Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Malware Removal & HijackThis Logs
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop driver dvd email error excel excel 2003 firefox hard drive hardware hijackthis internet keyboard laptop malware monitor network networking outlook problem processor ram recovery router safe mode screen slow sound spyware trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
3rd Posting Same Issue...Somebody Please Help (In Progress)

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
04-Nov-2009, 02:20 PM #16
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
If you are not sure how to disable see this help page.



Download ComboFix from one of these locations:

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:





Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
__________________
Microsoft MVP/Windows - Consumer Security
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
05-Nov-2009, 12:32 AM #17
The ComboFix scan has been running for about 4 hours now and hasnt finished so i will stop it, reboot the pc, and start it again...hopefully i did it right but not so sure.
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
05-Nov-2009, 05:26 AM #18
ComboFix has again been running for 4+ hours. I have to go to work and will just leave it on and running. I suppose this is the thing to do.
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
05-Nov-2009, 01:07 PM #19
When I got home from working, the computer was showing me vivid blue screen saying PROBLEM HAS BEEN DETECTED. WINDOWS HAS BEEN SHUT DOWN .IRQL_NOT_LESS_OR_EQUAL then at the bottom of the page it had this
***STOP: 0x0000000A technical information (0x00000000,0x00000002,0x00000000,0x0x804FD5F3) Beginning Dump of Physical Memory then Dump of Physical Memory Complete
I am searching all references of ComboFix, am planning to delete it-redownload and run it again and post results.
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
05-Nov-2009, 04:38 PM #20
Does the machine boot up ok?
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
05-Nov-2009, 05:20 PM #21
booting up
The pc actually shuts down and comes back up a little faster than before but it takes FOREVER to load pages. Also I tried deleting all the entries of ComboFix but not all would delete. I still cannot get ComboFix to run...The blue box loads and gives me this message ......"Scanning for Infected files...This typically doesnt take more than 10 minutes However scan times for badly infected machines may easily double" I'm not sure if there is something i need to be doing at this point or just wait but so far, it has run or attempted to run for about 12 hrs collectively. I have used ComboFix on previous issues when referenced by the techguy.org pros and have had good results...this time, I'm not sure it is ever actually starting....any ideas? I tried hitting the enter button...ive tried waiting...it is apparently just not happening.
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
06-Nov-2009, 12:22 AM #22
ComboFix has been running(I guess) for 6 or 7 hrs this time(maybe longer)...the Task Manager says its running...so ill let it go until I get another error message or until I hear from you. goodnight........
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
06-Nov-2009, 01:22 PM #23
Are you sure you have disabled Spybot S&D and avast?
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
06-Nov-2009, 03:30 PM #24
each time i try to run ComboFix, and just let it go for long periods i end up back the "blue screen" with the error messages. I will check both avast and spybot but im pretty sure i did what the directions indicated.
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
06-Nov-2009, 04:39 PM #25
Stop trying to run ComboFix.



Please run ESET Online Scanner

Note: You can use IE or FireFox for this scan. You need to disable your current installed Anti-Virus. If you need help with that look here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
  • Please go ESET Online Scanner and click on the ESET Online Scanner button
  • Select the option YES, I accept the Terms of Use then click on Start
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on Start
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on Finish
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
__________________
Microsoft MVP/Windows - Consumer Security
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
06-Nov-2009, 11:46 PM #26
3rd Posting Same Issue...Somebody Please Help(ESET LOG)
This is the logfile from ESET. For some reason, the copy and [aste didn't seem to work correctly. I hope this is what you need...

C:\SDFix\apps\Process.exe Win32/PrcView application
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\los lobos-one night in america.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\john hiatt-drive south.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\id love you all over again.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu [extended concert version].mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu (new album).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia satellites-every pictu (new album).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\ga satellites-every pictuer te new single.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\every picture tells story unreleased studio edition.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\Owner\Desktop\Misc.Set-Up Files\SDFix.exe Win32/PrcView application
C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\id love you all over again.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip Win32/Bagle.gen.zip worm
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
07-Nov-2009, 03:04 PM #27
It's very obvious that your usage of P2P programs is causing your problems.

The P2P programs you have installed expose you to risks because of the nature of the P2P file sharing process. File sharing/P2P programs rely on members giving and gaining unrestricted access to computers across the P2P network. This practice can make you vulnerable to data and identity theft. It also exposes you to very malicious worms and trojans. You change those risky default settings to a safer configuration but the act of downloading files from an anonymous source greatly increases your exposure to infection.

If you want my help go to add/remove programs and remove all P2P programs from your machine!




Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy all the lines in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Quote:
    :Files
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\los lobos-one night in america.mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\john hiatt-drive south.mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\id love you all over again.wma
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu [extended concert version].mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu (new album).mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\ga satellites-every pictuer te new single.mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\every picture tells story unreleased studio edition.mp3
    C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3
    C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\id love you all over again.wma
    C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



You should remove all of the tools I requested you to download and/or folders associated with them now. It is pointless to keep these tools around as they are updated so frequently that the tools can be outdated within a few days, sometimes within just hours.
  • Start OTS
  • Click the CleanUp button
    • OTS will download a small file from the Internet. If a security program or firewall warns you of this allow it to download.
    • OTS will delete any tools downloaded and files/folders created and then ask you to reboot so it can remove itself.
  • Click Yes.
__________________
Microsoft MVP/Windows - Consumer Security
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
08-Nov-2009, 03:25 AM #28
Otm log file
========== FILES ==========
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\los lobos-one night in america.mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\john hiatt-drive south.mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\id love you all over again.wma moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu [extended concert version].mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\georgia sattelites-every pictu (new album).mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\ga satellites-every pictuer te new single.mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\every picture tells story unreleased studio edition.mp3 moved successfully.
C:\Documents and Settings\Owner\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3 moved successfully.
C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\id love you all over again.wma moved successfully.
C:\Documents and Settings\HelpAssistant\My Documents\LimeWire\Saved\Beastie Boys - Flute Loop.mp3 moved successfully.

OTM by OldTimer - Version 3.0.0.6 log created on 11082009_032126
cybertech's Avatar
Computer Specs
Moderator with 68,253 posts.
 
Join Date: Apr 2002
Location: Washington State
08-Nov-2009, 01:53 PM #29
Post your hijackthis log again and let me know if you are still having problems.
biddle1's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Feb 2008
Experience: Beginner
08-Nov-2009, 03:37 PM #30
HJT Log again...
Changing from page to page is painfully slow, changing tabs is slow, and when I went to check the online bank page, I still for the attempted re-direct. My wife initially set this up and put a link in the Favorites which I deleted prior to trying to connect. Then I went into the Documents and Settings and manually deleted the file located there. Went back, tried again and the re-direct page was there. As mentioned, the bank has been notified and they said it definitely WAS NOT them trying to harvest the information. Do you have any suggestions on speeding up my system and re-securing my computer? Below is my HJT log file. Thank you again.

Logfile of HijackThis v1.99.1
Scan saved at 3:01:13 PM, on 11/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATT Internet Tools\blsloader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\LEX 18 Desktop Weather\liveonline_3251316.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\WINDOWS\System32\lxcgcoms.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\ATT Internet Tools\blspc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\ATT Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Startup: LEX 18 Desktop Weather.lnk = C:\Program Files\LEX 18 Desktop Weather\liveonline_3251316.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.75\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 3.75\MediaManager\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/...fslauncher.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} -
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} (Enlite 2.x Simulation Engine Installer) - http://myitlab.pearsoned.com/Pegasus...es/ax/stub.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab
O16 - DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - http://pbells.broadjump.com/wizlet/S...ller_4-2-0.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\msgrapp.8.5.1302.1018.dll
O18 - Filter: text/html - {6a8c4c93-417e-4fb0-9aba-c91a911009c0} - C:\WINDOWS\system32\mst122.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\System32\lxcgcoms.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
Closed Thread Bookmark and Share

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 09:41 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.