42E-4FB9-9B06-85B19BA56CDD}
[2012/05/19 08:32:53 | 000,000,007 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME
[2012/05/19 08:32:51 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/19 08:32:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/05/18 19:10:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/18 16:51:30 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{EC1D1A66-3486-4EF5-958F-E2BF0937D028}.job
[2012/05/18 14:16:55 | 001,958,801 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\20120518_141655.jpg
[2012/05/18 07:28:25 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/05/16 22:00:36 | 001,263,344 | —- | M] (ESET) – C:\Documents and Settings\Jeff\Desktop\eset_smart_security_live_installer.exe
[2012/05/16 20:55:12 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/15 19:54:46 | 000,006,557 | —- | M] () – C:\Documents and Settings\All Users\lxdm
[2012/05/15 11:29:00 | 002,140,432 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\20120515_112900.jpg
[2012/05/15 11:28:42 | 002,019,616 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\20120515_112842.jpg
[2012/05/15 11:28:26 | 002,398,105 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\20120515_112826.jpg
[2012/05/13 22:27:59 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/05/13 12:47:00 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/05/13 10:25:18 | 000,002,048 | —- | M] () – C:\Documents and Settings\Jeff\Application Data\PhotobooksExpress.com.au Prefs
[2012/05/12 07:12:50 | 000,309,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/11 23:25:32 | 000,444,160 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/05/11 23:25:32 | 000,072,418 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/05/11 23:22:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/05/10 16:07:17 | 000,000,767 | —- | M] () – C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/05/10 16:06:59 | 000,000,611 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\NTREGOPT.lnk
[2012/05/10 16:06:59 | 000,000,592 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\ERUNT.lnk
[2012/05/04 20:00:27 | 000,854,443 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\017.JPG
[2012/05/01 09:32:48 | 000,000,000 | —- | M] () – C:\Documents and Settings\Jeff\defogger_reenable
[2012/04/29 11:54:10 | 000,302,592 | —- | M] () – C:\Documents and Settings\Jeff\Desktop\lrrcb694.exe
[2012/04/29 11:38:15 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeff\Desktop\OTL.exe

========== Files Created - No Company Name ==========

[2012/05/18 15:18:36 | 001,958,801 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\20120518_141655.jpg
[2012/05/16 20:55:12 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/15 11:31:07 | 002,140,432 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\20120515_112900.jpg
[2012/05/15 11:31:07 | 002,019,616 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\20120515_112842.jpg
[2012/05/15 11:31:06 | 002,398,105 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\20120515_112826.jpg
[2012/05/12 21:38:11 | 000,584,937 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\my phone 08-11 026.jpg
[2012/05/11 23:17:03 | 000,111,468 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\ava's birthday fairy concert 026.jpg
[2012/05/11 22:59:20 | 000,524,764 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\avas dancing dec 2011 005.jpg
[2012/05/11 22:51:42 | 003,635,180 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\kings carnaval nov 2011 045.jpg
[2012/05/11 22:51:35 | 000,527,170 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\my phone 08-11 021.jpg
[2012/05/11 22:47:54 | 002,865,283 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\Webb sunday 17 april 008.jpg
[2012/05/11 22:47:47 | 001,822,935 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\Picture 047.jpg
[2012/05/11 22:47:43 | 000,503,473 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\my phone 08-11 045.jpg
[2012/05/11 22:47:33 | 001,188,817 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\my phone 08-11 030.jpg
[2012/05/11 22:47:22 | 001,698,302 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\kerry house - girls 030.jpg
[2012/05/11 22:47:16 | 001,781,376 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\kerry house - girls 011.jpg
[2012/05/11 22:46:53 | 002,217,244 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\bali + cubby house 029.jpg
[2012/05/11 22:46:46 | 001,823,945 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\20120405_091809.jpg
[2012/05/11 22:46:31 | 000,939,924 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\08 - 09 part 2 542.jpg
[2012/05/11 22:46:25 | 000,778,255 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\08 - 09 part 2 031.jpg
[2012/05/11 22:46:19 | 000,874,386 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\100_3497.JPG
[2012/05/11 22:45:58 | 000,854,443 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\017.JPG
[2012/05/11 22:26:59 | 000,517,396 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\08 - 09 part 2 303.jpg
[2012/05/11 22:05:37 | 001,916,778 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\mum 4-2011 191.jpg
[2012/05/11 22:05:03 | 002,158,991 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\mum 4-2011 296.jpg
[2012/05/11 22:03:33 | 000,653,070 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\jun-sep 09 090.jpg
[2012/05/11 22:03:16 | 001,013,419 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\jun-sep 09 064.jpg
[2012/05/11 22:02:54 | 000,427,307 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\girls 001.jpg
[2012/05/11 22:00:20 | 000,651,647 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\100_3165.JPG
[2012/05/11 21:57:32 | 001,057,144 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\100_3160.JPG
[2012/05/11 21:52:21 | 003,020,234 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\bali + cubby house 030.jpg
[2012/05/11 21:52:02 | 001,872,360 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\kelleys 18th 148.jpg
[2012/05/11 21:51:56 | 001,655,034 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\kelleys 18th 367.jpg
[2012/05/11 21:51:41 | 001,013,419 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\08 - 09 part 2 369.jpg
[2012/05/11 21:51:34 | 000,574,069 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\08 - 09 part 2 316.jpg
[2012/05/10 16:07:17 | 000,000,767 | —- | C] () – C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/05/10 16:06:59 | 000,000,611 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\NTREGOPT.lnk
[2012/05/10 16:06:59 | 000,000,592 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\ERUNT.lnk
[2012/05/01 09:32:48 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jeff\defogger_reenable
[2012/04/29 11:54:05 | 000,302,592 | —- | C] () – C:\Documents and Settings\Jeff\Desktop\lrrcb694.exe
[2012/03/30 09:44:24 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\JJAKEn.dll
[2012/03/10 07:31:46 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2012/03/09 17:35:25 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\cdga.dll
[2012/02/15 06:30:28 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/06/04 16:39:19 | 000,000,037 | —- | C] () – C:\WINDOWS\iltwain.ini
[2011/06/03 15:48:39 | 000,002,048 | —- | C] () – C:\Documents and Settings\Jeff\Application Data\PhotobooksExpress.com.au Prefs
[2011/04/05 20:03:50 | 000,002,048 | —- | C] () – C:\Documents and Settings\Jeff\Application Data\123 Cheese Prefs
[2011/03/08 13:58:49 | 000,065,648 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/11/10 10:45:32 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/11/10 10:45:30 | 010,898,456 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/11/10 10:45:20 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/11/10 10:31:42 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/08/27 12:46:37 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdmoem.dll
[2010/08/27 12:46:37 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\LXDMPMON.DLL
[2010/08/27 12:46:37 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXDMFXPU.DLL
[2010/07/22 15:42:21 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat

========== LOP Check ==========

[2010/08/27 12:46:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\5000 Series
[2009/06/19 22:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/12/01 22:07:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
[2011/11/07 14:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2009/06/19 22:41:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/07/18 13:33:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/11/25 06:37:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fisher-Price
[2011/11/25 06:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2009/06/19 22:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/03/07 08:56:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Snapshots
[2012/02/18 09:52:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/03/06 14:55:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/05 20:03:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\123 Cheese
[2010/08/27 14:51:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\5000 Series
[2011/08/25 14:11:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Acronis
[2011/01/04 16:38:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Clip Art Collection
[2009/06/19 22:42:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\DAEMON Tools
[2009/06/19 22:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\DAEMON Tools Lite
[2009/06/19 22:42:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\DAEMON Tools Pro
[2010/03/29 07:50:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\ElevatedDiagnostics
[2012/03/09 19:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\GetRightToGo
[2009/08/27 13:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Leadertech
[2010/08/27 13:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Lexmark Productivity Studio
[2010/01/19 13:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\LimeWire
[2011/06/03 15:48:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\PhotobooksExpress.com.au
[2011/08/13 18:06:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\PriceGong
[2011/12/09 16:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Scholastic
[2009/09/28 13:51:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Snapfish
[2009/06/19 22:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\TeamViewer
[2011/07/27 15:26:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Vso
[2010/03/22 20:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TeamViewer
[2012/05/18 16:51:30 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC1D1A66-3486-4EF5-958F-E2BF0937D028}.job

========== Purity Check ==========



< End of report >
Thanks for the information :thumbup: Please note that I will be offline this afternoon (May 19) until Wednesday, May 23, so I have requested another helper to step in. Thanks! :) Regards, Richard :wavey:
Hi molly39,

Questionable Toolbar/Plugin Uninstall:

Conduit Engine is an open to debate browser plugin.

If you would like to remove the Toolbar(s)/Plugin(s), follow these steps:
  • Click on Start > Control Panel.
  • Click on Add or Remove Programs.
  • Select the following from the list:


    Conduit Engine

  • Click the Remove button.
Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      
    :Commands
    [clearallrestorepoints] 
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
  • Copy and paste the contents of that report in your next reply.
In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.
HI , PC seems to be running better each time. I also want to ask abt messages I get from Skype. repairs@online maintenance and system warnings that my pc is under threat. Not sure what to do with these requests. kind regards All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Jeff ->Temp folder emptied: 242355 bytes ->Temporary Internet Files folder emptied: 25976015 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 978 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 255 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 25.00 mb OTL by OldTimer - Version 3.2.42.1 log created on 05202012_110356 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDBC2.tmp not found! File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDBDA.tmp not found! File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDE68.tmp not found! File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDE80.tmp not found! File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDFA6.tmp not found! File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DFDFC3.tmp not found! C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\XV041IJ9\google_com_au[1].htm moved successfully. C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\9YQVVB32\iframe[2].htm moved successfully. C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\9YQVVB32\search[1].htm moved successfully. C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\89GWX9PO\search[1].htm moved successfully. C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\4GY1UKIZ\index[1].htm moved successfully. C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\4GY1UKIZ\index[2].htm moved successfully. Registry entries deleted on Reboot…
Hi molly39, The messages from Skype appear to be a scam. Do Not answer them and don't click on any links that may be in the message(s). Ignore them, block the sender and change your settings to accept calls only from people you know. Any other issues?
Hi molly39,

You logs do not show any malware. We'll clean up the tools. The System Restore should have been reset in the last fix.

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER (lrrcb694.exe)

Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly.


Updates and upgrades

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall and a resident antispyware to what you have.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware, IMO)


I suggest either for a resident antispyware program. There may be others in the link further down that may interest you.

Windows Defender
OR
Winpatrol


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen option. Click your start button > Control Panel > System > Automatic Updates tab


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


Please post back if you have any problems.

Take care :adios:
HI… sorry , I could not locate "DEFOGGER"… do i have to download this again ( i have found an older log report from defogger… thats all ) thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI