Source : Google Reader
Wednesday, 4 May 2011
Xplorer²
Xplorer²: "Lightweight yet powerful tabbed dual pane file and information manager."
LibreOffice
LibreOffice: "A free open source personal productivity suite based on OpenOffice.org that offers six feature-rich applications to handle all of your document production and data processing needs"
Source : Google Reader
EarthView
EarthView: "A dynamic desktop wallpaper and screen saver that displays beautiful views of the earth with daylight and night shadows."
Source : Google Reader
Serv-U
Serv-U: "Serv-U is a powerful, easy-to-use, award-winning File Server from RhinoSoft.com."
Source : Google Reader
How to check if your PC is protected?
How to check if your PC is protected?: "
Have you noticed that your computer is running slow recently? Or maybe it's just behaving weirdly or not following commands. It could be that you've picked up a computer virus. In this case it is a good idea to scan your machine for the presence of an infection. Here are ways that you can carry out a free virus scan.
The first way that you can do this is to use an online scanner. These are websites that will allow you to use their service to find infections on their machine. Usually these are available free of charge. Ensure that you go to a reputable company website as there are some rogue traders in this field. McAfee and BitDefender have online scanners available for you to use.
The second way for you to carry out a virus scan for free is to download a free antivirus product. There are numerous products that you could try. AVG Antivirus free edition is a good product to choose. As well as allowing you to scan your PC it will also remove any problems that it finds free of charge.
The final way that you can carry out a free scan is to find the website of a premium (paid for) antivirus product, then take advantage of their free trial. Again there are numerous companies that will allow you to do this. For instance, Eset has a 30-day free trial of their well-regarded NOD32 product. This will allow you scan your computer for viruses and see if you like the software enough to buy in the future.
Once you have carried out your free virus scan you should think about how you are going to regularly check your system for problems in the future. Some of the latest software can be pre-programmed to carry out regular scans for you, so you know that you are always protected.
"The first way that you can do this is to use an online scanner. These are websites that will allow you to use their service to find infections on their machine. Usually these are available free of charge. Ensure that you go to a reputable company website as there are some rogue traders in this field. McAfee and BitDefender have online scanners available for you to use.
The second way for you to carry out a virus scan for free is to download a free antivirus product. There are numerous products that you could try. AVG Antivirus free edition is a good product to choose. As well as allowing you to scan your PC it will also remove any problems that it finds free of charge.
The final way that you can carry out a free scan is to find the website of a premium (paid for) antivirus product, then take advantage of their free trial. Again there are numerous companies that will allow you to do this. For instance, Eset has a 30-day free trial of their well-regarded NOD32 product. This will allow you scan your computer for viruses and see if you like the software enough to buy in the future.
Once you have carried out your free virus scan you should think about how you are going to regularly check your system for problems in the future. Some of the latest software can be pre-programmed to carry out regular scans for you, so you know that you are always protected.
Source : Google Reader
please open thread dated 02-04-2011
please open thread dated 02-04-2011: "
Hi
Please could you reopen the thread dated 02-04-2011 under username yellow4.
Many Thanks
below are my logs from the last thread you sent if that helps or I can post them again when you reopen the thread.
All processes killed
Error: Unable to interpret <Code:> in the current context!
Error: Unable to interpret <---------> in the current context!
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851 A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851 A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8 A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_USERS\S-1-5-21-1170690294-4168336947-2637714527-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{71576546-354D-41C9-AAE8-31F2EC22BF0D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7157654 6-354D-41C9-AAE8-31F2EC22BF0D}\ not found.
File move failed. C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
File move failed. C:\Users\lydia\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\Dell Dock.lnk scheduled to be moved on reboot.
Starting removal of ActiveX control {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D 5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D 5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8 F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8 F-472F-4FB0-9522-AC9BF37916A7}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717 E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717 E-7E19-11d0-97EE-00C04FD91972}\ not found.
File/Folder C:\Users\lydia\Documents\*.tmp not found.
File/Folder C:\Users\lydia\AppData\Local\*.tmp not found.
Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 .
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
->Temp folder emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: lydia
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7943818 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11762 bytes
%systemroot%\sysnative\config\systemprofile\AppDat a\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppDat a\LocalLow\Sun\Java\Deployment folder emptied: 243 bytes
RecycleBin emptied: 1819302477 bytes
Total Files Cleaned = 1,743.00 mb
[EMPTYFLASH]
User: All Users
User: AppData
User: Default
User: Default User
User: lydia
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.22.2 log created on 04182011_160107
Files\Folders moved on Reboot...
File\Folder C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
File\Folder C:\Users\lydia\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\Dell Dock.lnk not found!
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PXAD120E\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PERXZ1QR\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\77950H5G\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2BP0W27F\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ LocalLow\Sun\Java\Deployment\deployment.properties scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Results of screen317's Security Check version 0.99.7
Windows Vista (UAC is enabled)
Out of date service pack!!
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
avast! Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java(TM) 6 Update 24
Out of date Java installed!
Adobe Flash Player
Adobe Reader 9.1
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Alwil Software Avast4 aswUpdSv.exe
Alwil Software Avast4 ashServ.exe
Alwil Software Avast4 ashDisp.exe
Alwil Software Avast4 ashMaiSv.exe
Alwil Software Avast4 ashWebSv.exe
``````````End of Log````````````
"Please could you reopen the thread dated 02-04-2011 under username yellow4.
Many Thanks
below are my logs from the last thread you sent if that helps or I can post them again when you reopen the thread.
All processes killed
Error: Unable to interpret <Code:> in the current context!
Error: Unable to interpret <---------> in the current context!
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851 A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851 A-3207-45A2-B947-BE8AFE6163AB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8 A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_USERS\S-1-5-21-1170690294-4168336947-2637714527-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{71576546-354D-41C9-AAE8-31F2EC22BF0D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7157654 6-354D-41C9-AAE8-31F2EC22BF0D}\ not found.
File move failed. C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
File move failed. C:\Users\lydia\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\Dell Dock.lnk scheduled to be moved on reboot.
Starting removal of ActiveX control {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D 5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D 5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8 F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8 F-472F-4FB0-9522-AC9BF37916A7}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717 E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717 E-7E19-11d0-97EE-00C04FD91972}\ not found.
File/Folder C:\Users\lydia\Documents\*.tmp not found.
File/Folder C:\Users\lydia\AppData\Local\*.tmp not found.
Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 .
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
->Temp folder emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: lydia
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7943818 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11762 bytes
%systemroot%\sysnative\config\systemprofile\AppDat a\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppDat a\LocalLow\Sun\Java\Deployment folder emptied: 243 bytes
RecycleBin emptied: 1819302477 bytes
Total Files Cleaned = 1,743.00 mb
[EMPTYFLASH]
User: All Users
User: AppData
User: Default
User: Default User
User: lydia
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.22.2 log created on 04182011_160107
Files\Folders moved on Reboot...
File\Folder C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
File\Folder C:\Users\lydia\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\Dell Dock.lnk not found!
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PXAD120E\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PERXZ1QR\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\77950H5G\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2BP0W27F\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\ LocalLow\Sun\Java\Deployment\deployment.properties scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Results of screen317's Security Check version 0.99.7
Windows Vista (UAC is enabled)
Out of date service pack!!
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
avast! Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java(TM) 6 Update 24
Out of date Java installed!
Adobe Flash Player
Adobe Reader 9.1
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Alwil Software Avast4 aswUpdSv.exe
Alwil Software Avast4 ashServ.exe
Alwil Software Avast4 ashDisp.exe
Alwil Software Avast4 ashMaiSv.exe
Alwil Software Avast4 ashWebSv.exe
``````````End of Log````````````
Source : Google Reader
Need new monitor....
Need new monitor....: "
I'm looking to buy a new monitor, my old one is going. I never had a flat screen, not sure which one to look into. They have, LCD, LED, and also HD, any info on which one would be better? Thanks.....
"Source : Google Reader
[Active] Infected PC
[Active] Infected PC: "
I recieved an email from an old contact today asking me to stop sending him spam emails. These are apparently being sent unknowingly from my personal email account. I am using Thunderbird (current version) as my email program, using Eset SmartSecurity for virus protection, running WinXP Pro. All software is current and up to date. I have run virus scan several times with nothing detected. Have run SpyBot and Malware Bytes. Spyboy found a few things, malware bytes found nothing. Not sure what to do next. Can you help please?
"Source : Google Reader
Can't read hard drive and RAM memory usage is critically high
Can't read hard drive and RAM memory usage is critically high: "
I got the RAM memory usage is critically high message and a scanning program started asking to defrag my hard drive. I went through all your steps and my computer seems to be acting normal but all my saved stuff on my hard drive is gone. Is there anyway to get that information? Here are all the logs with the exception of the gmer log because there was no information when it was through scanning.
Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: 6470
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
4/29/2011 9:21:25 PM
mbam-log-2011-04-29 (21-21-25).txt
Scan type: Quick scan
Objects scanned: 159068
Time elapsed: 4 minute(s), 30 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5
Memory Processes Infected:
c:\programdata\gtadumrjbjxcvqd.exe (Trojan.FakeAlert) -> 2852 -> Unloaded process successfully.
c:\programdata\49405704.exe (Trojan.FakeAlert) -> 3824 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\gTADumrjbJxcVqD (Trojan.FakeAlert) -> Value: gTADumrjbJxcVqD -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery (Trojan.FakeAV) -> Quarantined and deleted successfully.
Files Infected:
c:\programdata\gtadumrjbjxcvqd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\49405704.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chris\Desktop\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery\uninstall windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6700 Notebook PC
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 150):
0x01C54000 \SystemRoot\system32\ntoskrnl.exe
0x01C0E000 \SystemRoot\system32\hal.dll
0x00607000 \SystemRoot\system32\kdcom.dll
0x00611000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064C000 \SystemRoot\system32\PSHED.dll
0x00660000 \SystemRoot\system32\CLFS.SYS
0x006BD000 \SystemRoot\system32\CI.dll
0x0080E000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008B2000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x008C1000 \SystemRoot\system32\drivers\acpi.sys
0x00917000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00920000 \SystemRoot\system32\drivers\msisadrv.sys
0x0092A000 \SystemRoot\system32\drivers\pci.sys
0x0095A000 \SystemRoot\System32\drivers\partmgr.sys
0x0096F000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00973000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x0097F000 \SystemRoot\system32\drivers\volmgr.sys
0x00993000 \SystemRoot\System32\drivers\volmgrx.sys
0x00800000 \SystemRoot\system32\drivers\intelide.sys
0x0076F000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x0077F000 \SystemRoot\System32\drivers\mountmgr.sys
0x00A05000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x00B09000 \SystemRoot\system32\drivers\atapi.sys
0x00B11000 \SystemRoot\system32\drivers\ataport.SYS
0x00B35000 \SystemRoot\system32\drivers\msahci.sys
0x00B3F000 \SystemRoot\system32\drivers\fltmgr.sys
0x00B86000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C05000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E0D000 \SystemRoot\system32\drivers\ndis.sys
0x00C8C000 \SystemRoot\system32\drivers\msrpc.sys
0x00CDC000 \SystemRoot\system32\drivers\NETIO.SYS
0x01000000 \SystemRoot\System32\drivers\tcpip.sys
0x01176000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0120D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0138D000 \SystemRoot\system32\drivers\volsnap.sys
0x013D1000 \SystemRoot\System32\Drivers\spldr.sys
0x013D9000 \SystemRoot\System32\Drivers\mup.sys
0x011A2000 \SystemRoot\System32\drivers\ecache.sys
0x013EB000 \SystemRoot\system32\drivers\disk.sys
0x011CE000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x01200000 \SystemRoot\system32\drivers\crcdisk.sys
0x02313000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0231F000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x02328000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x0232D000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x02336000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02403000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x02E00000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02EE3000 \SystemRoot\System32\drivers\watchdog.sys
0x02EF3000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02EFF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02F45000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x02C04000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0320E000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
0x036A0000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
0x036C5000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x036D7000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x036E7000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x03707000 \SystemRoot\system32\DRIVERS\rimmpx64.sys
0x0371B000 \SystemRoot\system32\DRIVERS\rimspx64.sys
0x03732000 \SystemRoot\system32\DRIVERS\rixdpx64.sys
0x03789000 \SystemRoot\system32\DRIVERS\HpqRemHid.sys
0x0378C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x0379E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x037A6000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x037BC000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x037C8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x02CF1000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x037D6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x037D8000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x037E4000 \SystemRoot\SysWOW64\drivers\Afc.sys
0x02D44000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x037ED000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x02D60000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x02D99000 \SystemRoot\system32\DRIVERS\storport.sys
0x03200000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02F56000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x02F79000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x02F85000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x02FB6000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02FC6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x02FE4000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x02B5E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x037FA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02B71000 \SystemRoot\system32\DRIVERS\ks.sys
0x02BA5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02BB0000 \SystemRoot\system32\DRIVERS\umbus.sys
0x02349000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x02BC0000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x02BCB000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06006000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06132000 \SystemRoot\system32\drivers\portcls.sys
0x0616D000 \SystemRoot\system32\drivers\drmk.sys
0x06190000 \SystemRoot\system32\drivers\ksthunk.sys
0x06401000 \SystemRoot\system32\DRIVERS\smserial.sys
0x06535000 \SystemRoot\system32\drivers\modem.sys
0x06544000 \SystemRoot\system32\drivers\MODEMCSA.sys
0x06551000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x0655B000 \SystemRoot\System32\Drivers\Null.SYS
0x06564000 \SystemRoot\System32\drivers\vga.sys
0x06572000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x06597000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x065A0000 \SystemRoot\system32\drivers\rdpencdd.sys
0x065A9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x065B4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x065C5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x065CE000 \SystemRoot\system32\DRIVERS\tdx.sys
0x06196000 \SystemRoot\system32\DRIVERS\smb.sys
0x02391000 \SystemRoot\system32\drivers\afd.sys
0x061B1000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02BDF000 \SystemRoot\system32\DRIVERS\pacer.sys
0x065EB000 \SystemRoot\system32\DRIVERS\netbios.sys
0x00FDE000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x00D35000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02200000 \SystemRoot\system32\drivers\nsiproxy.sys
0x00D82000 \SystemRoot\System32\Drivers\dfsc.sys
0x00D9F000 \SystemRoot\SysWOW64\drivers\archlp.sys
0x0220C000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x061F5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x02228000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x02233000 \SystemRoot\System32\Drivers\usbvideo.sys
0x0225D000 \SystemRoot\system32\DRIVERS\udfs.sys
0x022AB000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06609000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x0670D000 \SystemRoot\System32\drivers\Dxapi.sys
0x06719000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00410000 \SystemRoot\System32\TSDDD.dll
0x00690000 \SystemRoot\System32\cdd.dll
0x00800000 \SystemRoot\system32\drivers\intelide.sys
0x0672C000 \SystemRoot\system32\drivers\luafv.sys
0x0674E000 \SystemRoot\system32\drivers\spsys.sys
0x067E8000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x022B9000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x022ED000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x022F8000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x17605000 \SystemRoot\system32\drivers\HTTP.sys
0x176A8000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x176D1000 \SystemRoot\system32\DRIVERS\bowser.sys
0x176EF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x17709000 \SystemRoot\system32\drivers\mrxdav.sys
0x17730000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x17759000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x177A2000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x177C1000 \SystemRoot\System32\DRIVERS\srv2.sys
0x17802000 \SystemRoot\System32\DRIVERS\srv.sys
0x17895000 \SystemRoot\system32\drivers\peauth.sys
0x1794B000 \SystemRoot\System32\Drivers\secdrv.SYS
0x17956000 \SystemRoot\System32\drivers\tcpipreg.sys
0x76F00000 \WINDOWS\System32\ntdll.dll
Processes (total 76):
0 System Idle Process
4 System
480 C:\WINDOWS\System32\smss.exe
612 csrss.exe
648 C:\WINDOWS\System32\wininit.exe
668 csrss.exe
704 C:\WINDOWS\System32\services.exe
720 C:\WINDOWS\System32\lsass.exe
728 C:\WINDOWS\System32\lsm.exe
808 C:\WINDOWS\System32\winlogon.exe
908 C:\WINDOWS\System32\svchost.exe
968 C:\WINDOWS\System32\svchost.exe
1020 C:\WINDOWS\System32\svchost.exe
352 C:\WINDOWS\System32\svchost.exe
500 C:\WINDOWS\System32\svchost.exe
568 C:\WINDOWS\System32\svchost.exe
896 C:\WINDOWS\System32\audiodg.exe
368 C:\WINDOWS\System32\SLsvc.exe
1052 C:\WINDOWS\System32\svchost.exe
1164 C:\WINDOWS\System32\svchost.exe
1348 C:\WINDOWS\System32\spoolsv.exe
1372 C:\WINDOWS\System32\svchost.exe
1560 C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
1588 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1832 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1880 C:\WINDOWS\System32\svchost.exe
1892 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
1996 C:\WINDOWS\System32\taskeng.exe
2036 C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
768 C:\WINDOWS\System32\svchost.exe
1108 C:\WINDOWS\System32\svchost.exe
2040 C:\WINDOWS\System32\SearchIndexer.exe
2108 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
2324 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
2600 C:\WINDOWS\System32\dwm.exe
2620 C:\WINDOWS\System32\taskeng.exe
2660 C:\WINDOWS\explorer.exe
2912 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2928 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
2956 C:\WINDOWS\RAVCpl64.exe
2980 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3008 C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
3032 C:\Program Files\Windows Defender\MSASCui.exe
3064 C:\WINDOWS\System32\hkcmd.exe
1172 C:\WINDOWS\System32\igfxpers.exe
1112 C:\WINDOWS\ehome\ehtray.exe
2456 C:\Program Files (x86)\HP\QuickPlay\QPService.exe
2644 C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
2816 C:\WINDOWS\System32\igfxsrvc.exe
3084 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
3140 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
3152 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3160 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
3172 C:\WINDOWS\ehome\ehmsas.exe
3192 C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
3200 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
3236 C:\Program Files (x86)\iTunes\iTunesHelper.exe
3296 WmiPrvSE.exe
3724 C:\Program Files\iPod\bin\iPodService.exe
3968 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
2412 C:\Program Files\Windows Media Player\wmpnscfg.exe
1956 C:\Program Files\Windows Media Player\wmpnetwk.exe
3912 C:\WINDOWS\System32\svchost.exe
2120 C:\WINDOWS\System32\SearchProtocolHost.exe
2420 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2296 C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
2948 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
4740 C:\WINDOWS\System32\wuauclt.exe
4092 MpCmdRun.exe
1268 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
3600 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
3920 C:\WINDOWS\explorer.exe
4524 C:\WINDOWS\System32\SearchFilterHost.exe
1476 dllhost.exe
4180 dllhost.exe
1556 C:\Users\Chris\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000047`507bec00 (NTFS)
PhysicalDrive0 Model Number: FUJITSUMHZ2320BHG2, Rev: 8909
Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Chris at 21:47:51.92 on Fri 04/29/2011
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_24
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4085.2456 [GMT 10:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Chris\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.ex e" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
mRun: [DivX Download Manager] "C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe" start
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\TOTALM~1.LNK - C:\Program Files (x86)\ArcSoft\TotalMedia Extreme 2\BackUp & Recorder\uBBMonitor.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TB-X64: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
mRun-x64: [RtHDVCpl] RAVCpl64.exe
mRun-x64: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe"
mRun-x64: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Pro files\vhwhn7mq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Pro files\vhwhn7mq.default\extensions\engine@conduit.c om\components\RadioWMPCoreGecko19.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
R3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw5v64.sys [2008-11-17 4751360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 hcwhdpvr;Hauppauge HD PVR Capture Device;C:\WINDOWS\System32\drivers\hcwhdpvr.sys [2011-1-18 189440]
S3 NETw4v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw4v64.sys [2008-6-18 3148288]
S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2008-5-7 14464]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework6 4\v2.0.50727\mscorsvw.exe [2011-1-20 89920]
.
=============== File Associations ===============
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-04-29 11:15:40 -------- d--h--w- C:\Users\Chris\AppData\Roaming\Malwarebytes
2011-04-29 11:15:32 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-29 11:15:32 -------- d--h--w- C:\PROGRA~3\Malwarebytes
2011-04-29 11:15:29 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-04-29 11:15:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-29 10:50:30 8802128 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{64D7CDFD-B08E-4BB2-B97C-0548E5FD1965}\mpengine.dll
2011-04-20 12:51:15 40960 ---ha-r- C:\Users\Chris\AppData\Roaming\Microsoft\Installer \{ECF8D4B4-FADB-492E-A79A-5BCEA02DB95D}\NewShortcut1_0D8BB549999E4288839DD9D F4569C1EC.exe
2011-04-20 12:51:10 -------- d-----w- C:\Program Files (x86)\2d3
2011-04-20 12:50:51 296448 ----a-w- C:\Windows\System32\drivers\hardlock.sys
2011-04-20 12:50:49 24576 ----a-w- C:\Windows\SysWow64\hdsuinst.exe
2011-04-20 12:50:49 2164411 ----a-w- C:\Windows\SysWow64\haspds_windows.dll
2011-04-20 12:50:49 164864 ----a-w- C:\Windows\SysWow64\UNWISE.EXE
2011-04-20 12:29:52 -------- d--h--w- C:\PROGRA~3\SafeNet Sentinel
2011-04-20 12:29:43 -------- d-----w- C:\Program Files (x86)\Vicon
2011-04-18 12:49:05 -------- d--h--w- C:\Users\Chris\dwhelper
2011-04-18 12:41:32 307200 ----a-w- C:\Windows\SysWow64\TubeFinder.exe
2011-04-18 12:41:31 9728 ----a-w- C:\Windows\SysWow64\PCCLPFR.DLL
2011-04-18 12:41:31 84512 ----a-w- C:\Windows\SysWow64\PICCLP32.OCX
2011-04-18 12:41:31 364544 ----a-w- C:\Windows\SysWow64\PropertyGrid.ocx
2011-04-18 12:41:31 119568 ----a-w- C:\Windows\SysWow64\VB6FR.DLL
2011-04-18 12:41:31 101888 ----a-w- C:\Windows\SysWow64\VB6STKIT.DLL
2011-04-18 12:41:30 32768 ----a-w- C:\Windows\SysWow64\CMDLGFR.DLL
2011-04-18 12:41:30 24576 ----a-w- C:\Windows\SysWow64\ControlSubX.ocx
2011-04-18 12:41:30 141312 ----a-w- C:\Windows\SysWow64\MSCMCFR.DLL
2011-04-18 12:41:30 -------- d--h--w- C:\Users\Chris\AppData\Roaming\FreeFLVConverter
2011-04-18 12:41:30 -------- d-----w- C:\Program Files (x86)\Free FLV Converter
2011-04-17 16:12:57 -------- d-----w- C:\Program Files\MAXON
2011-04-17 16:10:16 -------- d--h--w- C:\Users\Chris\AppData\Roaming\MAXON
2011-04-17 13:05:38 -------- d--h--w- C:\AdobeTemp
2011-04-13 00:30:10 450560 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-04-13 00:30:10 176128 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-13 00:30:10 145920 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-13 00:30:04 991104 ----a-w- C:\Windows\System32\winresume.efi
2011-04-13 00:30:04 979840 ----a-w- C:\Windows\System32\winresume.exe
2011-04-13 00:30:04 1076608 ----a-w- C:\Windows\System32\winload.efi
2011-04-13 00:30:04 1063296 ----a-w- C:\Windows\System32\winload.exe
2011-04-13 00:30:03 20864 ----a-w- C:\Windows\System32\kdusb.dll
2011-04-13 00:30:03 18816 ----a-w- C:\Windows\System32\kd1394.dll
2011-04-13 00:30:03 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-04-13 00:29:22 603136 ----a-w- C:\Windows\System32\vbscript.dll
2011-04-13 00:29:22 430080 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-04-13 00:29:13 274432 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-04-13 00:29:12 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-04-13 00:29:12 135680 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-04-13 00:29:12 106496 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-04-13 00:29:03 975872 ----a-w- C:\Windows\System32\inetcomm.dll
2011-04-13 00:29:03 739328 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-04-05 22:04:47 -------- d-----w- C:\Program Files\iPod
2011-04-05 22:04:46 -------- d-----w- C:\Program Files\iTunes
2011-04-05 22:04:46 -------- d-----w- C:\Program Files (x86)\iTunes
.
==================== Find3M ====================
.
2011-03-28 16:33:34 73216 ----a-w- C:\Windows\SysWow64\ff_vfw.dll
2011-03-20 23:58:04 152064 ----a-w- C:\Windows\SysWow64\xvid.ax
2011-03-19 01:06:02 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2011-03-19 01:04:28 650752 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2011-03-10 17:18:03 1360384 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-10 17:18:02 1398784 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-10 17:03:51 1162240 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-03 13:46:31 2762240 ----a-w- C:\Windows\System32\win32k.sys
2011-03-02 16:12:21 117760 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-02-27 18:00:00 1003520 ----a-w- C:\Windows\SysWow64\VSFilter.dll
2011-02-22 14:47:08 479744 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-02-22 14:13:01 288768 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-02-22 13:53:33 1555968 ----a-w- C:\Windows\System32\DWrite.dll
2011-02-22 13:53:27 1149440 ----a-w- C:\Windows\System32\FntCache.dll
2011-02-22 13:33:12 1068544 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-18 16:50:48 1032192 ----a-w- C:\Windows\System32\wininet.dll
2011-02-18 16:38:42 834048 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-02-18 15:55:33 86528 ----a-w- C:\Windows\System32\ieencode.dll
2011-02-18 15:45:02 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2011-02-18 15:19:20 485376 ----a-w- C:\Windows\System32\html.iec
2011-02-18 14:49:21 389632 ----a-w- C:\Windows\SysWow64\html.iec
2011-02-18 06:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 06:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-02-16 16:37:47 48128 ----a-w- C:\Windows\System32\atmlib.dll
2011-02-16 16:16:37 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-02-16 14:15:24 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-02-16 14:02:23 292864 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-02-10 07:51:58 3075072 ----a-w- C:\Windows\SysWow64\x264vfw.dll
2011-02-02 11:40:23 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-02-02 08:11:20 270720 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 21:48:13.33 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/18/2008 2:53:32 AM
System Uptime: 4/29/2011 9:22:24 PM (0 hours ago)
.
Motherboard: Quanta | | 30CC
Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz | U2E1 | 2000/667mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 142.042 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 2.44 GiB free.
E: is CDROM (UDF)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Media Player
Adobe Reader 8.1.0
Apple Application Support
Apple Software Update
ArcSoft TotalMedia Extreme
BitTorrent
BitTorrentBar Toolbar
boujou 4
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conduit Engine
CyberLink YouCam
DVD Suite
EA Link
Free FLV Converter V 6.96.0
HASP HL Device Driver
Hauppauge HDPVR Scheduler
Hauppauge WinTV IR Blaster
Hauppauge WinTV Scheduler
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.30 E1
HP QuickPlay 3.6
HP Smart Web Printing
HP Update
HP User Guides 0087
HP Wireless Assistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
Java Auto Updater
Java(TM) 6 Update 2
Java(TM) 6 Update 24
LabelPrint
LiveUpdate (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox 4.0 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.6
QuickTime
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Slingbox Flash Tour
SlingPlayer
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Office 2007 (KB934528)
Vicon boujou 5.0
VideoToolkit01
Viewpoint Media Player
Vista Codec Package
.
==== End Of File ===========================
"Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: 6470
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
4/29/2011 9:21:25 PM
mbam-log-2011-04-29 (21-21-25).txt
Scan type: Quick scan
Objects scanned: 159068
Time elapsed: 4 minute(s), 30 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5
Memory Processes Infected:
c:\programdata\gtadumrjbjxcvqd.exe (Trojan.FakeAlert) -> 2852 -> Unloaded process successfully.
c:\programdata\49405704.exe (Trojan.FakeAlert) -> 3824 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\gTADumrjbJxcVqD (Trojan.FakeAlert) -> Value: gTADumrjbJxcVqD -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery (Trojan.FakeAV) -> Quarantined and deleted successfully.
Files Infected:
c:\programdata\gtadumrjbjxcvqd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\49405704.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chris\Desktop\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery\uninstall windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
c:\Users\Chris\AppData\Roaming\microsoft\Windows\s tart menu\Programs\windows recovery\windows recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6700 Notebook PC
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 150):
0x01C54000 \SystemRoot\system32\ntoskrnl.exe
0x01C0E000 \SystemRoot\system32\hal.dll
0x00607000 \SystemRoot\system32\kdcom.dll
0x00611000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064C000 \SystemRoot\system32\PSHED.dll
0x00660000 \SystemRoot\system32\CLFS.SYS
0x006BD000 \SystemRoot\system32\CI.dll
0x0080E000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008B2000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x008C1000 \SystemRoot\system32\drivers\acpi.sys
0x00917000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00920000 \SystemRoot\system32\drivers\msisadrv.sys
0x0092A000 \SystemRoot\system32\drivers\pci.sys
0x0095A000 \SystemRoot\System32\drivers\partmgr.sys
0x0096F000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00973000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x0097F000 \SystemRoot\system32\drivers\volmgr.sys
0x00993000 \SystemRoot\System32\drivers\volmgrx.sys
0x00800000 \SystemRoot\system32\drivers\intelide.sys
0x0076F000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x0077F000 \SystemRoot\System32\drivers\mountmgr.sys
0x00A05000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x00B09000 \SystemRoot\system32\drivers\atapi.sys
0x00B11000 \SystemRoot\system32\drivers\ataport.SYS
0x00B35000 \SystemRoot\system32\drivers\msahci.sys
0x00B3F000 \SystemRoot\system32\drivers\fltmgr.sys
0x00B86000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C05000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E0D000 \SystemRoot\system32\drivers\ndis.sys
0x00C8C000 \SystemRoot\system32\drivers\msrpc.sys
0x00CDC000 \SystemRoot\system32\drivers\NETIO.SYS
0x01000000 \SystemRoot\System32\drivers\tcpip.sys
0x01176000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0120D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0138D000 \SystemRoot\system32\drivers\volsnap.sys
0x013D1000 \SystemRoot\System32\Drivers\spldr.sys
0x013D9000 \SystemRoot\System32\Drivers\mup.sys
0x011A2000 \SystemRoot\System32\drivers\ecache.sys
0x013EB000 \SystemRoot\system32\drivers\disk.sys
0x011CE000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x01200000 \SystemRoot\system32\drivers\crcdisk.sys
0x02313000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0231F000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x02328000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x0232D000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x02336000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02403000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x02E00000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02EE3000 \SystemRoot\System32\drivers\watchdog.sys
0x02EF3000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02EFF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02F45000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x02C04000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0320E000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
0x036A0000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
0x036C5000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x036D7000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x036E7000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x03707000 \SystemRoot\system32\DRIVERS\rimmpx64.sys
0x0371B000 \SystemRoot\system32\DRIVERS\rimspx64.sys
0x03732000 \SystemRoot\system32\DRIVERS\rixdpx64.sys
0x03789000 \SystemRoot\system32\DRIVERS\HpqRemHid.sys
0x0378C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x0379E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x037A6000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x037BC000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x037C8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x02CF1000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x037D6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x037D8000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x037E4000 \SystemRoot\SysWOW64\drivers\Afc.sys
0x02D44000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x037ED000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x02D60000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x02D99000 \SystemRoot\system32\DRIVERS\storport.sys
0x03200000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02F56000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x02F79000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x02F85000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x02FB6000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02FC6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x02FE4000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x02B5E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x037FA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02B71000 \SystemRoot\system32\DRIVERS\ks.sys
0x02BA5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02BB0000 \SystemRoot\system32\DRIVERS\umbus.sys
0x02349000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x02BC0000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x02BCB000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06006000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06132000 \SystemRoot\system32\drivers\portcls.sys
0x0616D000 \SystemRoot\system32\drivers\drmk.sys
0x06190000 \SystemRoot\system32\drivers\ksthunk.sys
0x06401000 \SystemRoot\system32\DRIVERS\smserial.sys
0x06535000 \SystemRoot\system32\drivers\modem.sys
0x06544000 \SystemRoot\system32\drivers\MODEMCSA.sys
0x06551000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x0655B000 \SystemRoot\System32\Drivers\Null.SYS
0x06564000 \SystemRoot\System32\drivers\vga.sys
0x06572000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x06597000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x065A0000 \SystemRoot\system32\drivers\rdpencdd.sys
0x065A9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x065B4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x065C5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x065CE000 \SystemRoot\system32\DRIVERS\tdx.sys
0x06196000 \SystemRoot\system32\DRIVERS\smb.sys
0x02391000 \SystemRoot\system32\drivers\afd.sys
0x061B1000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02BDF000 \SystemRoot\system32\DRIVERS\pacer.sys
0x065EB000 \SystemRoot\system32\DRIVERS\netbios.sys
0x00FDE000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x00D35000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02200000 \SystemRoot\system32\drivers\nsiproxy.sys
0x00D82000 \SystemRoot\System32\Drivers\dfsc.sys
0x00D9F000 \SystemRoot\SysWOW64\drivers\archlp.sys
0x0220C000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x061F5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x02228000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x02233000 \SystemRoot\System32\Drivers\usbvideo.sys
0x0225D000 \SystemRoot\system32\DRIVERS\udfs.sys
0x022AB000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06609000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x0670D000 \SystemRoot\System32\drivers\Dxapi.sys
0x06719000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00410000 \SystemRoot\System32\TSDDD.dll
0x00690000 \SystemRoot\System32\cdd.dll
0x00800000 \SystemRoot\system32\drivers\intelide.sys
0x0672C000 \SystemRoot\system32\drivers\luafv.sys
0x0674E000 \SystemRoot\system32\drivers\spsys.sys
0x067E8000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x022B9000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x022ED000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x022F8000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x17605000 \SystemRoot\system32\drivers\HTTP.sys
0x176A8000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x176D1000 \SystemRoot\system32\DRIVERS\bowser.sys
0x176EF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x17709000 \SystemRoot\system32\drivers\mrxdav.sys
0x17730000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x17759000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x177A2000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x177C1000 \SystemRoot\System32\DRIVERS\srv2.sys
0x17802000 \SystemRoot\System32\DRIVERS\srv.sys
0x17895000 \SystemRoot\system32\drivers\peauth.sys
0x1794B000 \SystemRoot\System32\Drivers\secdrv.SYS
0x17956000 \SystemRoot\System32\drivers\tcpipreg.sys
0x76F00000 \WINDOWS\System32\ntdll.dll
Processes (total 76):
0 System Idle Process
4 System
480 C:\WINDOWS\System32\smss.exe
612 csrss.exe
648 C:\WINDOWS\System32\wininit.exe
668 csrss.exe
704 C:\WINDOWS\System32\services.exe
720 C:\WINDOWS\System32\lsass.exe
728 C:\WINDOWS\System32\lsm.exe
808 C:\WINDOWS\System32\winlogon.exe
908 C:\WINDOWS\System32\svchost.exe
968 C:\WINDOWS\System32\svchost.exe
1020 C:\WINDOWS\System32\svchost.exe
352 C:\WINDOWS\System32\svchost.exe
500 C:\WINDOWS\System32\svchost.exe
568 C:\WINDOWS\System32\svchost.exe
896 C:\WINDOWS\System32\audiodg.exe
368 C:\WINDOWS\System32\SLsvc.exe
1052 C:\WINDOWS\System32\svchost.exe
1164 C:\WINDOWS\System32\svchost.exe
1348 C:\WINDOWS\System32\spoolsv.exe
1372 C:\WINDOWS\System32\svchost.exe
1560 C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
1588 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1832 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1880 C:\WINDOWS\System32\svchost.exe
1892 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
1996 C:\WINDOWS\System32\taskeng.exe
2036 C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
768 C:\WINDOWS\System32\svchost.exe
1108 C:\WINDOWS\System32\svchost.exe
2040 C:\WINDOWS\System32\SearchIndexer.exe
2108 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
2324 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
2600 C:\WINDOWS\System32\dwm.exe
2620 C:\WINDOWS\System32\taskeng.exe
2660 C:\WINDOWS\explorer.exe
2912 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2928 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
2956 C:\WINDOWS\RAVCpl64.exe
2980 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3008 C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
3032 C:\Program Files\Windows Defender\MSASCui.exe
3064 C:\WINDOWS\System32\hkcmd.exe
1172 C:\WINDOWS\System32\igfxpers.exe
1112 C:\WINDOWS\ehome\ehtray.exe
2456 C:\Program Files (x86)\HP\QuickPlay\QPService.exe
2644 C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
2816 C:\WINDOWS\System32\igfxsrvc.exe
3084 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
3140 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
3152 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3160 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
3172 C:\WINDOWS\ehome\ehmsas.exe
3192 C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
3200 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
3236 C:\Program Files (x86)\iTunes\iTunesHelper.exe
3296 WmiPrvSE.exe
3724 C:\Program Files\iPod\bin\iPodService.exe
3968 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
2412 C:\Program Files\Windows Media Player\wmpnscfg.exe
1956 C:\Program Files\Windows Media Player\wmpnetwk.exe
3912 C:\WINDOWS\System32\svchost.exe
2120 C:\WINDOWS\System32\SearchProtocolHost.exe
2420 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2296 C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
2948 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
4740 C:\WINDOWS\System32\wuauclt.exe
4092 MpCmdRun.exe
1268 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
3600 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
3920 C:\WINDOWS\explorer.exe
4524 C:\WINDOWS\System32\SearchFilterHost.exe
1476 dllhost.exe
4180 dllhost.exe
1556 C:\Users\Chris\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000047`507bec00 (NTFS)
PhysicalDrive0 Model Number: FUJITSUMHZ2320BHG2, Rev: 8909
Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Chris at 21:47:51.92 on Fri 04/29/2011
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_24
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4085.2456 [GMT 10:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Chris\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion &pf=laptop
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.ex e" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
mRun: [DivX Download Manager] "C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe" start
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\TOTALM~1.LNK - C:\Program Files (x86)\ArcSoft\TotalMedia Extreme 2\BackUp & Recorder\uBBMonitor.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TB-X64: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
mRun-x64: [RtHDVCpl] RAVCpl64.exe
mRun-x64: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe"
mRun-x64: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Pro files\vhwhn7mq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Pro files\vhwhn7mq.default\extensions\engine@conduit.c om\components\RadioWMPCoreGecko19.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
R3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw5v64.sys [2008-11-17 4751360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 hcwhdpvr;Hauppauge HD PVR Capture Device;C:\WINDOWS\System32\drivers\hcwhdpvr.sys [2011-1-18 189440]
S3 NETw4v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw4v64.sys [2008-6-18 3148288]
S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2008-5-7 14464]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework6 4\v2.0.50727\mscorsvw.exe [2011-1-20 89920]
.
=============== File Associations ===============
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-04-29 11:15:40 -------- d--h--w- C:\Users\Chris\AppData\Roaming\Malwarebytes
2011-04-29 11:15:32 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-29 11:15:32 -------- d--h--w- C:\PROGRA~3\Malwarebytes
2011-04-29 11:15:29 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-04-29 11:15:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-29 10:50:30 8802128 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{64D7CDFD-B08E-4BB2-B97C-0548E5FD1965}\mpengine.dll
2011-04-20 12:51:15 40960 ---ha-r- C:\Users\Chris\AppData\Roaming\Microsoft\Installer \{ECF8D4B4-FADB-492E-A79A-5BCEA02DB95D}\NewShortcut1_0D8BB549999E4288839DD9D F4569C1EC.exe
2011-04-20 12:51:10 -------- d-----w- C:\Program Files (x86)\2d3
2011-04-20 12:50:51 296448 ----a-w- C:\Windows\System32\drivers\hardlock.sys
2011-04-20 12:50:49 24576 ----a-w- C:\Windows\SysWow64\hdsuinst.exe
2011-04-20 12:50:49 2164411 ----a-w- C:\Windows\SysWow64\haspds_windows.dll
2011-04-20 12:50:49 164864 ----a-w- C:\Windows\SysWow64\UNWISE.EXE
2011-04-20 12:29:52 -------- d--h--w- C:\PROGRA~3\SafeNet Sentinel
2011-04-20 12:29:43 -------- d-----w- C:\Program Files (x86)\Vicon
2011-04-18 12:49:05 -------- d--h--w- C:\Users\Chris\dwhelper
2011-04-18 12:41:32 307200 ----a-w- C:\Windows\SysWow64\TubeFinder.exe
2011-04-18 12:41:31 9728 ----a-w- C:\Windows\SysWow64\PCCLPFR.DLL
2011-04-18 12:41:31 84512 ----a-w- C:\Windows\SysWow64\PICCLP32.OCX
2011-04-18 12:41:31 364544 ----a-w- C:\Windows\SysWow64\PropertyGrid.ocx
2011-04-18 12:41:31 119568 ----a-w- C:\Windows\SysWow64\VB6FR.DLL
2011-04-18 12:41:31 101888 ----a-w- C:\Windows\SysWow64\VB6STKIT.DLL
2011-04-18 12:41:30 32768 ----a-w- C:\Windows\SysWow64\CMDLGFR.DLL
2011-04-18 12:41:30 24576 ----a-w- C:\Windows\SysWow64\ControlSubX.ocx
2011-04-18 12:41:30 141312 ----a-w- C:\Windows\SysWow64\MSCMCFR.DLL
2011-04-18 12:41:30 -------- d--h--w- C:\Users\Chris\AppData\Roaming\FreeFLVConverter
2011-04-18 12:41:30 -------- d-----w- C:\Program Files (x86)\Free FLV Converter
2011-04-17 16:12:57 -------- d-----w- C:\Program Files\MAXON
2011-04-17 16:10:16 -------- d--h--w- C:\Users\Chris\AppData\Roaming\MAXON
2011-04-17 13:05:38 -------- d--h--w- C:\AdobeTemp
2011-04-13 00:30:10 450560 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-04-13 00:30:10 176128 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-13 00:30:10 145920 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-13 00:30:04 991104 ----a-w- C:\Windows\System32\winresume.efi
2011-04-13 00:30:04 979840 ----a-w- C:\Windows\System32\winresume.exe
2011-04-13 00:30:04 1076608 ----a-w- C:\Windows\System32\winload.efi
2011-04-13 00:30:04 1063296 ----a-w- C:\Windows\System32\winload.exe
2011-04-13 00:30:03 20864 ----a-w- C:\Windows\System32\kdusb.dll
2011-04-13 00:30:03 18816 ----a-w- C:\Windows\System32\kd1394.dll
2011-04-13 00:30:03 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-04-13 00:29:22 603136 ----a-w- C:\Windows\System32\vbscript.dll
2011-04-13 00:29:22 430080 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-04-13 00:29:13 274432 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-04-13 00:29:12 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-04-13 00:29:12 135680 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-04-13 00:29:12 106496 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-04-13 00:29:03 975872 ----a-w- C:\Windows\System32\inetcomm.dll
2011-04-13 00:29:03 739328 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-04-05 22:04:47 -------- d-----w- C:\Program Files\iPod
2011-04-05 22:04:46 -------- d-----w- C:\Program Files\iTunes
2011-04-05 22:04:46 -------- d-----w- C:\Program Files (x86)\iTunes
.
==================== Find3M ====================
.
2011-03-28 16:33:34 73216 ----a-w- C:\Windows\SysWow64\ff_vfw.dll
2011-03-20 23:58:04 152064 ----a-w- C:\Windows\SysWow64\xvid.ax
2011-03-19 01:06:02 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2011-03-19 01:04:28 650752 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2011-03-10 17:18:03 1360384 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-10 17:18:02 1398784 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-10 17:03:51 1162240 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-03 13:46:31 2762240 ----a-w- C:\Windows\System32\win32k.sys
2011-03-02 16:12:21 117760 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-02-27 18:00:00 1003520 ----a-w- C:\Windows\SysWow64\VSFilter.dll
2011-02-22 14:47:08 479744 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-02-22 14:13:01 288768 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-02-22 13:53:33 1555968 ----a-w- C:\Windows\System32\DWrite.dll
2011-02-22 13:53:27 1149440 ----a-w- C:\Windows\System32\FntCache.dll
2011-02-22 13:33:12 1068544 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-18 16:50:48 1032192 ----a-w- C:\Windows\System32\wininet.dll
2011-02-18 16:38:42 834048 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-02-18 15:55:33 86528 ----a-w- C:\Windows\System32\ieencode.dll
2011-02-18 15:45:02 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2011-02-18 15:19:20 485376 ----a-w- C:\Windows\System32\html.iec
2011-02-18 14:49:21 389632 ----a-w- C:\Windows\SysWow64\html.iec
2011-02-18 06:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 06:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-02-16 16:37:47 48128 ----a-w- C:\Windows\System32\atmlib.dll
2011-02-16 16:16:37 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-02-16 14:15:24 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-02-16 14:02:23 292864 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-02-10 07:51:58 3075072 ----a-w- C:\Windows\SysWow64\x264vfw.dll
2011-02-02 11:40:23 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-02-02 08:11:20 270720 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 21:48:13.33 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/18/2008 2:53:32 AM
System Uptime: 4/29/2011 9:22:24 PM (0 hours ago)
.
Motherboard: Quanta | | 30CC
Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz | U2E1 | 2000/667mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 142.042 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 2.44 GiB free.
E: is CDROM (UDF)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Media Player
Adobe Reader 8.1.0
Apple Application Support
Apple Software Update
ArcSoft TotalMedia Extreme
BitTorrent
BitTorrentBar Toolbar
boujou 4
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conduit Engine
CyberLink YouCam
DVD Suite
EA Link
Free FLV Converter V 6.96.0
HASP HL Device Driver
Hauppauge HDPVR Scheduler
Hauppauge WinTV IR Blaster
Hauppauge WinTV Scheduler
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.30 E1
HP QuickPlay 3.6
HP Smart Web Printing
HP Update
HP User Guides 0087
HP Wireless Assistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
Java Auto Updater
Java(TM) 6 Update 2
Java(TM) 6 Update 24
LabelPrint
LiveUpdate (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox 4.0 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.6
QuickTime
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Slingbox Flash Tour
SlingPlayer
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Office 2007 (KB934528)
Vicon boujou 5.0
VideoToolkit01
Viewpoint Media Player
Vista Codec Package
.
==== End Of File ===========================
Source : Google Reader
Winodws Live Mail
Winodws Live Mail: "
Hi
I hope this is the right place to ask this question. If not, perhaps someone would be kind enough to move it.
I don't use Windows Live Mail myself, but a friend who does has a problem.
I don't have immediate access to her computer, so can't send a screenshot, but, basically, she has TWO duplicate email accounts on the left-hand side of the page.
If it makes it any clearer, the first one - which is her name@her service provider is labelled as her 'default account'. (And the 'make this my default account' option is greyed-out.)
The one immediately below is also her name@her service provider. It has the option to become the default account.
If an email arrives it goes into both accounts so she has two of everything..
My question is: can she safely press the 'remove account' button for the second account, without automatically deleting both because they have the same details?
And why are there two accounts? My friend seems to think she didn't always have both. It may be that they were set up for her by the people who sold her the computer. She's not sure. She's a bit scatter-brained and certainly couldn't have set them up herself. Can it be done accidentally?
Thanks for any help you can give me.
James
"I hope this is the right place to ask this question. If not, perhaps someone would be kind enough to move it.
I don't use Windows Live Mail myself, but a friend who does has a problem.
I don't have immediate access to her computer, so can't send a screenshot, but, basically, she has TWO duplicate email accounts on the left-hand side of the page.
If it makes it any clearer, the first one - which is her name@her service provider is labelled as her 'default account'. (And the 'make this my default account' option is greyed-out.)
The one immediately below is also her name@her service provider. It has the option to become the default account.
If an email arrives it goes into both accounts so she has two of everything..
My question is: can she safely press the 'remove account' button for the second account, without automatically deleting both because they have the same details?
And why are there two accounts? My friend seems to think she didn't always have both. It may be that they were set up for her by the people who sold her the computer. She's not sure. She's a bit scatter-brained and certainly couldn't have set them up herself. Can it be done accidentally?
Thanks for any help you can give me.
James
Source : Google Reader
Connecting XP Pro Netbook to Win 7 Desktop
Connecting XP Pro Netbook to Win 7 Desktop: "
Currently I have a Win 7 Desktop and Win 7 Laptop working on a Homegroup with no problem. Easy to setup and easy to maintain.
I also have a Win XP Pro Netbook, which I cannot upgrade to Win 7 as I have only 2 licences for Win 7. I wish to use the XP Netbook on the same network. I know I cannot use Homegroup for XP and I also know the obvious solution is to use the Workgroup solution for all three computers. Before I go down that road I want to explore any other possible solutions. One I have come across is Remote Desktop, which I have never used before. Thus far I have enabled Remote Desktop on my Win 7 Desktop (which is my primary PC) and enabled connections from PCs using any version of Remote Desktop. Permissions on Windows Firewall also seem to be ok. The problem is when I try to log in from my XP Pro Netbook I successfully get to the login screen on Win 7, it does not recognise either the User Name or Password.
Questions
Is the unrecognised User Name/Password login the one I use on my Win 7 or do I need to setup another account to represent my Netbook? I have tried this, but the Win 7 PC cannot find that account, presumably because it is not on the network?
2. Does Remote Desktop only work on a LAN, whereas I am tring to use it on my home wireless network?
3. Are there any other workarounds or is the Workgroup the only other solution?
Many thanks
Gareth
"I also have a Win XP Pro Netbook, which I cannot upgrade to Win 7 as I have only 2 licences for Win 7. I wish to use the XP Netbook on the same network. I know I cannot use Homegroup for XP and I also know the obvious solution is to use the Workgroup solution for all three computers. Before I go down that road I want to explore any other possible solutions. One I have come across is Remote Desktop, which I have never used before. Thus far I have enabled Remote Desktop on my Win 7 Desktop (which is my primary PC) and enabled connections from PCs using any version of Remote Desktop. Permissions on Windows Firewall also seem to be ok. The problem is when I try to log in from my XP Pro Netbook I successfully get to the login screen on Win 7, it does not recognise either the User Name or Password.
Questions
Is the unrecognised User Name/Password login the one I use on my Win 7 or do I need to setup another account to represent my Netbook? I have tried this, but the Win 7 PC cannot find that account, presumably because it is not on the network?
2. Does Remote Desktop only work on a LAN, whereas I am tring to use it on my home wireless network?
3. Are there any other workarounds or is the Workgroup the only other solution?
Many thanks
Gareth
Source : Google Reader
Word document recovery
Word document recovery: "
Dear all,
I just began using word 2010 recently. .. I was working on a document about two weeks ago. I had two copies open: one was the document; another was a pasted version, with modifications I was working on. ... Then I dropped the computer and broke my display and had to force-shut-down, since I could not see anything in the display any more.
Today I got my computer back from repair and opened word for the first time. It seemed to have both versions of the document. I opened the first one, read through quickly, and clicked the save-symbol (a floppy-symbol). As soon as I did, both recovery-documents disappeared from the sidebar. ... what have I done? I do not even know whether I have saved the original or the modified version...
...
yours,
Janelle
"I just began using word 2010 recently. .. I was working on a document about two weeks ago. I had two copies open: one was the document; another was a pasted version, with modifications I was working on. ... Then I dropped the computer and broke my display and had to force-shut-down, since I could not see anything in the display any more.
Today I got my computer back from repair and opened word for the first time. It seemed to have both versions of the document. I opened the first one, read through quickly, and clicked the save-symbol (a floppy-symbol). As soon as I did, both recovery-documents disappeared from the sidebar. ... what have I done? I do not even know whether I have saved the original or the modified version...
...
yours,
Janelle
Source : Google Reader
Help - Monitor won't turn on
Help - Monitor won't turn on: "
My monitor was working i moved it from one place to another now it will not turn on when i push the start button you only here a beep plaese help
"Source : Google Reader
D-A-L Site Rules
D-A-L Site Rules: "
For our site rules please visit - D-A-L.com Rules | D-A-L Computer Help
"Source : Google Reader
How to restore BlackBerry Playbook to factory default?
How to restore BlackBerry Playbook to factory default?: "
Recently I have purchased BlackBerry Playbook. From past few days I am getting performance issue with the device of mine. so I have decided to do a Factory Default on the device of mine. I have searched on the Google to get the steps for the same. but I was unable to find out anything to fix the matter of mine. let me know if you are having any suggestion to get the requirement of mine. thanks a
"Source : Google Reader
How to Enjoy DVD on iPod Touch/Classic/Nano
How to Enjoy DVD on iPod Touch/Classic/Nano: "
Now iPod has entered your digital world.
You can only buy video or audio from iTune. In this way, many other resources are wasted like DVD, video or audio downloaded from websites.
So here I would like to share an easy and useful way to make full use of DVD in your hands. And then you can enjoy your favorite DVD anytime and everywhere.
iPod can only accepts H.264 and MP4 video formats. First
"You can only buy video or audio from iTune. In this way, many other resources are wasted like DVD, video or audio downloaded from websites.
So here I would like to share an easy and useful way to make full use of DVD in your hands. And then you can enjoy your favorite DVD anytime and everywhere.
iPod can only accepts H.264 and MP4 video formats. First
Source : Google Reader
Unable to connect BlackBerry Bridge
Unable to connect BlackBerry Bridge: "
As the title suggesting itself what i am going to asking over here. Well i have found that the PlayBook of mine is does not seem to connect with the Bridge. The Playbook of mine is prompting that it is Waiting. Let me know why this particular issue is being happening on the device of yours. Any help on this particular matter would be highly appreciated. Thanks a lot in advance.
"Source : Google Reader
BlackBerry Bold Touch 9930 / 9900 Full Hardware and BlackBerry 7 Software
BlackBerry Bold Touch 9930 / 9900 Full Hardware and BlackBerry 7 Software: "
BlackBerry Bold 9930/9900 Hardware: The longer we in the new Bold are more in love with the hardware. Of course, the features and specs list is very complete and feel the performance and processor speed of 1.2GHz. The photos do not do integrity to how thin, mutually touching the Bold is and how light it feels in your hand. At the same time the width of the device is similar as the 9000, we
"Source : Google Reader
Unable to find Patch of ISO image in CentOS.
Unable to find Patch of ISO image in CentOS.: "
Hello everyone, I am using CentOS in my computer and I am facing some problem since from many days. I am getting some error in installing the CentOS 5.6 and update. ISO using USB drive. I have also customized the pendrive with proper package removing like openoffice etc. I am writing some detail about the my anaconda and kernel
anaconda : anaconda-11.1.2.209-1.el5.centos
kernel : kernel-
"anaconda : anaconda-11.1.2.209-1.el5.centos
kernel : kernel-
Source : Google Reader
You’re Review on Red River PC game
You’re Review on Red River PC game: "
My comment for this game that lasted 3 hours of testing, accidents and furious display several punches were seen after this review is also a game box broken. Operation Flashpoint console war.
1. Operation Flashpoint Red River is an impressive title that has everything a PC gamer console would feel a range of even dull persistent statistics system to show his teammates and some awesome w
"1. Operation Flashpoint Red River is an impressive title that has everything a PC gamer console would feel a range of even dull persistent statistics system to show his teammates and some awesome w
Source : Google Reader
CentOS 5.2 and Apache 2.2.3: Getting error message 403
CentOS 5.2 and Apache 2.2.3: Getting error message 403: "
It is very first thread on this particular forum I am hoping that the users of this particular forum will help me out from the annoying situation which I am going to mentioned below. Well I have installed CentOS 5.2 on the computer of mine and also Apache 2.2.3. whenever I am trying to access any of the webpage I am getting following error message on the computer of mine ‘You don't have permission
"Source : Google Reader
Blackberry 9850 vs. 9930 or Bold Touch vs. Touch
Blackberry 9850 vs. 9930 or Bold Touch vs. Touch: "
I am looking for your thoughts. I use my phone for work email and personal (movies and travel applications, etc.) used. About 50/50. I've never had a touch tone phone and generally not happy with the Blackberry-style phone (other than a short visit to a droid Pro). The Touchscreen phone only looks good and seems to be great for movies during the flight, etc, and ease of use, but I wonder about usi
"Source : Google Reader
Ethnic Hmong handbag/Embroidered bag / code B0013
Ethnic Hmong handbag/Embroidered bag / code B0013: "
$29.99
Hand-Embroidered bag.
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
Traditional bag ,even clothes or piece of cloth are very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong bag made from our idea to bring back and traditional style with everyday life.
size approx :
height : 22 inches
wide top : 13 inches
wide below : 22 inches
Strap : 23 inches
2 Zipper <1 Zipper inside>
2 sides embroidered
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio :)
"
$29.99
Hand-Embroidered bag.
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
Traditional bag ,even clothes or piece of cloth are very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong bag made from our idea to bring back and traditional style with everyday life.
size approx :
height : 22 inches
wide top : 13 inches
wide below : 22 inches
Strap : 23 inches
2 Zipper <1 Zipper inside>
2 sides embroidered
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio :)
"
Source : Google Reader
A couple lucky bird Hmong Embroidered Pouch and Purses/gadget/cosmetic bag/ B0036
A couple lucky bird Hmong Embroidered Pouch and Purses/gadget/cosmetic bag/ B0036: "
$15.00
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure and wristlet
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 7.5"x 10.5 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
$15.00
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure and wristlet
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 7.5"x 10.5 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
Source : Google Reader
Ethnic Hmong mobile case for SumSung /Nokia /Sony Ericsson /Embroidered bag/ code B0023
Ethnic Hmong mobile case for SumSung /Nokia /Sony Ericsson /Embroidered bag/ code B0023: "
$12.99
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
This Traditional mobile case ,made of piece of cloth which is very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong product made from our idea to bring back and traditional style with everyday life.
size approx :
height : 2 3/4 x 5 inches
Strap with pom : 44 inches
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio :)
"
$12.99
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
This Traditional mobile case ,made of piece of cloth which is very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong product made from our idea to bring back and traditional style with everyday life.
size approx :
height : 2 3/4 x 5 inches
Strap with pom : 44 inches
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio :)
"
Source : Google Reader
Hmong handmade Embroidered Pouch and Purses/cosmetic bag/gadget bag/B0059
Hmong handmade Embroidered Pouch and Purses/cosmetic bag/gadget bag/B0059: "
$14.99
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 5 "x 7 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
$14.99
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 5 "x 7 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
Source : Google Reader
Hmong handmade Embroidered Pouch and Purses/cosmetic bag/gadget bag/B0061
Hmong handmade Embroidered Pouch and Purses/cosmetic bag/gadget bag/B0061: "
$14.99
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure
and 1 zipper inside
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 8.5 "x 10 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
$14.99
Embroidered Pouch 2 side
Embroider by Hmong;Hill-tribe on the northern of Thailand
* Zipper closure
and 1 zipper inside
Can be used as a pencil case, cosmetic case, Big enough to hold your blackberry,ipod ,iphone etc.
Approx Size: 8.5 "x 10 "
About us : We're in small village near by hill, Northern of Chiang Mai , Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you by registered mail.
If you have any question pls.feel free to convo.
Thanks for your shopping
asian direct studio :)
"
Source : Google Reader
Lovely Hmong Handmade necklace
Lovely Hmong Handmade necklace: "
$11.00
A Lovely Handmade necklace
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
Traditional Hmong necklace,even clothes or piece of cloth are very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong necklace made from our idea to bring back and traditional style with everyday life.
It's adjustable.
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio
"
$11.00
A Lovely Handmade necklace
Embroider by Hmong;Hill-tribe on the northern of Thailand.
It’ would make the ideal gift for a friend, family, or perhaps it may be that’s right for you.
Hmong are ethnic people who live in mountain in Northern part of Thailand and Laos.
In Thailand and Laos,the Hmong wore traditional clothing every single day.Today, most Hmong in Thailand & Laos.
Traditional Hmong necklace,even clothes or piece of cloth are very colorful and bright they are goes a lot farther than a suit and tie, or a kilt. It is mostly about needlework, and it is made very well.
This modern style Hmong necklace made from our idea to bring back and traditional style with everyday life.
It's adjustable.
The products will be shipped by registered air mail ,within 1-3 official day after payment clear. Shipping normally needs 8-18 days from Chiang mai ,Thailand. This enables you to track the package shipment by its tracking number.
About us : We're in small village near by hill, Chiang Mai , Northern of Thailand.
All our products are constructed in a non-smoking studio and using supplied in our local.
It will be delivered from Thailand to you in anywhere by registered mail.
If you have any question pls.feel free to convo.
Thanks for shopping.
asian direct studio
"
Source : Google Reader
Should you buy the $114 or $139 Kindle?
Should you buy the $114 or $139 Kindle?: "Is the $114 Kindle with Special Offers a better deal than the $139 ad-free Kindle Wi-Fi? The answer may surprise you."
Source : Google Reader
Report: Wireless carriers rethink mobile payments
Report: Wireless carriers rethink mobile payments: "AT&T, Verizon Wireless, and T-Mobile USA are abandoning plans to build their own payment network as they rethink how to address the mobile payment market."
Source : Google Reader
Subscribe to:
Posts (Atom)