This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Smitfraud-C problems

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Unless I am blind I see neither of those in my Add or Remove Programs. I removed the only McAfee program I saw in there before I DLed the remover tool you sent me.
bomshelltron,

Let's nuke it then. :P

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    c:\Program Files\Network Associates
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== c:\Program Files\Network Associates\Common Framework\0409 moved successfully. c:\Program Files\Network Associates\Common Framework moved successfully. c:\Program Files\Network Associates moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\NAILogs\UpdaterUI_NINKAXP01.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\etilqs_7jXbA9Oe3NPHXPS8mn4a scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\fla73.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DF4081.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DF5321.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DFC685.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DFC698.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_660.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02102009_171432 Files moved on Reboot… C:\DOCUME~1\Ninka\LOCALS~1\Temp\NAILogs\UpdaterUI_NINKAXP01.log moved successfully. File C:\DOCUME~1\Ninka\LOCALS~1\Temp\etilqs_7jXbA9Oe3NPHXPS8mn4a not found! File C:\DOCUME~1\Ninka\LOCALS~1\Temp\fla73.tmp not found! File C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DF4081.tmp not found! File C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DF5321.tmp not found! File C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DFC685.tmp not found! File C:\DOCUME~1\Ninka\LOCALS~1\Temp\~DFC698.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_660.dat not found! C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\XUL.mfl moved successfully.
bomshelltron,

OOps. It looks like you accidently copied the word with the script. Looks like the important part worked anyway.

Now try the McAfee removal tool and see if it's gone.
I spoke with a friend waitign for your reply, and he told me it's because I uninstalled it the wrong way ( the way McAfee didn't want me to uninstall it ) but it's not there.. ( Mind you; my friend wasn't physically with me when I did this, he just helped me via phone ) But let me give you the HijackThis log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:31:54 PM, on 2/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\AIM\aim.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1198818838093
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5421 bytes
bomshelltron,

Your friend is correct. That's the reason for running the removal tool. It should clean up traces that weren't removed "correctly".

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
      O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    McAfeeFramework
    
    :Reg
    
    :Files
    C:\Program Files\Network Associates
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then run your removal tool.

PS: Don't copy the work Code in the script. :D
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service McAfeeFramework stopped successfully. Service McAfeeFramework deleted successfully. ========== REGISTRY ========== ========== FILES ========== File/Folder C:\Program Files\Network Associates not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Ninka\LOCALS~1\Temp\etilqs_Fh398ut1kQHGv3lcwlGe scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_798.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02112009_004754 Files moved on Reboot… File C:\DOCUME~1\Ninka\LOCALS~1\Temp\etilqs_Fh398ut1kQHGv3lcwlGe not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_798.dat not found! C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Ninka\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wptathe.default\urlclassifier3.sqlite moved successfully. I used the tool, it got farther than the last time, but says it's still finding McAfee.
bomshelltron,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 7:02:05.04 on Wed 02/11/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1498 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe


C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\AIM\aim.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ninka\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [nwiz] nwiz.exe /install
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: E&xport; to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - d:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198818838093
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ninka\applic~1\mozilla\firefox\profiles\5wptathe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.livestrong.com/
FF - plugin: d:\mozilla plugins\npitunes.dll

============= SERVICES / DRIVERS ===============

R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 DCamUSBTP10;iP2936 USB Camera;c:\windows\system32\drivers\ip293x.sys –> c:\windows\system32\drivers\iP293x.sys [?]
S3 PCAlertDriver;PCAlertDriver;c:\biostools\NTGLM7X.SYS [2007-12-27 22048]

=============== Created Last 30 ================

2009-02-10 17:17 23,392 a——- c:\windows\system32\nscompat.tlb
2009-02-10 17:17 16,832 a——- c:\windows\system32\amcompat.tlb
2009-02-10 17:14 –d—– C:\_OTMoveIt
2009-02-10 14:55 –d—– c:\program files\SpywareBlaster
2009-02-10 14:40 410,984 a——- c:\windows\system32\deploytk.dll
2009-02-10 14:40 73,728 a——- c:\windows\system32\javacpl.cpl
2009-02-10 13:00 –d—– c:\program files\Trend Micro
2009-02-10 11:55 –d—– c:\docume~1\ninka\applic~1\Malwarebytes
2009-02-10 11:55 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-02-10 11:55 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-10 11:55 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-08 23:02 –d—– c:\documents and settings\ninka\Contacts
2009-02-08 21:26 –d—– C:\QUARANTINE
2009-02-08 20:58 –d—– c:\program files\MSXML 4.0
2009-02-08 20:58 –d—– c:\program files\AOD
2009-02-08 10:44 –d—– c:\docume~1\alluse~1\applic~1\Symantec(2)
2009-02-08 10:31 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-02-08 09:04 –d—– c:\program files\NavNT
2009-02-08 09:04 –d—– c:\program files\common files\Symantec Shared

==================== Find3M ====================

2008-11-13 14:12 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat

============= FINISH: 7:02:16.75 ===============


EDIT: Please let me know what programs I can delete when you're done.. :P I dislike having a lot of programs on my comp.
bomshelltron,

I don't see anything related to McAfee but looks like you also used to have Symantec (Norton).

Use the link below to see how to run the Norton Removal Tool
http://service1.symantec.com/SUPPORT/tsgen…005033108162039

You don't appear to have any Anti-virus running. You need to get one installed.
I knoowwww. :[ I'm working on it, been a little busy. EDIT: I don't know why, but websites haven't been loading/load really slow with weird HTML in my Firefox browser.. Trying to DL the Norton Removal and it's acting weird and taking forever. Another edit; I don't know what program of Norton I have on my computer? That was another one I ended up trying to uninstall, but McAfee was in the way.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI