Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: Need some help on my log

  1. #11
    Join Date
    Mar 2008
    Posts
    9
    here is the next report and thank you again

    Find AWF report by noahdfear ©2006
    Version 1.40
    Option 2 run successfully

    The current date is: Sun 03/09/2008
    The current time is: 18:42:04.01


    bak folders found
    ~~~~~~~~~~~


    Directory of C:\PROGRA~1\CCLEANER\BAK

    07/13/2007 04:10 AM 598,656 ccleaner.exe
    1 File(s) 598,656 bytes

    Directory of C:\PROGRA~1\ITUNES\BAK

    09/14/2007 10:00 AM 267,064 iTunesHelper.exe
    1 File(s) 267,064 bytes

    Directory of C:\PROGRA~1\LINKSY~1\BAK

    10/30/2006 11:01 AM 392,832 LinksysAgent.exe
    1 File(s) 392,832 bytes

    Directory of C:\PROGRA~1\MESSEN~1\BAK

    0 File(s) 0 bytes

    Directory of C:\PROGRA~1\QUICKT~1\BAK

    06/29/2007 06:24 AM 286,720 QTTask.exe
    1 File(s) 286,720 bytes

    Directory of C:\PROGRA~1\REGIST~1\BAK

    10/30/2006 01:12 PM 2,287,152 RegMech.exe
    1 File(s) 2,287,152 bytes

    Directory of C:\WINDOWS\SYSTEM32\BAK

    08/12/2004 08:56 AM 15,360 ctfmon.exe
    09/20/2005 09:32 AM 77,824 hkcmd.exe
    09/20/2005 09:36 AM 114,688 igfxpers.exe
    09/20/2005 09:35 AM 94,208 igfxtray.exe
    4 File(s) 302,080 bytes

    Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

    12/10/2006 09:52 PM 49,152 HPWuSchd2.exe
    1 File(s) 49,152 bytes

    Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK

    07/27/2004 04:50 PM 81,920 issch.exe
    1 File(s) 81,920 bytes

    Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

    07/12/2007 04:00 AM 132,496 jusched.exe
    1 File(s) 132,496 bytes


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    816368 Jan 17 2008 "C:\Program Files\CCleaner\ccleaner.exe"
    598656 Jul 13 2007 "C:\Program Files\CCleaner\bak\ccleaner.exe"
    267048 Feb 19 2008 "C:\Program Files\iTunes\iTunesHelper.exe"
    267064 Sep 14 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
    102400 Feb 27 2008 "C:\WINDOWS\Installer\{80FD852F-5AAC-4129-B931-06AAFFA43138}\iTunesIco.exe"
    75048 Feb 27 2008 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.1.9\iTunesSetupAdmin.exe"
    393344 Oct 30 2006 "C:\Program Files\Linksys EasyLink Advisor\LinksysAdvisor.exe"
    392832 Oct 30 2006 "C:\Program Files\Linksys EasyLink Advisor\bak\LinksysAgent.exe"
    385024 Feb 1 2008 "C:\Program Files\QuickTime\QTTask.exe"
    286720 Jun 29 2007 "C:\Program Files\QuickTime\bak\QTTask.exe"
    2287152 Oct 30 2006 "C:\Program Files\Registry Mechanic\RegMech.exe"
    2287152 Oct 30 2006 "C:\Program Files\Registry Mechanic\bak\RegMech.exe"
    15360 Aug 12 2004 "C:\WINDOWS\system32\ctfmon.exe"
    15360 Aug 12 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
    77824 Sep 20 2005 "C:\WINDOWS\system32\hkcmd.exe"
    77824 Sep 20 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
    114688 Sep 20 2005 "C:\WINDOWS\system32\igfxpers.exe"
    114688 Sep 20 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
    94208 Sep 20 2005 "C:\WINDOWS\system32\igfxtray.exe"
    94208 Sep 20 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
    49152 Dec 10 2006 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
    86960 Mar 20 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"
    81920 Jul 27 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe"
    32881 Mar 4 2005 "C:\Program Files\Java\j2re1.4.2_08\bin\jusched.exe"
    36975 Apr 13 2005 "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe"
    49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"


    end of report

  2. #12
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Double-click the FindAWF icon once again.
    • A command prompt will open and ask you to "Press any key to continue...".
    • You will be presented with a Menu.
    • Press 3 then 'Enter' to remove bak folders.
    • A text file named files.txt will then open.
    • Click below the line and copy/paste the following list of folders in the quote box into the text file:
    C:\Program Files\CCleaner\ccleaner.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Linksys EasyLink Advisor\LinksysAdvisor.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    • Close the text file and click Yes to save the changes.
    • When done, it automatically runs a new scan and opens a new log.
    • Please copy/paste the contents of the new awf.txt log in your reply.

  3. #13
    Join Date
    Mar 2008
    Posts
    9
    here is the next one

    Find AWF report by noahdfear ©2006
    Version 1.40
    Option 3 run successfully

    The current date is: Mon 03/10/2008
    The current time is: 1:51:02.01


    bak folders found
    ~~~~~~~~~~~


    Directory of C:\PROGRA~1\CCLEANER\BAK

    07/13/2007 04:10 AM 598,656 ccleaner.exe
    1 File(s) 598,656 bytes

    Directory of C:\PROGRA~1\ITUNES\BAK

    09/14/2007 10:00 AM 267,064 iTunesHelper.exe
    1 File(s) 267,064 bytes

    Directory of C:\PROGRA~1\LINKSY~1\BAK

    10/30/2006 11:01 AM 392,832 LinksysAgent.exe
    1 File(s) 392,832 bytes

    Directory of C:\PROGRA~1\MESSEN~1\BAK

    0 File(s) 0 bytes

    Directory of C:\PROGRA~1\QUICKT~1\BAK

    06/29/2007 06:24 AM 286,720 QTTask.exe
    1 File(s) 286,720 bytes

    Directory of C:\PROGRA~1\REGIST~1\BAK

    10/30/2006 01:12 PM 2,287,152 RegMech.exe
    1 File(s) 2,287,152 bytes

    Directory of C:\WINDOWS\SYSTEM32\BAK

    08/12/2004 08:56 AM 15,360 ctfmon.exe
    09/20/2005 09:32 AM 77,824 hkcmd.exe
    09/20/2005 09:36 AM 114,688 igfxpers.exe
    09/20/2005 09:35 AM 94,208 igfxtray.exe
    4 File(s) 302,080 bytes

    Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

    12/10/2006 09:52 PM 49,152 HPWuSchd2.exe
    1 File(s) 49,152 bytes

    Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK

    07/27/2004 04:50 PM 81,920 issch.exe
    1 File(s) 81,920 bytes

    Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

    07/12/2007 04:00 AM 132,496 jusched.exe
    1 File(s) 132,496 bytes


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    816368 Jan 17 2008 "C:\Program Files\CCleaner\ccleaner.exe"
    598656 Jul 13 2007 "C:\Program Files\CCleaner\bak\ccleaner.exe"
    267048 Feb 19 2008 "C:\Program Files\iTunes\iTunesHelper.exe"
    267064 Sep 14 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
    102400 Feb 27 2008 "C:\WINDOWS\Installer\{80FD852F-5AAC-4129-B931-06AAFFA43138}\iTunesIco.exe"
    75048 Feb 27 2008 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.1.9\iTunesSetupAdmin.exe"
    393344 Oct 30 2006 "C:\Program Files\Linksys EasyLink Advisor\LinksysAdvisor.exe"
    392832 Oct 30 2006 "C:\Program Files\Linksys EasyLink Advisor\bak\LinksysAgent.exe"
    385024 Feb 1 2008 "C:\Program Files\QuickTime\QTTask.exe"
    286720 Jun 29 2007 "C:\Program Files\QuickTime\bak\QTTask.exe"
    2287152 Oct 30 2006 "C:\Program Files\Registry Mechanic\RegMech.exe"
    2287152 Oct 30 2006 "C:\Program Files\Registry Mechanic\bak\RegMech.exe"
    15360 Aug 12 2004 "C:\WINDOWS\system32\ctfmon.exe"
    15360 Aug 12 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
    77824 Sep 20 2005 "C:\WINDOWS\system32\hkcmd.exe"
    77824 Sep 20 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
    114688 Sep 20 2005 "C:\WINDOWS\system32\igfxpers.exe"
    114688 Sep 20 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
    94208 Sep 20 2005 "C:\WINDOWS\system32\igfxtray.exe"
    94208 Sep 20 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
    49152 Dec 10 2006 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
    86960 Mar 20 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"
    81920 Jul 27 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe"
    32881 Mar 4 2005 "C:\Program Files\Java\j2re1.4.2_08\bin\jusched.exe"
    36975 Apr 13 2005 "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe"
    49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"


    end of report

  4. #14
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    magi58, I owe you a HUGE apology, I gave the wrong instructions on the last step this is a new tool for me too. Hope you will have patience with me and continue. You will need to do this last step again.

    Double-click the FindAWF icon once again.
    • A command prompt will open and ask you to "Press any key to continue...".
    • You will be presented with a Menu.
    • Press 3 then 'Enter' to remove bak folders.
    • A text file named files.txt will then open.
    • Click below the line and copy/paste the following list of folders in the quote box into the text file:
    C:\Program Files\iTunes\bak
    C:\Program Files\CCleaner\bak
    C:\Program Files\Linksys EasyLink Advisor\bak
    C:\Program Files\QuickTime\bak
    C:\Program Files\Registry Mechanic\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\Program Files\HP\HP Software Update\bak
    C:\Program Files\Common Files\InstallShield\UpdateService\bak
    • Close the text file and click Yes to save the changes.
    • When done, it automatically runs a new scan and opens a new log.
    • Please copy/paste the contents of the new awf.txt log in your reply.
    Again I apologize. Hope you will have patience with me and continue.
    Judy

  5. #15
    Join Date
    Mar 2008
    Posts
    9
    here you go and its no problem unless it messes up my computer to no end @_@

    Find AWF report by noahdfear ©2006
    Version 1.40
    Option 3 run successfully

    The current date is: Mon 03/10/2008
    The current time is: 14:26:02.59


    bak folders found
    ~~~~~~~~~~~


    Directory of C:\PROGRA~1\MESSEN~1\BAK

    0 File(s) 0 bytes

    Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

    07/12/2007 04:00 AM 132,496 jusched.exe
    1 File(s) 132,496 bytes


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    32881 Mar 4 2005 "C:\Program Files\Java\j2re1.4.2_08\bin\jusched.exe"
    36975 Apr 13 2005 "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe"
    49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"


    end of report

  6. #16
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Double-click the FindAWF icon once again.
    • A command prompt will open and ask you to "Press any key to continue...".
    • You will be presented with a Menu.
    • Press 4 then 'Enter' to reset domain zones.
    • You will receive a warning to reset domain zones.
    • Press 1 then 'Enter'.
    • When done, you will receive a message: "Done! Zones have been reset".
    • After resetting the domain zones, the program will return to the main menu.
    • Press E then 'Enter' to EXIT.
    • Note: If you had manually added any sites in the trusted zones, they will need to be re-inserted.
    After that then if you have not done so, Please download ATF Cleaner by Atribune & save it to your desktop.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main "Select Files to Delete" choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords, please click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords, please click No at the prompt.
    • Click Exit on the Main menu to close the program.
    Do that and then reboot and run one more HJT scan and post the log here.
    Judy

  7. #17
    Join Date
    Mar 2008
    Posts
    9
    Here you go
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:42:14 PM, on 3/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
    C:\analize.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /S
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1134437796250
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/...jolauncher.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/6...l/gtdownls.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{00D3E441-1287-45F4-87BA-CBB5DEBF8FF5}: NameServer = 151.164.1.8,206.13.28.12
    O20 - AppInit_DLLs: cru629.dat
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

    --
    End of file - 10280 bytes

  8. #18
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, this log looks much better BUT...I still do not see an active anti-virus program OR a firewall on the computer...ABSOLUTE MUSTS
    There are several very good FREE anti-virus programs available and linked in PROTECT YOURSELF FROM MALWARE: Tools & Tips

    You absolutely MUST download, install, update and USE one of those free anti-virus programs to keep your computer clean. For a Firewall you can either choose to enable the built in Windows Firewall or choose one of those linked on the above thread. But until you begin protecting your computer with these two items you WILL be infected again.

    Another thing you have to do is go to Add/Remove and Uninstall all of the old versions of Java on the machine, you are showing that you have 7 old versions on the machine. You need to install the newest version which is SunJava version 6 update 5
    Choose the offline download. Download to the desktop, uninstall the old versions, install the new one and verify the installation by going here

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •