Website URL






  1. Today, from out of the blue, my Chrome web browser notified me that: "Chrome detected that your browser settings may have been changed without your knowledge. Would you like to reset them to their original defaults?".... what just happened? I did some searching around, and found this news article, published within the last 8 hours. After reading suggestions by Google that I may have acquired malware of a sort, I decided to do a scan with Malwarebytes Pro in safemode. It found "hijack.drives" (attached), which it then prompted to quarantine. How the heck did this get on my system, and is it something I should be concerned about?? The name of the find itself doesn't sound very friendly, and the fact my browser settings was changed by some unknown entity has had me paranoid. I have no idea if this "hijack.drives" is linked to the Chrome problem above. A pinned listing posted today on the Google Chrome Forums state that the 'reset' message is related to Chrome extensions. I found another article posted today regarding cleanup written by the vice-president of engineering. Can someone help me make sense of all this? I don't quite know what to do. A lot of the extensions I use contain sensitive information, such as the Lastpass extension which contains all my passwords. I'm hoping that nothing else inside my browser was exploited except browser settings. I'm tempted to do a System Restore to reverse what has happened:
  2. https://forums.malwarebytes.org/index.php?showtopic=125369 I was browsing the forums just about now and I saw the little shield thing on the google chrome URL Bar, and I'm wondering, what does it do/mean? I'm interested, because its on the MBAM Forums and I'm slightly paranoid about PC issues.
  3. HELLO! ok, so i just got my pc two weeks ago, and i havnt really downloaded anything on it. But, no matter how many times i try to set my homepage or settings to google, when i press google chrome, it opens up three windows instead of one all with www.delta - something websites. and MCAFEE tells me every now and then someone with the ip address is on my computer, i looked it up and i think its in italy somewhere. I went a little overboard with the anti viruses and have ad-aware antivirus, mcafee antivirus, norton anti virus, and SUPERantivirus. none of these detect anything wrong, but im sure there is still malware or a false program on my computer. can it be one of those anti virus programs i installed? i tried scanning each of them with each others program, but i dont know if that would work? any help would be great! im not good with computers and racking my brain here!
  4. Ever since i had installed the adblock plugin for my google chrome browser, I've been getting various types of ads, such as: 1) the highlighted text ad: http://snag.gy/CtKoh.jpg these things highlight texts that are not links and are really annoying when i accidentally click them, thinking its a link. 2) the classic pop-up ad : http://snag.gy/3xxV8.jpg 3) alnaddy.com : http://snag.gy/EOjXi.jpg This site is the most annoying as everytime i start up google chrome (my default browser) this comes as the home page when I clearly set it to google, and everytime i'm just browsing this site pops up for no reason. Pls help. Pc details: OS: Windows 7 Ultimate Processor: 64-bit Google chrome plugin: https://chrome.google.com/webstore/detail/adblock/gighmmpiobklfepjocnamgkkbiglidom?hl=en PLS HELP !!!
  5. Esta é a mensagem que tenho recebido constantemente do AVAST. Sempre que abro o browser ...sempre abre uma segunda janela que foi direcionada para outros dominios. como exemplo: o ultimo foi este: http://newsalert.timehares.com/?sov=62570201&hid=fpnprltlhjhjhvnj&ctrl1=nodl&id=XNSX.nodl O avast entra em ação e mostra essa mensagem URL: http://newsalert.timehares.com/?sov Process: C:\Users\Sandro Zanini\AppData\Local\Map... Infection: URL:Mal Tenho instalado também o Malwarebytes mas mesmo fazendo scan completo não consegui me livrar dessa praga. Seguindo as instruções, segue os log do DDS: Agradeço antecipadamente. Sandro Zanini attach.txt dds.txt
  6. Recently, only on google chrome and only regarding the google search on it, am I encountering a redirect issue. Usually I am being sent to sites which are just advertisment sites or worse such as virus attack sites, which were all blocked by Norton. As of this morning, I have run Malwarebytes, Norton, Unhack Me and TDSS Killer by Kaspersky and they have found nothing. Here are the results of the DDS. Attach.txt DDS.txt
  7. I've used both Norton Anti-virus, Malwarebytes, Unhack Me and a TDSS Killer from Kasparky (sp) to try to deal with an issue I'm having with Google Chrome but none of them can find the malware. When I use Google Search on Google Chrome (issue does not arise on other search engines or on IE9 or the latest Firefox) I get redirected to a website which either is an ad website or a website trying to launch attacks on my computer, which Norton blocks. I ran all 4 of the anti-virus checkers today and nothing was detected, each running one after the other and occuring while no other processes were turned on by myself. Any help would be greatly appreciated
  8. Hi, hoping you can help me. It seems a search engine called "Mystart" has taken over Google Chrome and I can't get rid of it. DDS logs attached below. Thanks for your help! Nick . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by Nick at 19:02:53 on 2012-05-22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3710.2428 [GMT -4:00] . AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Kontiki\KService.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Norton 360\Engine\\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Norton 360\Engine\\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe C:\Program Files\Brownie\BrStsWnd.exe C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\ehome\ehtray.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe C:\Program Files\HP Connections\6811507\Program\HP Connections.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Windows\ehome\ehsched.exe C:\Windows\ehome\ehRecvr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Brownie\brpjp04a.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\hp\kbd\kbd.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\mmc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://search.myheritage.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\\ips\IPSBHO.DLL BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\\coIEPlg.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" uRun: [skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [CCUTRAYICON] FactoryMode mRun: [iAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [EEventManager] c:\program files\epson\creativity suite\event manager\EEventManager.exe mRun: [updatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [Family Tree Builder Update] c:\program files\myheritage\bin\FTBCheckUpdates.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [brStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [brdefprn] c:\program files\brother\brhl3070\Brdefprn.exe -d mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\users\nick\appdata\roaming\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\logitech webcam software\eReg.exe StartupFolder: c:\users\nick\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\users\nick\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote Table Of Contents.onetoc2 StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpconn~1.lnk - c:\program files\hp connections\6811507\program\HP Connections.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {363D09D0-9D94-4880-86B2-7A8801920854} - hxxp://org-au.anytime-tv.com/anytime_au/cab/AnytimeAU_3_5_0_20.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - hxxp://org-au.anytime-tv.com/anytime_au/cab/Entriq_3_7_0_2_Silent.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = TCP: Interfaces\{5F936592-C249-46FD-BE32-76BD917395A6} : DhcpNameServer = TCP: Interfaces\{B155EA8A-F1B9-4530-BEC3-170402C6D935} : DhcpNameServer = Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0602010.005\symds.sys [2012-5-19 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0602010.005\symefa.sys [2012-5-19 905336] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.2.0.9\definitions\bashdefs\20120507.001\BHDrvx86.sys [2012-5-19 821880] R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\0602010.005\ccsetx86.sys [2012-5-19 132744] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.2.0.9\definitions\ipsdefs\20120518.002\IDSvix86.sys [2012-5-21 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0602010.005\ironx86.sys [2012-5-19 149624] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0602010.005\symtdiv.sys [2012-5-19 345208] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2006-9-3 208896] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-5-4 21504] R2 N360;Norton 360;c:\program files\norton 360\engine\\ccsvchst.exe [2012-5-19 138232] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2012-1-23 92592] R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2007-1-25 2831232] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-5-19 106104] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-17 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-4-8 116648] S2 IntelDHSvcConf;Intel DH Service;c:\program files\intel\inteldh\intel media server\tools\IntelDHSvcConf.exe [2006-5-10 29696] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-1-31 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-2 257696] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-4-8 116648] S3 MCLServiceATL;Intel® Application Tracker;c:\program files\intel\inteldh\intel media server\shells\MCLServiceATL.exe [2006-9-11 167936] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-17 753504] . =============== Created Last 30 ================ . 2012-05-20 00:12:47 345208 ----a-r- c:\windows\system32\drivers\n360\0602010.005\symtdiv.sys 2012-05-20 00:12:47 318584 ----a-r- c:\windows\system32\drivers\n360\0602010.005\symnets.sys 2012-05-20 00:12:46 905336 ----a-r- c:\windows\system32\drivers\n360\0602010.005\symefa.sys 2012-05-20 00:12:46 574072 ----a-w- c:\windows\system32\drivers\n360\0602010.005\srtsp.sys 2012-05-20 00:12:46 340088 ----a-r- c:\windows\system32\drivers\n360\0602010.005\symds.sys 2012-05-20 00:12:46 32888 ----a-w- c:\windows\system32\drivers\n360\0602010.005\srtspx.sys 2012-05-20 00:12:46 149624 ----a-r- c:\windows\system32\drivers\n360\0602010.005\ironx86.sys 2012-05-20 00:12:46 132744 ----a-r- c:\windows\system32\drivers\n360\0602010.005\ccsetx86.sys 2012-05-20 00:12:42 -------- d-----w- c:\windows\system32\drivers\n360\0602010.005 2012-05-20 00:09:41 141944 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2012-05-20 00:09:41 -------- d-----w- c:\program files\Symantec 2012-05-20 00:09:08 -------- d-----w- c:\windows\system32\drivers\N360 2012-05-20 00:09:06 -------- d-----w- c:\program files\Norton 360 2012-05-20 00:08:48 -------- d-----w- c:\program files\NortonInstaller 2012-05-16 16:29:23 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-05-16 16:29:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-05-16 16:07:54 -------- d-----w- c:\users\nick\appdata\local\temp 2012-05-16 16:07:02 -------- d-sh--w- C:\$RECYCLE.BIN 2012-05-16 15:46:06 98816 ----a-w- c:\windows\sed.exe 2012-05-16 15:46:06 518144 ----a-w- c:\windows\SWREG.exe 2012-05-16 15:46:06 256000 ----a-w- c:\windows\PEV.exe 2012-05-16 15:46:06 208896 ----a-w- c:\windows\MBR.exe 2012-05-16 15:36:58 -------- d-----w- c:\programdata\blekko toolbars 2012-05-16 15:36:54 -------- d-----w- c:\program files\blekkotb_soc 2012-05-16 15:09:58 107368 ----a-r- c:\windows\system32\GEARAspi.dll 2012-05-16 14:40:58 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-16 14:40:58 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-05-16 14:40:57 2044928 ----a-w- c:\windows\system32\win32k.sys 2012-05-03 01:53:10 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-03 01:35:39 -------- d-----w- c:\users\nick\appdata\roaming\Malwarebytes 2012-05-03 01:35:33 -------- d-----w- c:\programdata\Malwarebytes 2012-05-02 03:54:01 -------- d-----w- c:\users\nick\appdata\local\NPE . ==================== Find3M ==================== . 2012-05-16 14:56:14 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-30 12:39:11 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-03-20 23:28:50 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys 2012-03-01 14:46:01 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2012-03-01 14:46:01 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2012-02-29 15:11:45 5120 ----a-w- c:\windows\system32\wmi.dll 2012-02-29 15:11:42 172032 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 15:09:53 157696 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 14:08:47 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2012-02-29 13:44:50 683008 ----a-w- c:\windows\system32\d2d1.dll 2012-02-29 13:41:40 1069056 ----a-w- c:\windows\system32\DWrite.dll 2012-02-29 13:32:37 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-02-28 01:18:55 1799168 ----a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 ----a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 19:03:58.68 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 17/04/2007 3:28:31 AM System Uptime: 22/05/2012 6:47:16 PM (1 hours ago) . Motherboard: ASUSTek Computer INC. | | LEONITE Processor: Intel® Core2 CPU 6400 @ 2.13GHz | Socket 775 | 2133/266mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 292 GiB total, 31.964 GiB free. D: is FIXED (NTFS) - 6 GiB total, 0.584 GiB free. E: is FIXED (NTFS) - 466 GiB total, 165.66 GiB free. I: is Removable J: is Removable K: is Removable L: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: HP 802.11b/g Wireless Network Adapter Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&33087CF&0&28F0 Manufacturer: Atheros Communications Inc. Name: HP 802.11b/g Wireless Network Adapter PNP Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&33087CF&0&28F0 Service: athr . Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318} Description: CD-ROM Drive Device ID: IDE\CDROMHL-DT-ST_DVDRRW_GSA-H30L________________S755____\4&30F406D4&1&0.1.0 Manufacturer: (Standard CD-ROM drives) Name: HL-DT-ST DVDRRW GSA-H30L PNP Device ID: IDE\CDROMHL-DT-ST_DVDRRW_GSA-H30L________________S755____\4&30F406D4&1&0.1.0 Service: cdrom . Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318} Description: CD-ROM Drive Device ID: IDE\CDROMHL-DT-ST_DVDRAM_GH22NS40________________NL01____\4&30F406D4&1&0.3.0 Manufacturer: (Standard CD-ROM drives) Name: HL-DT-ST DVDRAM GH22NS40 PNP Device ID: IDE\CDROMHL-DT-ST_DVDRAM_GH22NS40________________NL01____\4&30F406D4&1&0.3.0 Service: cdrom . ==== System Restore Points =================== . RP1599: 19/05/2012 6:24:42 PM - Windows Update RP1600: 20/05/2012 4:03:05 PM - Scheduled Checkpoint RP1601: 21/05/2012 9:55:38 AM - Scheduled Checkpoint . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) ABBYY FineReader 6.0 Sprint Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.3) Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoImpression 5 Audacity 1.2.6 AutoUpdate Bonjour Brother HL-3070CW ComparatorPro CyberLink PhotoNow CyberLink PowerDirector DivX Enhanced Multimedia Keyboard Solution EPSON Attach To Email EPSON Copy Utility 3 EPSON Event Manager EPSON File Manager EPSON Scan EPSON Scan Assistant Family Tree Maker 2010 GearDrvs Google Apps Migration For Microsoft Outlook® Google Apps Sync™ for Microsoft Outlook® Google Calendar Sync Google Chrome Google Earth Plug-in Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Connections (remove only) HP Customer Experience Enhancements HP Easy Setup - Core HP Easy Setup - Frontend HP On-Screen Caps/Num/Scroll Lock Indicator HP Picasso Media Center Add-In iCloud Intel® Matrix Storage Manager Intel® Viiv™ Software iPhone Configuration Utility iTunes Japanese Fonts Support For Adobe Reader 8 Java Auto Updater Java 6 Update 29 LightScribe Logitech Webcam Software MainConcept for Software Encoder Malwarebytes Anti-Malware version Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Primary Interoperability Assemblies 2005 Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Microsoft WSE 3.0 MobileMe Control Panel MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) muvee autoProducer 5.0 MyHeritage Family Tree Builder NETGEAR Print Server Software Norton 360 NVIDIA Drivers OGA Notifier 2.0.0048.0 OpenOffice.org Installer 1.0 PerfV350 User's Guide Photo Viewer V208G2 PowerDirector Express PowerDVD PowerProducer Python 2.4.3 QuickTime RealPlayer Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Safari Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB979332) Skype™ 5.8 SmartSound Quicktracks Plugin Sony USB Driver Symantec Technical Support Web Controls TomTom HOME TomTom HOME Visual Studio Merge Modules Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2598306) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) WARP Video 2 Windows Media Encoder 9 Series Xiph QuickTime Components . ==== Event Viewer Messages From Past Week ======== . 22/05/2012 6:49:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom i8042prt 22/05/2012 6:49:16 PM, Error: Service Control Manager [7001] - The NVIDIA Display Driver Service service depends on the nvlddmkm service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 22/05/2012 6:49:16 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 22/05/2012 6:49:16 PM, Error: Service Control Manager [7000] - The LVSrvLauncher service failed to start due to the following error: The system cannot find the file specified. 22/05/2012 6:47:42 PM, Error: atikmdag [45062] - CRT invalid display type 19/05/2012 8:18:22 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt 16/05/2012 6:57:53 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom 16/05/2012 12:05:20 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 16/05/2012 11:57:30 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 16/05/2012 11:44:56 AM, Error: Service Control Manager [7034] - The Process Monitor service terminated unexpectedly. It has done this 1 time(s). . ==== End Of File ===========================
