1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

links redirect open new window and redirect to advertising site

Discussion in 'Virus & Other Malware Removal' started by mat64b, May 9, 2010.

Thread Status:
Not open for further replies.
  1. mat64b

    mat64b Thread Starter

    Joined:
    May 9, 2010
    Messages:
    4
    Hi
    Recently, when I click a link brought up from a Google search it opens a new window and the first time I click the link it takes me to a different site than the link should. This happens in Safari 4.0.5 and IE8.
    Also, my wife purchased a train ticket online and 1 hour later we had a phone call from the bank suggesting fraudulent use of the card detailed she had entered. I do not know if this is related but am very concerned. I was running AVG but uninstalled as it was showing no errors and Combofix didn't want it running when it was scanning.

    I have found a few similar posts and therefore have down loaded and run:

    Combofix.exe - ran this first and theno I rebooted
    Hijackthis - ran this, have not rebooted since

    The problem appears to be resolved as the links open in the same window correctly now but here are the logs from my scans, can you please confirm if I have removed all the malicious software?

    Combofix log:
    ComboFix 10-05-08.03 - Mat 09/05/2010 13:05:47.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.1180 [GMT 1:00]
    Running from: c:\users\Mat\AppData\Local\Temp\af9jj5r9.tmp\ComboFix.exe
    SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\programdata\hpe3201.dll
    c:\windows\system32\spool\prtprocs\w32x86\0000421c.tmp
    c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

    .
    ((((((((((((((((((((((((( Files Created from 2010-04-09 to 2010-05-09 )))))))))))))))))))))))))))))))
    .

    2010-05-09 12:17 . 2010-05-09 12:17 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
    2010-05-09 12:17 . 2010-05-09 12:17 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-04-28 20:50 . 2010-04-28 20:50 -------- d-----w- c:\program files\iPod
    2010-04-28 20:44 . 2010-04-28 20:44 -------- d-----w- c:\program files\Bonjour
    2010-04-28 20:34 . 2010-04-28 20:34 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
    2010-04-28 20:28 . 2010-04-28 20:28 -------- d-----w- c:\program files\Safari
    2010-04-28 20:21 . 2010-04-28 20:21 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
    2010-04-20 13:09 . 2010-04-20 13:09 -------- d-----w- c:\users\Mat\AppData\Roaming\Serif
    2010-04-20 12:58 . 2010-04-20 12:58 -------- d-----w- c:\program files\Serif
    2010-04-15 01:53 . 2010-04-15 01:53 -------- d-----w- c:\programdata\VirtualizedApplications
    2010-04-14 18:44 . 2010-04-14 18:44 -------- d-----w- c:\users\Mat\AppData\Local\NVD
    2010-04-14 18:44 . 2010-04-14 18:44 -------- d-----w- c:\users\Mat\AppData\Roaming\NVD
    2010-04-14 18:43 . 2010-04-14 18:43 -------- d-----w- c:\users\Mat\AppData\Local\SoftGrid Client
    2010-04-14 18:43 . 2010-05-09 11:43 -------- d-----w- c:\users\Mat\AppData\Roaming\SoftGrid Client
    2010-04-14 18:41 . 2010-04-14 18:41 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
    2010-04-14 18:39 . 2010-04-14 18:44 -------- d-----w- c:\users\Mat\AppData\Roaming\TP
    2010-04-13 09:38 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
    2010-04-12 23:25 . 2010-04-12 22:35 38784 ----a-w- c:\users\Mat\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-04-12 22:49 . 2010-04-12 22:49 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
    2010-04-12 22:49 . 2010-04-12 23:17 -------- d-----w- c:\users\Mat\Adobe Flash Builder 4
    2010-04-12 22:35 . 2010-04-12 22:35 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-04-12 22:35 . 2010-04-12 22:35 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-04-12 10:34 . 2010-04-12 10:34 -------- d-----w- c:\program files\AAALOGO2009
    2010-04-11 20:34 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
    2010-04-11 20:34 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-05-09 11:42 . 2007-07-20 23:02 2140 ----a-w- c:\windows\bthservsdp.dat
    2010-05-07 22:14 . 2009-06-20 23:33 209036 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-04-28 20:51 . 2009-07-19 22:05 -------- d-----w- c:\program files\iTunes
    2010-04-28 20:50 . 2009-02-02 18:35 -------- d-----w- c:\program files\Common Files\Apple
    2010-04-20 13:16 . 2008-10-31 11:27 131808 ----a-w- c:\users\Mat\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-04-18 20:19 . 2007-07-23 18:44 -------- d-----w- c:\programdata\Microsoft Help
    2010-04-17 23:07 . 2007-07-23 18:37 -------- d-----w- c:\program files\Google
    2010-04-12 23:11 . 2007-07-23 18:49 -------- d-----w- c:\program files\Common Files\Adobe
    2010-04-12 22:16 . 2009-07-26 21:50 -------- d-----w- c:\program files\Citrix
    2010-04-12 22:14 . 2007-07-23 18:50 -------- d-----w- c:\program files\Sony
    2010-04-12 22:14 . 2007-07-20 23:46 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-04-08 12:20 . 2010-04-08 12:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-04-08 12:20 . 2010-04-08 12:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-04-08 10:30 . 2010-04-06 21:13 -------- d-----w- c:\programdata\Avanquest Bluetooth SDK
    2010-04-06 22:44 . 2010-04-06 22:39 -------- d-----w- c:\users\Mat\AppData\Roaming\Sony
    2010-04-06 22:43 . 2010-04-06 22:43 10134 ----a-r- c:\users\Mat\AppData\Roaming\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
    2010-04-06 22:42 . 2007-07-23 18:58 -------- d-----w- c:\programdata\Sony Corporation
    2010-04-06 22:39 . 2010-04-06 22:39 -------- d-----w- c:\users\Mat\AppData\Roaming\Sony Setup
    2010-04-06 22:38 . 2010-04-06 22:38 -------- d-----w- c:\program files\Sony Setup
    2010-04-06 22:13 . 2010-04-06 22:11 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    2010-04-06 22:07 . 2010-04-06 22:06 -------- d-----w- c:\program files\QuickTime
    2010-04-06 22:02 . 2010-04-06 22:02 -------- d-----w- c:\program files\Apple Software Update
    2010-04-06 21:12 . 2010-04-06 21:12 -------- d-----w- c:\programdata\BVRP Software
    2010-04-06 20:08 . 2010-04-06 20:08 -------- d-----w- c:\programdata\Sony Ericsson
    2010-04-06 20:08 . 2010-04-06 20:08 -------- d-----w- c:\program files\Sony Ericsson
    2010-04-04 14:44 . 2010-04-04 14:43 -------- d-----w- c:\program files\Veetle
    2010-04-01 18:37 . 2010-04-01 18:37 -------- d-----w- c:\users\Mat\AppData\Roaming\Trusteer
    2010-04-01 18:35 . 2010-04-01 18:35 -------- d-----w- c:\programdata\Trusteer
    2010-03-31 19:39 . 2007-07-23 19:00 -------- d-----w- c:\program files\Common Files\Java
    2010-03-31 19:37 . 2007-07-23 19:00 -------- d-----w- c:\program files\Java
    2010-03-22 23:51 . 2010-03-22 23:51 -------- d-----w- c:\program files\Windows Portable Devices
    2010-03-22 23:51 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2010-03-22 23:51 . 2010-03-22 23:51 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
    2010-03-22 23:51 . 2010-03-22 23:51 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2010-03-21 09:35 . 2010-03-21 09:35 -------- d-----w- c:\programdata\Office Genuine Advantage
    2010-03-20 02:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
    2010-03-20 00:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
    2010-03-19 23:03 . 2010-03-19 23:03 784136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
    2010-03-18 00:06 . 2009-08-26 21:07 -------- d-----w- c:\users\Mat\AppData\Roaming\Azureus
    2010-03-13 09:25 . 2008-10-31 11:26 150821 ----a-w- c:\users\Mat\AppData\Roaming\nvModes.dat
    2010-03-09 03:28 . 2009-01-01 20:56 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-23 06:39 . 2010-03-31 19:50 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-02-23 06:33 . 2010-03-31 19:50 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-02-23 06:33 . 2010-03-31 19:50 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-02-23 04:55 . 2010-03-31 19:50 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-02-20 23:06 . 2010-03-20 01:58 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2010-02-20 23:05 . 2010-03-20 01:58 30720 ----a-w- c:\windows\system32\httpapi.dll
    2010-02-20 20:53 . 2010-03-20 01:58 411648 ----a-w- c:\windows\system32\drivers\http.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-11-20 434176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
    "Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 317560]
    "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-06-28 86016]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8429568]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
    "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-02-22 500208]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-6-22 739880]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2007-07-12 15:33 98304 ----a-w- c:\windows\System32\VESWinlogon.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2"=hex(b):a9,e6,89,5a,c9,c7,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1940038719-2940398501-1664066158-1000]
    "EnableNotificationsRef"=dword:00000001

    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 135664]
    R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-09-26 4639136]
    S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2009-09-26 819600]
    S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
    S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2009-09-23 447832]
    S2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [2009-11-13 46824]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2007-07-03 28464]
    S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-06-28 75008]
    S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-06-28 43904]
    S3 sftfs;sftfs;c:\program files\Microsoft Application Virtualization Client\drivers\sftfslh.sys [2009-09-23 543064]
    S3 sftplay;sftplay;c:\program files\Microsoft Application Virtualization Client\drivers\sftplaylh.sys [2009-09-23 190312]
    S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-09-23 21848]
    S3 sftvol;sftvol;c:\program files\Microsoft Application Virtualization Client\drivers\sftvollh.sys [2009-09-23 14680]
    S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2009-09-23 203608]
    S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-06-06 812544]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder

    2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 14:35]

    2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 14:35]

    2010-05-09 c:\windows\Tasks\User_Feed_Synchronization-{813D40C1-55A6-402F-8E8A-117F61A911EE}.job
    - c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com
    Trusted Zone: corel.com
    Trusted Zone: intervideo.com
    Trusted Zone: intervideo.com\www
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b4

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2010-05-09 13:22:18
    ComboFix-quarantined-files.txt 2010-05-09 12:22

    Pre-Run: 91,169,116,160 bytes free
    Post-Run: 93,699,486,720 bytes free

    - - End Of File - - 9DC505380B7B30849505C960F0E658A9

    Hijackthis Log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:51:21, on 09/05/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18904)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Apoint\ApMsgFwd.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O15 - Trusted Zone: http://*.corel.com
    O15 - Trusted Zone: www.intervideo.com
    O15 - Trusted Zone: http://*.intervideo.com
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Xobni\Skype4Com.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe

    --
    End of file - 8606 bytes
     
  2. mat64b

    mat64b Thread Starter

    Joined:
    May 9, 2010
    Messages:
    4
    Hi
    Have I supplied incorrect information on this thread or are there no issues remaining with the PC?

    Any assistance anyone can provide would be much appreciated?
    Thanks
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/921994

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice