Jump to content

Harrison

Members
  • Posts

    17
  • Joined

  • Last visited

Everything posted by Harrison

  1. The issue was resolved after the update. Thanks for the prompt response.
  2. It doesn't appear as a threat, after a full scan, since the update. I'm still curious why an att file was labeled with trojan.bank.
  3. It seems like everyone is up in the air about the issue being a 4/2 definition update and possibly an ATT compromise... I've uninstalled my banking apps for security purposes and will wait for a update that can address this. Harrison
  4. I'm glad yo hear you took that measure to try and fix the issue. I have alot of finance apps on my device and a good credit score to target. Do you think you picked it up installing a bad app? Or do you think the legitimate banking apps were the ones that caused it?
  5. On the same note - How can i "clear" or reset my system apps so it is no longer corrupt?
  6. I took it off the whitelist (even tough it's a system app) I don't want a corrupt file to have full access.
  7. I disabled it in settings, but I don't know what else I can do to clean this up. If I attempt to 'remove it it says 'cannot remove a system file and tells me to whitelist it. Thanks, Harrison
  8. I actually did find the log with torvi in it. Malwarebytes Anti-Malwarewww.malwarebytes.org Scan Date: 9/15/2014Scan Time: 12:55:05 AMLogfile: Administrator: Yes Version: 2.00.2.1012Malware Database: v2014.09.15.03Rootkit Database: v2014.09.13.01License: PremiumMalware Protection: EnabledMalicious Website Protection: DisabledSelf-protection: Disabled OS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser: Harry S Scan Type: Threat ScanResult: CompletedObjects Scanned: 396212Time Elapsed: 19 min, 41 sec Memory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledHeuristics: EnabledPUP: WarnPUM: Enabled Processes: 0(No malicious items detected) Modules: 0(No malicious items detected) Registry Keys: 1PUP.Optional.SearchProtect.A, HKU\S-1-5-21-313453830-395109726-2256184908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Quarantined, [35f640ad32495fd76cecbacadb27b24e], Registry Values: 0(No malicious items detected) Registry Data: 0(No malicious items detected) Folders: 0(No malicious items detected) Files: 13PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nsbF7B2.exe, Quarantined, [b279cd207ffccb6be651038fcf326a96], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nsbFDCB.exe, Quarantined, [b7743faea1da5bdb51e6543e6d9412ee], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nskBC80.exe, Quarantined, [8aa126c74635c6702e09dcb6a061d32d], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nsl7FDE.exe, Quarantined, [0526df0ec6b593a3e1560f835fa242be], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nsl850D.exe, Quarantined, [919ad5186219e94df4436032d72a8f71], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nslE691.exe, Quarantined, [46e545a8e09ba591ec4bfc9651b0b34d], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\nsv7A03.exe, Quarantined, [15167875ec8f1521b18697fb4bb68b75], PUP.Optional.SearchProtect.A, C:\Users\Harry S\AppData\Local\Temp\sp-downloader.exe, Quarantined, [d15a7b72d1aad363e938424fc73a06fa], PUP.Optional.Conduit.A, C:\Users\Harry S\AppData\Local\Temp\~nsu.tmp\Au_.exe, Quarantined, [89a2519ccead49ed1423eba7d32eb34d], PUP.Optional.OpenCandy, C:\Users\Harry S\AppData\Local\Temp\nsa5E86.tmp\OCSetupHlp.dll, Quarantined, [b972b23beb90c07674c327fc2fd6dc24], PUP.Optional.OpenCandy, C:\Users\Harry S\AppData\Local\Temp\nsv7B49.tmp\OCSetupHlp.dll, Quarantined, [6ebd5d90f982e84e49ee4dd631d4857b], PUP.Optional.OpenCandy, C:\Users\Harry S\Downloads\PowerISO6-x64.exe, Quarantined, [d556a647592286b02c0bc06306ff6d93], PUP.Optional.Trovi.A, C:\Users\Harry S\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "new_tab_url": "https://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M188E8FB8-2685-49F7-8FB0-10152F539FC0&SearchSource=69&CUI=&SSPV=SP21715TB_sp_ch&lay=5&p=cnts&UM=6&UP=SPCE0592D8-C338-43FF-8AF4-F00CF22809E1&SAT=CNTS",), Replaced,[4dde94594a3164d2e7c97fb234d1e21e] Physical Sectors: 0(No malicious items detected) (end)
  9. So last night I left my PC on and went away for about 4 hours. No, I was not browsing porn at the time I went AFK. I came back and my laptop wouldn't boot up. I had to plugin my power cord to start it up. battery was at 16%, though. Then pops up a failure to start and pc repair window (the kind that doesn't load windows fully) It looks like win 98. I restored windows to a "previously working point in time" and went on. Then I ran MBAM out of curiosity. I found trovi and other malware. Obviously i attempted to remove them all. I was prompted to restart for full removal so I did, BUT after 30 mins of waiting I decided to go ahead and restart while it still said "shutting down" still. My real problem is that I can't remove trovi and the other crap again. I can't even find it. I don't have the logs to show you either. How can i fix this?
  10. I usualy use Google chrome as a web browser. I'm gonna try different ones just to see if it makes any differenece.
  11. MiniToolBox by Farbar Version: 25-11-2012 Ran by Harry (administrator) on 27-11-2012 at 17:53:35 Running from "C:\Users\Harry\Desktop" Windows Vista Home Premium Service Pack 2 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= FF Proxy Settings: ============================== "Reset FF Proxy Settings": Firefox Proxy settings were reset. ========================= Hosts content: ================================= 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com 127.0.0.1 localhost ========================= IP Configuration: ================================ Realtek PCIe GBE Family Controller = Local Area Connection (Connected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : HStam Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller Physical Address. . . . . . . . . : 00-19-66-BC-D0-65 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::3537:706c:d90f:fc93%8(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.13(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Tuesday, November 27, 2012 5:47:11 PM Lease Expires . . . . . . . . . . : Wednesday, November 28, 2012 5:47:10 PM Default Gateway . . . . . . . . . : 192.168.1.1 DHCP Server . . . . . . . . . . . : 192.168.1.1 DHCPv6 IAID . . . . . . . . . . . : 134224230 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-FF-8F-EF-00-19-66-BC-D0-65 DNS Servers . . . . . . . . . . . : 192.168.1.1 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter Local Area Connection* 6: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : isatap.{4632C2DB-5409-4BAA-8201-1EC80E333038} Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 7: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 02-00-54-55-4E-01 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6ab8:305a:2830:3f57:fef2(Preferred) Link-local IPv6 Address . . . . . : fe80::305a:2830:3f57:fef2%9(Preferred) Default Gateway . . . . . . . . . : :: NetBIOS over Tcpip. . . . . . . . : Disabled Server: UnKnown Address: 192.168.1.1 Name: google.com Addresses: 2607:f8b0:4004:801::1008 74.125.228.69 74.125.228.67 74.125.228.65 74.125.228.70 74.125.228.66 74.125.228.68 74.125.228.71 74.125.228.72 74.125.228.64 74.125.228.73 74.125.228.78 Pinging google.com [74.125.228.73] with 32 bytes of data: Reply from 74.125.228.73: bytes=32 time=20ms TTL=54 Reply from 74.125.228.73: bytes=32 time=20ms TTL=54 Ping statistics for 74.125.228.73: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 20ms, Maximum = 20ms, Average = 20ms Server: UnKnown Address: 192.168.1.1 Name: yahoo.com Addresses: 72.30.38.140 98.138.253.109 98.139.183.24 Pinging yahoo.com [98.139.183.24] with 32 bytes of data: Reply from 98.139.183.24: bytes=32 time=285ms TTL=52 Reply from 98.139.183.24: bytes=32 time=206ms TTL=52 Ping statistics for 98.139.183.24: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 206ms, Maximum = 285ms, Average = 245ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 8 ...00 19 66 bc d0 65 ...... Realtek PCIe GBE Family Controller 1 ........................... Software Loopback Interface 1 17 ...00 00 00 00 00 00 00 e0 isatap.{4632C2DB-5409-4BAA-8201-1EC80E333038} 9 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.13 20 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.13 276 192.168.1.13 255.255.255.255 On-link 192.168.1.13 276 192.168.1.255 255.255.255.255 On-link 192.168.1.13 276 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.13 276 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.13 276 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 9 18 ::/0 On-link 1 306 ::1/128 On-link 9 18 2001::/32 On-link 9 266 2001:0:9d38:6ab8:305a:2830:3f57:fef2/128 On-link 8 276 fe80::/64 On-link 9 266 fe80::/64 On-link 9 266 fe80::305a:2830:3f57:fef2/128 On-link 8 276 fe80::3537:706c:d90f:fc93/128 On-link 1 306 ff00::/8 On-link 9 266 ff00::/8 On-link 8 276 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Catalog5 05 C:\Windows\System32\mswsock.dll [223232] (Microsoft Corporation) Catalog5 06 C:\Windows\System32\winrnr.dll [19968] (Microsoft Corporation) Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.) Catalog5 08 C:\Windows\system32\wshbth.dll [34304] (Microsoft Corporation) Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 29 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 30 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 31 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 32 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 33 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 34 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 35 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (11/27/2012 05:51:43 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\9\EF> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:43 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\9\EF> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:43 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\8\69> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:43 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\8\69> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:42 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\B\88> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:42 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\B\88> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:41 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\2\31> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:41 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\2\31> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:40 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\4\92> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (11/27/2012 05:51:40 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HARRY\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\DDEIZ9FO.DEFAULT\CACHE\4\92> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) System errors: ============= Error: (11/27/2012 05:49:44 PM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (11/27/2012 05:49:44 PM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (11/27/2012 05:47:44 PM) (Source: Service Control Manager) (User: ) Description: i8042prt maagqb qozysh Error: (11/27/2012 05:47:44 PM) (Source: Service Control Manager) (User: ) Description: Net.Tcp Listener Adapterwas Error: (11/27/2012 05:47:44 PM) (Source: Service Control Manager) (User: ) Description: Net.Pipe Listener Adapterwas Error: (11/27/2012 05:47:44 PM) (Source: Service Control Manager) (User: ) Description: Net.Msmq Listener Adaptermsmq Error: (11/27/2012 05:47:08 PM) (Source: EventLog) (User: ) Description: The previous system shutdown at 5:45:19 PM on 11/27/2012 was unexpected. Error: (11/27/2012 05:46:53 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT AUTHORITY) Description: Error: (11/27/2012 05:45:57 PM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (11/27/2012 05:45:57 PM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Microsoft Office Sessions: ========================= Error: (06/29/2010 08:52:39 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 551042 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2012-11-15 00:45:22.533 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-11-15 00:45:21.704 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-11-15 00:45:20.851 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-11-15 00:45:20.018 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-11-15 00:45:19.181 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-11-15 00:45:18.344 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-10-17 15:19:49.654 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll because the set of per-page image hashes could not be found on the system. Date: 2012-10-16 23:39:26.538 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll because the set of per-page image hashes could not be found on the system. Date: 2012-10-16 23:38:58.660 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll because the set of per-page image hashes could not be found on the system. Date: 2012-10-16 12:39:30.616 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll because the set of per-page image hashes could not be found on the system. **** End of log **** On a side note: After this whole incident began my PC has started to crash at odd intervals. And I can tell whenever it is about to happen. It will freeze ( no more functional progress) , tehn the mouse and audio will cut out along with the blinking of my CPU light on my case. Then I scroll my mouse wheel literally 3 clicks or click the mouse button 3 times and everything freezes and it requires a restart. I've given my computer time to attempt to recover from the initial freeze, bu nothing happens. Thanks, Harrison
  12. I was downloading on that PC (my desktop) I have Comodo Internet Security Premium on that PC. I turned it off as not to cause any conflicts with the programs you asked me to run. Comodo is essentially the paranoia program.
  13. FSS.Txt Farbar Service Scanner Version: 09-11-2012 Ran by Harry (administrator) on 26-11-2012 at 17:52:28 Running from "C:\Users\Harry\Desktop" Windows Vista Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Attempt to access Google IP returned error. Google.com is accessible. Attempt to access Yahoo IP returned error. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is OK. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll [2012-10-09 20:19] - [2012-06-01 19:02] - 0133120 ____A (Microsoft Corporation) F1E8C34892336D33EDDCDFE44E474F64 C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** Checkup.txt Results of screen317's Security Check version 0.99.56 Windows Vista Service Pack 2 x86 (UAC is disabled!) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Disabled! WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.65.1.1000 CCleaner JavaFX 2.1.1 Java 6 Update 32 Java 7 Update 5 Java version out of Date! Adobe Flash Player 11.4.402.287 Adobe Reader 10.1.4 Adobe Reader out of Date! Mozilla Firefox 12.0 Firefox out of Date! Google Chrome 21.0.1180.83 Google Chrome 21.0.1180.89 Google Chrome 22.0.1229.79 Google Chrome 22.0.1229.92 Google Chrome 22.0.1229.94 Google Chrome 23.0.1271.64 Google Chrome plugins... ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` sorry about the checkup.txt. It used my notepad++ to auto run the final .txt doc it needed. Thanks again, Harrison
  14. DDS.TXT DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.5.1 Run by Harry at 17:45:04 on 2012-11-26 . ============== Running Processes ================ . . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uURLSearchHooks: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - <orphaned> uURLSearchHooks: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - <orphaned> dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned> BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned> BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file> BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll BHO: Google Gears Helper: {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Google Update] "c:\users\harry\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Mobile-based device management] c:\windows\windowsmobile\wmdSync.exe mRun: [Windows Mobile Device Center] c:\windows\windowsmobile\wmdc.exe mRun: [OdoPlus] c:\users\harry\desktop\extra\OdoPlus.exe /autorun mRun: [Aimersoft Helper Compact.exe] c:\program files\common files\aimersoft\aimersoft helper compact\ASHelper.exe mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [ProfilerU] c:\program files\saitek\sd6\software\ProfilerU.exe mRun: [saiMfd] c:\program files\saitek\sd6\software\SaiMfd.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYASwBQAEMAQgAtADYAQgBXAEYATQAtAFQAUgBMAFEAUgAtAEIAUgBVAEgAUAAtAEMAUAA4ADYARwA"&"inst=NwA3AC0ANAA1ADIAMAA5ADgAMQA2ADQALQBGAFAAOQArADYALQBCAEEAUgA5AEcAKwAxAC0AVABCADkAKwAyAC0ARgBMACsAOQAtAFgATwAzADYAKwAxAC0ARgA5AE0ANwBDACsAMwAtAEYAOQBNADEAMABCACsAMgA"&"prod=90"&"ver=9.0.872 dRunOnce: [DeleteEngineAfterUpdate] reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine /f StartupFolder: c:\users\harry\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_294823.exe mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: Free YouTube Download - c:\users\harry\appdata\roaming\dvdvideosoftiehelpers\freeytvdownloader.htm IE: Lookup on Merriam Webster - <no file> IE: Lookup on Wikipedia - <no file> IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} Trusted Zone: alipay.com Trusted Zone: alipay.com Trusted Zone: alisoft.com Trusted Zone: alisoft.com Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com Trusted Zone: taobao.com Trusted Zone: taobao.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{4632C2DB-5409-4BAA-8201-1EC80E333038} : DHCPNameServer = 192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs= c:\windows\system32\guard32.dll SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg Hosts: 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\harry\appdata\roaming\mozilla\firefox\profiles\bhwpeyre.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=112050&tt=3012_2&babsrc=HP_ss&mntrId=7c6c3a34000000000000001966bcd065 FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=112050&tt=3012_2&babsrc=KW_ss&mntrId=7c6c3a34000000000000001966bcd065&q= FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin.dll FF - plugin: c:\program files\battlelog web plugins\1.122.0\npesnlaunch.dll FF - plugin: c:\program files\battlelog web plugins\sonar\0.70.4\npesnsonar.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwangwang.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\harry\appdata\local\facebook\messenger\2.1.4590.0\npFbDesktopPlugin.dll FF - plugin: c:\users\harry\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\users\harry\appdata\local\roblox\versions\version-fa4cea1530284e83\NPRobloxProxy.dll FF - plugin: c:\users\harry\appdata\locallow\sony online entertainment\npsoe.dll FF - plugin: c:\users\harry\appdata\locallow\sony online entertainment\npsoeact.dll FF - plugin: c:\users\harry\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll . ---- FIREFOX POLICIES ---- FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112050&tt=3012_2 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q= FF - user.js: extensions.BabylonToolbar.id - 7c6c3a34000000000000001966bcd065 FF - user.js: extensions.BabylonToolbar.instlDay - 15549 FF - user.js: extensions.BabylonToolbar.vrsn - 1.5.29.1 FF - user.js: extensions.BabylonToolbar.vrsni - 1.5.29.1 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.29.120:16:07 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - sst FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false . ============= SERVICES / DRIVERS =============== . . =============== File Associations =============== . FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [userChoice] . =============== Created Last 30 ================ . 2073-04-13 21:17:26 203576 ----a-w- c:\program files\microsoft games\age of empires iii\autopatcher2.exe 2012-11-20 19:10:14 413696 ----a-w- c:\windows\system32\wrap_oal.dll 2012-11-20 19:10:14 110592 ----a-w- c:\windows\system32\OpenAL32.dll 2012-11-20 19:10:01 2873820 ------w- c:\windows\system32\Sens_oal.dll 2012-11-15 01:31:46 -------- d-----w- c:\users\harry\.swt 2012-11-14 03:19:08 2557288 ----a-w- c:\windows\system32\nvsvcr.dll 2012-11-14 02:15:10 75776 ----a-w- c:\windows\system32\synceng.dll 2012-11-14 02:14:51 2047488 ----a-w- c:\windows\system32\win32k.sys 2012-10-30 02:03:58 32832 ----a-w- c:\program files\common files\microsoft shared\vsto\10.0\microsoft visual studio 2010 tools for office runtime (x86)\install.res.1028.dll 2012-10-30 02:03:56 48192 ----a-w- c:\program files\common files\microsoft shared\vsto\10.0\microsoft visual studio 2010 tools for office runtime (x86)\install.res.1033.dll 2012-10-30 02:03:56 32320 ----a-w- c:\program files\common files\microsoft shared\vsto\10.0\microsoft visual studio 2010 tools for office runtime (x86)\install.res.2052.dll 2012-10-30 02:03:54 597040 ----a-w- c:\program files\common files\microsoft shared\vsto\10.0\microsoft visual studio 2010 tools for office runtime (x86)\install.exe . ==================== Find3M ==================== . 2012-10-17 15:16:54 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-17 15:16:54 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-17 15:16:46 9575864 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe 2012-10-11 02:15:04 1867112 ----a-w- c:\windows\system32\nvcuvenc.dll 2012-10-11 02:15:00 2574696 ----a-w- c:\windows\system32\nvcuvid.dll 2012-10-11 02:14:50 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll 2012-10-11 02:14:50 12501352 ----a-w- c:\windows\system32\nvwgf2um.dll 2012-10-11 02:14:46 17559912 ----a-w- c:\windows\system32\nvcompiler.dll 2012-10-11 02:14:44 2428776 ----a-w- c:\windows\system32\nvapi.dll 2012-10-11 02:14:42 7697768 ----a-w- c:\windows\system32\nvcuda.dll 2012-10-11 02:14:28 10837352 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-10-11 02:14:22 19906920 ----a-w- c:\windows\system32\nvoglv32.dll 2012-10-11 02:14:22 1009512 ----a-w- c:\windows\system32\nvdispco32.dll 2012-10-11 02:14:16 6127464 ----a-w- c:\windows\system32\nvopencl.dll 2012-10-11 02:14:16 15309160 ----a-w- c:\windows\system32\nvd3dum.dll 2012-10-08 07:56:24 1800704 ----a-w- c:\windows\system32\jscript9.dll 2012-10-08 07:48:03 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-10-08 07:47:44 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-10-08 07:44:05 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-10-08 07:43:21 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-10-08 07:40:56 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-10-02 19:29:42 645992 ----a-w- c:\windows\system32\nvvsvc.exe 2012-10-02 19:29:41 62312 ----a-w- c:\windows\system32\nvshext.dll 2012-10-02 19:29:41 108392 ----a-w- c:\windows\system32\nvmctray.dll 2012-10-02 19:29:22 2853224 ----a-w- c:\windows\system32\nvsvc.dll 2012-10-02 19:28:53 3965288 ----a-w- c:\windows\system32\nvcpl.dll 2012-10-02 18:15:52 430952 ----a-w- c:\windows\system32\nvStreaming.exe 2012-09-30 00:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-09-13 13:28:08 2048 ----a-w- c:\windows\system32\tzres.dll 2012-09-05 00:23:17 348160 ----a-w- c:\windows\system32\msvcr71.dll 2012-09-05 00:23:17 1700352 ----a-w- c:\windows\system32\gdiplus.dll 2012-09-01 02:09:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll 2012-08-29 11:27:41 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-08-29 11:27:41 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe . ============= FINISH: 17:46:31.18 =============== Attach.TXt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . . ==== Disk Partitions ========================= . . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) 10 button usb64 Controller 32 Bit HP CIO Components Installer AC3Filter 1.63b Acrobat.com Adobe Acrobat Connect Add-in Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Drive CS4 Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Fonts All Adobe Linguistics CS4 Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Support Adobe Reader X (10.1.4) Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Shockwave Player 11.6 Adobe Type Support CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Aimersoft DRM Media Converter(Build 1.5.3.0) Aimersoft Video Converter Ultimate(Build 4.2.4.0) Amazon MP3 Downloader 1.0.15 Aspell English Dictionary-0.50-2 ATI Catalyst Install Manager Audiosurf Battlefield Play4Free Battlelog Web Plugins BitTorrent Black & White® 2 BlackBerry Desktop Software 6.1 BlackBerry Device Software Updater BlackBerry Device Software v6.0.0 for the BlackBerry 9800 smartphone Bonjour CCleaner COMODO Internet Security Connect Core Temp version 0.99.7 Counter-Strike Counter-Strike: Source Creative Audio Control Panel Creative Software AutoUpdate Creative Sound Blaster Properties Creative WaveStudio 7 D3DX10 Daniusoft DVD to PC Ripper(Build 2.1.0.14) Defraggler Desktop Ticker 1.6.0 Diablo III Digsby Download Updater (AOL LLC) Elasto Mania ERUNT 1.1j ESN Sonar ffdshow v1.1.3476 [2010-06-15] FileZilla Client 3.5.3 FOREXTraderPro Game Room GIMP 2.6.11 GLtron version 0.71-beta GNU Aspell 0.50-3 Google AdWords Editor Google Apps Google Chrome Google Earth Google Gears Google SketchUp 7 Google Talk (remove only) Google Toolbar for Internet Explorer Google Update Helper Google Updater GTK+ Runtime 2.14.7 rev a (remove only) Haali Media Splitter Half-Life 2 Half-Life 2: Deathmatch Half-Life 2: Lost Coast HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2542054) Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2635973) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2280741) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2284668) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2295689) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2420513) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2452649) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2455033) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2485545) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982517) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982721) Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB983233) HP My Display Inkscape 0.48.1 Java Auto Updater Java 6 Update 32 Java 7 Update 5 JavaFX 2.1.1 Junk Mail filter update K-Lite Codec Pack 5.7.0 (Full) kuler MagicDisc 2.7.106 Malwarebytes Anti-Malware version 1.65.1.1000 Mesh Runtime Messenger Companion Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Application Error Reporting Microsoft Easy Assist v2 Microsoft Flight Microsoft Flight Simulator X Demo Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Help Viewer 1.1 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SkyDrive Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft Visual C++ Compilers 2010 Standard - enu - x86 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 Microsoft Visual C++ 2010 Express - ENU Microsoft Visual Studio 2010 Service Pack 1 Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Microsoft WSE 3.0 Runtime MiracleTrafficBot Mozilla Firefox 12.0 (x86 en-US) Mozilla Maintenance Service MS Access 97 SP2 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Munch My Articles Music Manager NEF to JPG Notepad++ NVIDIA 3D Vision Controller Driver NVIDIA 3D Vision Controller Driver 306.23 NVIDIA 3D Vision Driver 306.97 NVIDIA Control Panel 306.97 NVIDIA Graphics Driver 306.97 NVIDIA HD Audio Driver 1.3.18.0 NVIDIA Install Application NVIDIA PhysX NVIDIA PhysX System Software 9.12.0604 NVIDIA Stereoscopic 3D Driver NVIDIA Update 1.10.8 NVIDIA Update Components OGA Notifier 2.0.0048.0 OnlyWire Origin PC Remote PDF Settings CS4 PeerBlock 1.1 (r518) Photoshop Camera Raw Pidgin Ping Machine Pivot Software Project64 1.6 PunkBuster Services PVSonyDll QuickTime RAR Password Recovery v1.1 RC17 (remove only) Realtek Ethernet Controller Driver For Windows Vista Realtek High Definition Audio Driver Roblox for Harry RollerCoaster Tycoon 3 Platinum SDK SecondLifeViewer (remove only) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687314) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2687315) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Segoe UI SEO PowerSuite Sid Meier's Civilization 4 SimCity 4 Deluxe SimCity™ Societies Skype Click to Call Skype™ 5.10 Smart Technology Programming Software 7.0.2.7 Source SDK Base 2006 Speccy SPORE™ Steam Suite Shared Configuration CS4 swMSM Take On Helicopters Take On Hinds TextPad 5 The Sims™ 3 The Works version 3.2 Toy Soldiers Train Simulator 2013 TVersity Codec Pack 1.2 TVersity Media Server 1.8 Beta Tweaking.com - Registry Backup Tweaking.com - Windows Repair (All in One) U3Launcher Ulead PhotoImpact 12 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760413) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update or Uninstall SENukeX VLC media player 1.0.1 VTFEdit 1.3.3 West Point Bridge Designer 2011 (2nd Edition) (remove only) Winamp Winamp Detector Plug-in Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live OneCare safety scanner Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Encoder 9 Series Windows Mobile Device Center Windows Mobile Device Updater Component WinRAR archiver WinZip 14.5 WordWeb World of Warcraft WPF Toolkit February 2010 (Version 3.5.50211.1) XMind Yahoo! Messenger Zune Zune Language Pack (CHS) Zune Language Pack (CHT) Zune Language Pack (CSY) Zune Language Pack (DAN) Zune Language Pack (DEU) Zune Language Pack (ELL) Zune Language Pack (ESP) Zune Language Pack (FIN) Zune Language Pack (FRA) Zune Language Pack (HUN) Zune Language Pack (IND) Zune Language Pack (ITA) Zune Language Pack (JPN) Zune Language Pack (KOR) Zune Language Pack (MSL) Zune Language Pack (NLD) Zune Language Pack (NOR) Zune Language Pack (PLK) Zune Language Pack (PTB) Zune Language Pack (PTG) Zune Language Pack (RUS) Zune Language Pack (SVE) . ==== End Of File ===========================
  15. The attached screenshot is my issue . No internet connection... Keep with me and I apologize for the excessively large screenshots. The error message caught my attention, though right after this scan. I couldn't "analyze this" I got the 'No internet connection available' pop up. I began searching my PC for issues to resolve another issue that brings up the same internet error. The game League of Legends. I came across this error about 2 weeks ago out of random. I hopped back on my PC after not using it for maybe a month solid (I was using my laptop). And I ended up uninstalling and attempting to reinstall the game. And everytime i try and reinstall the game (even after a fresh client download) I get a very similar No internet connection error. Attached is a HijackThis log. The only thing i had up was this tab in google. Please help me understand if there is anything obviously wrong with these results that are reparable. = = = = = = Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 5:59:20 PM, on 11/24/2012 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16455) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Users\Harry\Desktop\extra\OdoPlus.exe C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\Saitek\SD6\Software\ProfilerU.exe C:\Program Files\Saitek\SD6\Software\SaiMfd.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehmsas.exe C:\ProgramData\U3\U3Launcher\LaunchU3.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\wbem\unsecapp.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Users\Harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) R3 - URLSearchHook: (no name) - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file) O1 - Hosts: 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe O4 - HKLM\..\Run: [OdoPlus] C:\Users\Harry\Desktop\extra\OdoPlus.exe /autorun O4 - HKLM\..\Run: [Aimersoft Helper Compact.exe] C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe O4 - HKLM\..\Run: [saiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYASwBQAEMAQgAtADYAQgBXAEYATQAtAFQAUgBMAFEAUgAtAEIAUgBVAEgAUAAtAEMAUAA4ADYARwA"&"inst=NwA3AC0ANAA1ADIAMAA5ADgAMQA2ADQALQBGAFAAOQArADYALQBCAEEAUgA5AEcAKwAxAC0AVABCADkAKwAyAC0ARgBMACsAOQAtAFgATwAzADYAKwAxAC0ARgA5AE0ANwBDACsAMwAtAEYAOQBNADEAMABCACsAMgA"&"prod=90"&"ver=9.0.872 O4 - HKCU\..\Run: [Google Update] "C:\Users\Harry\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-18\..\RunOnce: [DeleteEngineAfterUpdate] reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine /f (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [DeleteEngineAfterUpdate] reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine /f (User 'Default user') O4 - Global Startup: LaunchU3.exe.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Users\Harry\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://*.alipay.com O15 - Trusted Zone: http://*.alisoft.com O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O15 - Trusted Zone: http://*.taobao.com O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creat...13/CTPIDPDE.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creat...015/CTSUEng.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creat...21022/CTPID.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- End of file - 12425 bytes Thanks for your time, Harrison
  16. Hello, Maniac I have a very similar problem and I was hoping you could help interpret my logs. I just ran TDSSKiller and OTL scans. I have both the logs. It would be greatly appreciated if you could help.
  17. I just removed a virus a day ago. I suppose this is the last of it... No matter what I'm doing I will get the message "TCP/IP.exe 'or PING.EXE' has stopped working" and proceed to terminate or check for solution ; as it prompts me to. I will then go to check my task manger and see the process is still running and not to my surprise, it is using mass amounts of my PC's memory. I try to terminate the process by hand in the task manger and it works, but it reappears almost immediately( only using about 3k instead of 76-90k of memory. I'm not sure what this is saying about the security of my computer or the stability of my PC. I haven't seen any pop-ups or advertisements, though. How can I stop this from happening so often and what is the purpose of the process PING.EXE? I have malaware-bytes pro and MSE. It seems to be an effective combo. Any actual related feedback would be appreciated. It seems all the threads I have read are just diluted crap. PLEASE, ONLY POST RELATED INFO!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.