Jump to content

from my help post in general


Recommended Posts

Hello TakumiRyu! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Step 1

Please uninstall this application: µTorrent

Step 2

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

Step 3

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

aswMBR2-1.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

aswMBR2.png

In your next reply, post the following log files:

  • Malwarebytes' Anti-Malware log
  • aswMBR log
  • a new fresh DDS log

Link to post
Share on other sites

Hello Maniac here is what you asked for also I still cannot complete a full scan.

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.03.21.11

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 10.0.9200.16521

David Bado :: SAC-COM [administrator]

3/21/2013 10:01:18 AM

mbam-log-2013-03-21 (10-01-18).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 205606

Time elapsed: 4 minute(s), 10 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

aswMBR.txtattach.txtdds.txt

Link to post
Share on other sites

Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please post the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

good evening maniac here is the combo.txtComboFix 13-03-21.01 - David Bado 03/21/2013 16:28:59.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3764.2238 [GMT -7:00]

Running from: c:\users\David Bado\Downloads\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\Temp\log.txt

.

.

((((((((((((((((((((((((( Files Created from 2013-02-22 to 2013-03-22 )))))))))))))))))))))))))))))))

.

.

2013-03-22 01:25 . 2013-03-22 01:25 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-03-21 18:26 . 2013-03-21 23:24 -------- d-----w- c:\users\David Bado\AppData\Roaming\uTorrent

2013-03-21 16:05 . 2012-11-28 09:53 972264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1943EC62-1B52-4B44-92E7-7152BE2FAFCD}\gapaengine.dll

2013-03-21 16:03 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D7EAF4A-D002-445C-A947-23FCC9904F0C}\mpengine.dll

2013-03-21 00:23 . 2013-02-08 00:28 9162192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-03-14 15:52 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll

2013-03-14 15:52 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll

2013-03-14 15:52 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll

2013-03-14 15:52 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll

2013-03-14 15:52 . 2013-01-13 19:02 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll

2013-03-14 15:52 . 2013-01-13 18:32 465920 ----a-w- c:\windows\system32\WMPhoto.dll

2013-03-14 15:50 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys

2013-03-14 08:09 . 2013-03-14 08:09 -------- d-----w- C:\690384c18c2b00009514

2013-03-12 02:35 . 2012-11-28 09:53 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C2896185-F24F-4455-8088-6709BDC14D69}\gapaengine.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-02-12 05:45 . 2013-03-14 15:50 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-02-12 05:45 . 2013-03-14 15:50 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-02-12 05:45 . 2013-03-14 15:50 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-02-12 05:45 . 2013-03-14 15:50 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-02-12 04:48 . 2013-03-14 15:50 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-02-12 04:48 . 2013-03-14 15:50 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-01-30 10:53 . 2011-04-15 03:30 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-20 23:59 . 2013-01-20 23:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys

2013-01-20 23:59 . 2010-10-25 04:25 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys

2013-01-05 05:53 . 2013-02-12 20:23 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-01-05 05:00 . 2013-02-12 20:23 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-01-05 05:00 . 2013-02-12 20:23 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-01-04 05:46 . 2013-02-12 20:23 215040 ----a-w- c:\windows\system32\winsrv.dll

2013-01-04 04:51 . 2013-02-12 20:23 5120 ----a-w- c:\windows\SysWow64\wow32.dll

2013-01-04 04:43 . 2013-02-12 20:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2013-01-04 03:26 . 2013-02-12 20:23 3153408 ----a-w- c:\windows\system32\win32k.sys

2013-01-04 02:47 . 2013-02-12 20:23 25600 ----a-w- c:\windows\SysWow64\setup16.exe

2013-01-04 02:47 . 2013-02-12 20:23 7680 ----a-w- c:\windows\SysWow64\instnm.exe

2013-01-04 02:47 . 2013-02-12 20:23 2048 ----a-w- c:\windows\SysWow64\user.exe

2013-01-04 02:47 . 2013-02-12 20:23 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

2013-01-03 06:00 . 2013-02-12 20:23 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys

2013-01-03 06:00 . 2013-02-12 20:23 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2010-05-27 03:40 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-06 5629312]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-06-28 265984]

"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]

"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264]

"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584]

"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920]

"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-11 975952]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-17 421736]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/03/10 12:43;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2011-02-12 240112]

R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-06-10 40448]

R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]

R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-03 51712]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-04 1255736]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]

S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]

S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]

S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-13 140672]

S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/12/06 22:04];c:\program files (x86)\CyberLink\PowerDVD9\000.fcl [2010-08-16 17:54 146928]

S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2012-03-09 23816]

S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-11 321104]

S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]

S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]

S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2012-04-05 255376]

S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]

S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]

S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640]

S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]

S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2012-04-05 255376]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]

S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-21 287232]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-06-08 406056]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - ASWMBR

*Deregistered* - aswMBR

*Deregistered* - CLKMDRV10_9EC60124

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081192946-2027394010-2679772704-1001Core.job

- c:\users\David Bado\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-30 22:18]

.

2013-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081192946-2027394010-2679772704-1001UA.job

- c:\users\David Bado\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-30 22:18]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2010-05-27 03:42 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-29 11101800]

"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-10-22 325120]

"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216]

"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-06-10 324608]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-17 161304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-17 386584]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-17 415256]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Wow6432Node-HKCU-Run-mdsad - c:\users\David Bado\AppData\Roaming\mdsad.dll

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

Toolbar-Locked - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}]

"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD9\000.fcl"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*2*€‚ÎD]

@Class="Shell"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*2*€‚ÎD\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*C*+Œ?]

@Class="Shell"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*C*+Œ?\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*V*D*R**­½B\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*V*D*R*hïQ'\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*Ä#\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*ºrÄ%\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*

/T\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*G”G\¢**Œ]

@Class="Shell"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*G”G\¢**Œ\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*mÇþ,\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*4× +\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*îØe$\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*ýØ +\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*ÄÙ +\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_*T*h*e*_*P*r*i*n*c*e*s*s*e*s*'*_*R*o*n*d*åÙ +\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ï*/j]

@Class="Shell"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ï*/j\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Ä.©DÜ*€í]

@Class="Shell"

.

[HKEY_USERS\S-1-5-21-4081192946-2027394010-2679772704-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Ä.©DÜ*€í\OpenWithList]

@Class="Shell"

"a"="vlc.exe"

"MRUList"="a"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]

@="?????????????????? v1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]

@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]

@="?????????????????? v2"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]

@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-03-21 18:29:21

ComboFix-quarantined-files.txt 2013-03-22 01:29

.

Pre-Run: 132,415,430,656 bytes free

Post-Run: 132,367,511,552 bytes free

.

- - End Of File - - FF6A3F4FF7A945413215B231232907A8

Link to post
Share on other sites

Step 1

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:

  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

Step 2

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\ESET\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic

In your next reply, post the following log files:

  • MiniToolBox log
  • ESET Online Scanner log

Link to post
Share on other sites

here you go maniacMiniToolBox by Farbar Version:05-03-2013

Ran by David Bado (administrator) on 22-03-2013 at 10:29:08

Running from "C:\Users\David Bado\Desktop"

Windows 7 Home Premium Service Pack 1 (X64)

Boot Mode: Normal

***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.

No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

Broadcom 802.11n Network Adapter = Wireless Network Connection (Connected)

Broadcom NetLink Gigabit Ethernet = Local Area Connection (Media disconnected)

# ----------------------------------

# IPv4 Configuration

# ----------------------------------

pushd interface ipv4

reset

set global

popd

# End of IPv4 configuration

Windows IP Configuration

Host Name . . . . . . . . . . . . : SAC-Com

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Hybrid

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . : wistron.com

Description . . . . . . . . . . . : Broadcom NetLink Gigabit Ethernet

Physical Address. . . . . . . . . : 20-6A-8A-26-CE-F0

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Broadcom 802.11n Network Adapter

Physical Address. . . . . . . . . : 18-F4-6A-B1-2A-40

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Link-local IPv6 Address . . . . . : fe80::a14c:ce3e:476d:542c%10(Preferred)

IPv4 Address. . . . . . . . . . . : 192.168.0.13(Preferred)

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Lease Obtained. . . . . . . . . . : Friday, March 22, 2013 7:52:43 AM

Lease Expires . . . . . . . . . . : Friday, March 22, 2013 11:22:51 AM

Default Gateway . . . . . . . . . : 192.168.0.1

DHCP Server . . . . . . . . . . . : 192.168.0.1

DHCPv6 IAID . . . . . . . . . . . : 286848106

DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-14-8F-84-D3-18-F4-6A-B1-2A-40

DNS Servers . . . . . . . . . . . : 209.18.47.61

209.18.47.62

NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{4A9F373F-A789-44A3-9AEE-D8B96FC4CDF4}:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Microsoft ISATAP Adapter

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

IPv6 Address. . . . . . . . . . . : 2001:0:9d38:953c:288c:293b:5179:53a8(Preferred)

Link-local IPv6 Address . . . . . : fe80::288c:293b:5179:53a8%13(Preferred)

Default Gateway . . . . . . . . . : ::

NetBIOS over Tcpip. . . . . . . . : Disabled

Server: dns-cac-lb-01.rr.com

Address: 209.18.47.61

Name: google.com

Addresses: 2001:4860:4001:800::1007

74.125.224.37

74.125.224.38

74.125.224.39

74.125.224.40

74.125.224.41

74.125.224.46

74.125.224.32

74.125.224.33

74.125.224.34

74.125.224.35

74.125.224.36

Pinging google.com [74.125.224.135] with 32 bytes of data:

Reply from 74.125.224.135: bytes=32 time=63ms TTL=54

Reply from 74.125.224.135: bytes=32 time=25ms TTL=54

Ping statistics for 74.125.224.135:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 25ms, Maximum = 63ms, Average = 44ms

Server: dns-cac-lb-01.rr.com

Address: 209.18.47.61

Name: yahoo.com

Addresses: 98.139.183.24

206.190.36.45

98.138.253.109

Pinging yahoo.com [206.190.36.45] with 32 bytes of data:

Reply from 206.190.36.45: bytes=32 time=71ms TTL=50

Reply from 206.190.36.45: bytes=32 time=359ms TTL=50

Ping statistics for 206.190.36.45:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 71ms, Maximum = 359ms, Average = 215ms

Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================

Interface List

11...20 6a 8a 26 ce f0 ......Broadcom NetLink Gigabit Ethernet

10...18 f4 6a b1 2a 40 ......Broadcom 802.11n Network Adapter

1...........................Software Loopback Interface 1

15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter

13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface

===========================================================================

IPv4 Route Table

===========================================================================

Active Routes:

Network Destination Netmask Gateway Interface Metric

0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.13 25

127.0.0.0 255.0.0.0 On-link 127.0.0.1 306

127.0.0.1 255.255.255.255 On-link 127.0.0.1 306

127.255.255.255 255.255.255.255 On-link 127.0.0.1 306

192.168.0.0 255.255.255.0 On-link 192.168.0.13 281

192.168.0.13 255.255.255.255 On-link 192.168.0.13 281

192.168.0.255 255.255.255.255 On-link 192.168.0.13 281

224.0.0.0 240.0.0.0 On-link 127.0.0.1 306

224.0.0.0 240.0.0.0 On-link 192.168.0.13 281

255.255.255.255 255.255.255.255 On-link 127.0.0.1 306

255.255.255.255 255.255.255.255 On-link 192.168.0.13 281

===========================================================================

Persistent Routes:

None

IPv6 Route Table

===========================================================================

Active Routes:

If Metric Network Destination Gateway

13 58 ::/0 On-link

1 306 ::1/128 On-link

13 58 2001::/32 On-link

13 306 2001:0:9d38:953c:288c:293b:5179:53a8/128

On-link

10 281 fe80::/64 On-link

13 306 fe80::/64 On-link

13 306 fe80::288c:293b:5179:53a8/128

On-link

10 281 fe80::a14c:ce3e:476d:542c/128

On-link

1 306 ff00::/8 On-link

13 306 ff00::/8 On-link

10 281 ff00::/8 On-link

===========================================================================

Persistent Routes:

None

========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)

Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)

Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)

Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)

Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

Catalog5 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog5 09 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)

Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)

x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)

x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

x64-Catalog5 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)

x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)

x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)

x64-Catalog5 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog5 09 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)

x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:

==================

Error: (03/22/2013 10:13:14 AM) (Source: SideBySide) (User: )

Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.

The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (03/21/2013 06:57:35 PM) (Source: Application Hang) (User: )

Description: The program mbam.exe version 1.70.0.9 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1130

Start Time: 01ce269e28f91497

Termination Time: 0

Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

Report Id: d6a7ff4e-9293-11e2-a751-206a8a26cef0

Error: (03/21/2013 01:30:09 PM) (Source: SideBySide) (User: )

Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.

The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (03/21/2013 10:25:58 AM) (Source: Application Hang) (User: )

Description: The program mbam.exe version 1.70.0.9 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: a60

Start Time: 01ce265582bd13f4

Termination Time: 8

Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

Report Id: 5f855d24-924c-11e2-a751-206a8a26cef0

Error: (03/20/2013 06:17:49 PM) (Source: Application Hang) (User: )

Description: The program mbam.exe version 1.70.0.9 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 15dc

Start Time: 01ce25cfd0d7f317

Termination Time: 16

Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

Report Id: 2237b8ae-91c5-11e2-a673-206a8a26cef0

Error: (03/20/2013 03:25:02 PM) (Source: Application Hang) (User: )

Description: The program mbam.exe version 1.70.0.9 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 82c

Start Time: 01ce25b685278d35

Termination Time: 16

Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

Report Id: 0058b33d-91ad-11e2-a673-206a8a26cef0

Error: (03/20/2013 03:16:23 PM) (Source: Application Hang) (User: )

Description: The program SoftwareUpdate.exe version 2.1.3.127 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: e0c

Start Time: 01ce25b7dc361faa

Termination Time: 0

Application Path: C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe

Report Id: c860f0f2-91ab-11e2-a673-206a8a26cef0

Error: (03/20/2013 02:41:48 PM) (Source: Application Hang) (User: )

Description: The program mbam.exe version 1.70.0.9 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 14f0

Start Time: 01ce25b10ebe2664

Termination Time: 0

Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

Report Id: f10fab5a-91a6-11e2-baa9-206a8a26cef0

Error: (03/20/2013 01:38:06 AM) (Source: SideBySide) (User: )

Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.

The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (03/18/2013 07:15:42 PM) (Source: SideBySide) (User: )

Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.

The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

System errors:

=============

Error: (03/22/2013 07:53:44 AM) (Source: DCOM) (User: NT AUTHORITY)

Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (03/21/2013 06:25:50 PM) (Source: Service Control Manager) (User: )

Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (03/21/2013 06:25:09 PM) (Source: Application Popup) (User: )

Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (03/21/2013 06:23:07 PM) (Source: Service Control Manager) (User: )

Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (03/21/2013 04:26:14 PM) (Source: Service Control Manager) (User: )

Description: The HP CUE DeviceDiscovery Service service terminated unexpectedly. It has done this 1 time(s).

Error: (03/21/2013 04:26:14 PM) (Source: Service Control Manager) (User: )

Description: The hpqcxs08 service terminated unexpectedly. It has done this 1 time(s).

Error: (03/21/2013 08:50:33 AM) (Source: DCOM) (User: NT AUTHORITY)

Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (03/20/2013 03:01:07 PM) (Source: DCOM) (User: NT AUTHORITY)

Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (03/20/2013 02:59:51 PM) (Source: Microsoft Antimalware) (User: )

Description: %60 has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.

Signatures Attempted: %24

Error Code: 0x80070002

Error description: The system cannot find the file specified.

Signature version: 0.0.0.0;0.0.0.0

Engine version: %600

Error: (03/20/2013 01:59:01 PM) (Source: DCOM) (User: NT AUTHORITY)

Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Microsoft Office Sessions:

=========================

Error: (03/22/2013 10:13:14 AM) (Source: SideBySide)(User: )

Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (03/21/2013 06:57:35 PM) (Source: Application Hang)(User: )

Description: mbam.exe1.70.0.9113001ce269e28f914970C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exed6a7ff4e-9293-11e2-a751-206a8a26cef0

Error: (03/21/2013 01:30:09 PM) (Source: SideBySide)(User: )

Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (03/21/2013 10:25:58 AM) (Source: Application Hang)(User: )

Description: mbam.exe1.70.0.9a6001ce265582bd13f48C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe5f855d24-924c-11e2-a751-206a8a26cef0

Error: (03/20/2013 06:17:49 PM) (Source: Application Hang)(User: )

Description: mbam.exe1.70.0.915dc01ce25cfd0d7f31716C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe2237b8ae-91c5-11e2-a673-206a8a26cef0

Error: (03/20/2013 03:25:02 PM) (Source: Application Hang)(User: )

Description: mbam.exe1.70.0.982c01ce25b685278d3516C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe0058b33d-91ad-11e2-a673-206a8a26cef0

Error: (03/20/2013 03:16:23 PM) (Source: Application Hang)(User: )

Description: SoftwareUpdate.exe2.1.3.127e0c01ce25b7dc361faa0C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exec860f0f2-91ab-11e2-a673-206a8a26cef0

Error: (03/20/2013 02:41:48 PM) (Source: Application Hang)(User: )

Description: mbam.exe1.70.0.914f001ce25b10ebe26640C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exef10fab5a-91a6-11e2-baa9-206a8a26cef0

Error: (03/20/2013 01:38:06 AM) (Source: SideBySide)(User: )

Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (03/18/2013 07:15:42 PM) (Source: SideBySide)(User: )

Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

CodeIntegrity Errors:

===================================

Date: 2013-03-21 18:25:09.852

Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-03-21 18:25:09.805

Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

=========================== Installed Programs ============================

µTorrent (Version: 3.3.0.29342)

18 Wheels of Steel - American Long Haul (Version: 2.2.0.95)

4500_G510nz_Help (Version: 000.0.439.000)

4500G510nz (Version: 000.0.439.000)

4500G510nz_Software_Min (Version: 000.0.423.000)

64 Bit HP CIO Components Installer (Version: 7.2.8)

Acer Backup Manager (Version: 2.0.0.68)

Acer Crystal Eye webcam Ver:1.1.194.1021 (Version: 1.1.194.1021)

Acer ePower Management (Version: 5.00.3005)

Acer eRecovery Management (Version: 4.05.3013)

Acer Game Console

Acer Games (Version: 1.0.1.3)

Acer Registration (Version: 1.03.3003)

Acer ScreenSaver (Version: 1.1.1124.2010)

Acer Updater (Version: 1.02.3502)

Acrobat.com (Version: 1.6.65)

Adobe AIR (Version: 1.5.3.9130)

Adobe Flash Player 11 ActiveX (Version: 11.6.602.180)

Adobe Reader 9.4.6 MUI (Version: 9.4.6)

Agatha Christie - Death on the Nile (Version: 2.2.0.95)

Alcor Micro USB Card Reader (Version: 1.9.17.06019)

ALPS Touch Pad Driver (Version: 7.105.2015.1107)

Apple Application Support (Version: 2.1.6)

Apple Mobile Device Support (Version: 4.0.0.97)

Apple Software Update (Version: 2.1.3.127)

Backup Manager Basic (Version: 2.0.0.68)

Bejeweled 2 Deluxe (Version: 2.2.0.95)

Blackhawk Striker 2 (Version: 2.2.0.95)

Bonjour (Version: 3.0.0.10)

Broadcom Gigabit NetLink Controller (Version: 14.2.4.2)

BufferChm (Version: 130.0.331.000)

Build-a-lot 2 (Version: 2.2.0.95)

Chuzzle Deluxe (Version: 2.2.0.95)

Compiled Driver Disk (LG Electronics) 0.99 (Version: 0.99.1.1)

CPUID CPU-Z 1.60.1

CPUID HWMonitor 1.21

CyberLink PowerDVD 9 (Version: 9.0.3814.50)

D3DX10 (Version: 15.4.2368.0902)

Destinations (Version: 130.0.0.0)

DeviceDiscovery (Version: 130.0.372.000)

Diner Dash 2 Restaurant Rescue (Version: 2.2.0.95)

DocMgr (Version: 130.0.000.000)

DocProc (Version: 13.0.0.0)

Dora's Carnival Adventure (Version: 2.2.0.95)

eBay Worldwide (Version: 2.1.0901)

eSobi v2 (Version: 2.0.4.000274)

FATE (Version: 2.2.0.95)

Fax (Version: 130.0.418.000)

Google Chrome (Version: 25.0.1364.172)

GPBaseService2 (Version: 130.0.371.000)

HiJackThis (Version: 1.0.0)

HP Customer Participation Program 13.0 (Version: 13.0)

HP Document Manager 2.0 (Version: 2.0)

HP Imaging Device Functions 13.0 (Version: 13.0)

HP Officejet 4500 G510n-z (Version: 13.0)

HP Smart Web Printing 4.5 (Version: 4.5)

HP Solution Center 13.0 (Version: 13.0)

HP Update (Version: 5.003.001.001)

HPDiagnosticAlert (Version: 1.00.0000)

HPProductAssistant (Version: 130.0.371.000)

HPSSupply (Version: 130.0.371.000)

Identity Card (Version: 1.00.3003)

Intel® Graphics Media Accelerator Driver (Version: 8.15.10.2189)

Intel® Management Engine Components (Version: 6.0.0.1179)

Intel® Rapid Storage Technology (Version: 9.6.0.1014)

iTunes (Version: 10.5.3.3)

Java 7 Update 9 (64-bit) (Version: 7.0.90)

Java 7 Update 9 (Version: 7.0.90)

Java Auto Updater (Version: 2.1.9.0)

JavaFX 2.0.3 (Version: 2.0.3)

Jewel Quest - Heritage (Version: 2.2.0.95)

Jewel Quest Solitaire 2 (Version: 2.2.0.95)

John Deere Drive Green (Version: 2.2.0.95)

Junk Mail filter update (Version: 15.4.3502.0922)

Launch Manager (Version: 4.0.14)

LG United Mobile Driver (Version: 3.6.0.0)

Malwarebytes Anti-Malware version 1.70.0.1100 (Version: 1.70.0.1100)

MarketResearch (Version: 130.0.374.000)

Mesh Runtime (Version: 15.4.5722.2)

Microsoft Application Error Reporting (Version: 12.0.6015.5000)

Microsoft Office 2010 (Version: 14.0.4763.1000)

Microsoft Security Client (Version: 4.2.0223.1)

Microsoft Security Essentials (Version: 4.2.223.1)

Microsoft Silverlight (Version: 5.1.20125.0)

Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)

Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)

MSVCRT (Version: 15.4.2862.0708)

MSVCRT_amd64 (Version: 15.4.2862.0708)

MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)

MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)

MyWinLocker (Version: 3.1.212.0)

MyWinLocker Suite (Version: 3.1.212.0)

Network64 (Version: 130.0.374.000)

Network64 (Version: 140.0.221.000)

NOOK for PC (Version: 2.5.1.237)

Norton Online Backup (Version: 2.1.17869)

NTI Backup Now 5 (Version: 5.1.2.630)

NTI Backup Now Standard (Version: 5.1.2.630)

NTI Media Maker 8 (Version: 8.0.12.6636)

OCR Software by I.R.I.S. 13.0 (Version: 13.0)

Penguins! (Version: 2.2.0.95)

Plants vs. Zombies (Version: 2.2.0.95)

Polar Bowler (Version: 2.2.0.95)

Polar Golfer (Version: 2.2.0.95)

Realtek High Definition Audio Driver (Version: 6.0.1.6167)

Scan (Version: 13.0.0.0)

Shop for HP Supplies (Version: 13.0)

Shredder (Version: 2.0.8.3)

SmartWebPrinting (Version: 130.0.373.000)

SolutionCenter (Version: 130.0.373.000)

Status (Version: 130.0.373.000)

SUPERAntiSpyware (Version: 5.0.1150)

System Requirements Lab CYRI (Version: 5.0.6.0)

System Requirements Lab for Intel (Version: 4.5.11.0)

System Requirements Lab Test (Version: 5.0.6.0)

TechPowerUp GPU-Z

Times Reader (Version: 2.055)

Toolbox (Version: 130.0.648.000)

TrayApp (Version: 130.0.376.000)

Virtual Villagers 4 - The Tree of Life (Version: 2.2.0.95)

VLC media player 2.0.5 (Version: 2.0.5)

WebReg (Version: 130.0.132.017)

Welcome Center (Version: 1.02.3005)

Windows Live Communications Platform (Version: 15.4.3502.0922)

Windows Live Essentials (Version: 15.4.3502.0922)

Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)

Windows Live Installer (Version: 15.4.3502.0922)

Windows Live Language Selector (Version: 15.4.3502.0922)

Windows Live Mail (Version: 15.4.3502.0922)

Windows Live Mesh (Version: 15.4.3502.0922)

Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)

Windows Live Messenger (Version: 15.4.3502.0922)

Windows Live MIME IFilter (Version: 15.4.3502.0922)

Windows Live Movie Maker (Version: 15.4.3502.0922)

Windows Live Photo Common (Version: 15.4.3502.0922)

Windows Live Photo Gallery (Version: 15.4.3502.0922)

Windows Live PIMT Platform (Version: 15.4.3502.0922)

Windows Live Remote Client (Version: 15.4.5722.2)

Windows Live Remote Client Resources (Version: 15.4.5722.2)

Windows Live Remote Service (Version: 15.4.5722.2)

Windows Live Remote Service Resources (Version: 15.4.5722.2)

Windows Live SOXE (Version: 15.4.3502.0922)

Windows Live SOXE Definitions (Version: 15.4.3502.0922)

Windows Live UX Platform (Version: 15.4.3502.0922)

Windows Live UX Platform Language Pack (Version: 15.4.3502.0922)

Windows Live Writer (Version: 15.4.3502.0922)

Windows Live Writer Resources (Version: 15.4.3502.0922)

WinRAR 4.00 (64-bit) (Version: 4.00.0)

Zuma's Revenge (Version: 2.2.0.95)

========================= Devices: ================================

Name: Officejet 4500 G510n-z

Description: Officejet 4500 G510n-z

Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}

Manufacturer: HP

Service:

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Officejet 4500 G510n-z

Description: Officejet 4500 G510n-z

Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}

Manufacturer: HP

Service: StillCam

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

========================= Memory info: ===================================

Percentage of memory in use: 33%

Total physical RAM: 3764.5 MB

Available physical RAM: 2516.07 MB

Total Pagefile: 7527.18 MB

Available Pagefile: 5747.11 MB

Total Virtual: 4095.88 MB

Available Virtual: 3968.64 MB

========================= Partitions: =====================================

1 Drive c: (ACER) (Fixed) (Total:451.01 GB) (Free:122 GB) NTFS

========================= Users: ========================================

User accounts for \\SAC-COM

Administrator David Bado Guest

========================= Minidump Files ==================================

No minidump file found

**** End of log ****

eset log

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IVAW05BX\947[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IVAW05BX\947[2].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VZQQK596\947[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VZQQK596\st[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W44XA800\062a4f0c[1].pdf JS/Exploit.Pdfka.PMN trojan cleaned by deleting - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W44XA800\counter[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W44XA800\st[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W44XA800\st[2].htm HTML/Iframe.B.Gen virus deleted - quarantined

C:\Users\David Bado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YWJTQ6GO\st[1].htm HTML/Iframe.B.Gen virus deleted - quarantined

Link to post
Share on other sites

they are better maniac thanks for the help, but my ie 10 still will not work properly i have to manually enter websites and cannot use any links. also im running a super anti sypware right now and its finding bugs again, but mbam.exe full scan is still broken unfortunately and all i can do is quick scans.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.