Jump to content

Malwarebytes/ IOBit


Recommended Posts

Have got Malwarebytes, download IOBIT360 and it said it found a trojan32 in my system that both MWB and my AVG didnt find,

Then I ran MWB and it has IObit as a rogue.installer

Who is right and how do I get rid of it as MWB has taken the uninstaller away

thanks

Link to post
Share on other sites

Hi Jake224 And Welcome to Malwarebytes!

Where did you download Security 360 at? Also, Please post the Malwarebytes log.

Hi

I downloaded the 360 from advanced systemcare3 I have on my computer

I deleted it using MWB and now it doesnt find anything, does that mean I am okay?

Link to post
Share on other sites

I don't trust IObit to find malware. All IObit products reputation is not the best in the world. Visit:

http://news.cnet.com/8301-27080_3-10389650-245.html

Now if you want to remove all of IObit. You can use this tool at:

http://www.t-tools.nl/bitremoveren.php

I deleted it using MWB and now it doesnt find anything, does that mean I am okay?

I like to look at two scans to make sure.

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however may need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: EOLS1.gif
  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:

    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

[*]Now click on: EOLS3.gif

[*]The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.

[*]When completed the Online Scan will begin automatically.

[*]Do not touch either the Mouse or keyboard during the scan otherwise it may stall.

[*]When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!

[*]Now click on: EOLS4.gif

[*]Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.

[*]Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Next

Click here to download HJTInstall.exe

  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

In your next reply, please include these log(s):

EsetOnlineScanner\log.txt

Hijackthis Log

Link to post
Share on other sites

I don't trust IObit to find malware. All IObit products reputation is not the best in the world. Visit:

http://news.cnet.com/8301-27080_3-10389650-245.html

Now if you want to remove all of IObit. You can use this tool at:

http://www.t-tools.nl/bitremoveren.php

I like to look at two scans to make sure.

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however may need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: EOLS1.gif
  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:

    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

[*]Now click on: EOLS3.gif

[*]The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.

[*]When completed the Online Scan will begin automatically.

[*]Do not touch either the Mouse or keyboard during the scan otherwise it may stall.

[*]When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!

[*]Now click on: EOLS4.gif

[*]Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.

[*]Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Next

Click here to download HJTInstall.exe

  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

In your next reply, please include these log(s):

EsetOnlineScanner\log.txt

Hijackthis Log

Wasnt able to get rid of the 360 using that tool. had to delete it via delete desktop as it wasnt letting me do in add/remove--got an error message on HJT which said it wouldnt let me open the host files?

C:\Users\retread\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\632D61B3-0000006B.eml JS/TrojanDownloader.Agent.NRL trojan

C:\Users\retread\Downloads\Nero-9.4.12.3d_free.exe Win32/Toolbar.AskSBar application

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:58:03, on 20/04/2010

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v8.00 (8.00.6001.18904)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

C:\Program Files\AVG\AVG9\avgtray.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Common Files\aol\1261151017\ee\aolsoftware.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\IObit\IObit Security 360\is360tray.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\OpenOffice.org 3\program\soffice.exe

C:\Program Files\OpenOffice.org 3\program\soffice.bin

C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe

C:\Program Files\Trusteer\Rapport\bin\RapportService.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Windows\explorer.exe

C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Windows Live\Contacts\wlcomm.exe

C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe

C:\Program Files\Java\jre6\bin\java.exe

C:\Program Files\AOL 9.1\waol.exe

C:\Program Files\AOL 9.1\shellmon.exe

C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe

C:\Users\retread\Downloads\HijackThis.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\system32\SearchFilterHost.exe

C:\Users\retread\Desktop\HijackThis(2).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.co.uk

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll

R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: AOL Toolbar Loader - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1261151017\ee\AOLSoftware.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [iObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [GoTrusted] C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel v2.1\GoTrusted Secure Tunnel.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [GoTrusted] C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel v2.1\GoTrusted Secure Tunnel.exe (User 'Default user')

O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

O13 - Gopher Prefix:

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe

O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe

O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Emma Device Management (EmmaDevMgmtSvc) - Sony Ericsson Mobile Communications - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe

O23 - Service: Emma Update Management (EmmaUpdMgmtSvc) - Sony Ericsson Mobile Communications - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)

O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe

O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

--

End of file - 10694 bytes

Link to post
Share on other sites

Please download RunScanner from here

  • Save runscanner.exe to your desktop and double-click it to run it.
  • Once it starts, select Expert Mode and click Ok
  • When the main program opens, click on the Scan Computer button at the top, be patient it may take a few moments.
  • Once that's done click on the Save run file button at the top and when the save dialogue box opens, save the file as runlog and save it to your desktop.
  • Now right-click on the runlog.run file located on your desktop and highlight Send To and select Compressed (zipped) Folder
  • Please attach the runlog.zip file you just created to your next post.

Link to post
Share on other sites

Please download RunScanner from here

  • Save runscanner.exe to your desktop and double-click it to run it.
  • Once it starts, select Expert Mode and click Ok
  • When the main program opens, click on the Scan Computer button at the top, be patient it may take a few moments.
  • Once that's done click on the Save run file button at the top and when the save dialogue box opens, save the file as runlog and save it to your desktop.
  • Now right-click on the runlog.run file located on your desktop and highlight Send To and select Compressed (zipped) Folder
  • Please attach the runlog.zip file you just created to your next post.

couldnt find the run file when I saved it to desktop, hope this is it?

runscanner.zip

Link to post
Share on other sites

Can you copy and paste the log here?

Runscanner logfile

* = signed file

- = file not found

General info

------------

Computer name : RETREAD-PC

Creation time : 20/04/2010 13:07:42

Hosts <> 127.0.0.1 : 0

Hosts file location : %SystemRoot%\System32\drivers\etc

IE version : 8.0.6001.18904

OS : Windows Vista Home Premium

OS Build : 6002

OS SP : Service Pack 2

RunScanner Version : 1.9.0.9

User Language : English (United Kingdom)

User rights : Administrator

Windows folder : C:\Windows

Running processes

-----------------

* C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)

* C:\Program Files\Common Files\aol\1261151017\ee\aolsoftware.exe (AOL Inc.)

* C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)

* C:\Program Files\a-squared Free\a2free.exe (Emsi Software GmbH)

* C:\Program Files\a-squared Free\a2service.exe (Emsi Software GmbH)

* C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgui.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)

* C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)

* C:\Windows\system32\csrss.exe (Microsoft Corporation)

* C:\Windows\system32\csrss.exe (Microsoft Corporation)

* C:\Windows\system32\Dwm.exe (Microsoft Corporation)

C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications)

C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Sony Ericsson Mobile Communications)

* C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

* C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

* C:\Users\retread\Desktop\HijackThis(2).exe (Trend Micro Inc.)

* C:\Windows\System32\hkcmd.exe (Intel Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\System32\svchost.exe (Microsoft Corporation)

* C:\Windows\System32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\System32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\svchost.exe (Microsoft Corporation)

* C:\Windows\system32\igfxsrvc.exe (Intel Corporation)

* C:\Windows\System32\igfxtray.exe (Intel Corporation)

* C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)

* C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)

* C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

* C:\Windows\system32\lsass.exe (Microsoft Corporation)

* C:\Windows\system32\lsm.exe (Microsoft Corporation)

* C:\Windows\system32\SLsvc.exe (Microsoft Corporation)

* C:\Windows\system32\SearchFilterHost.exe (Microsoft Corporation)

* C:\Windows\system32\SearchIndexer.exe (Microsoft Corporation)

* C:\Windows\system32\SearchProtocolHost.exe (Microsoft Corporation)

C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)

C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)

* C:\Windows\System32\igfxpers.exe (Intel Corporation)

* C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

* C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)

* C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

* C:\Users\retread\Downloads\runscanner.exe (Runscanner.net)

* C:\Windows\system32\services.exe (Microsoft Corporation)

* c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (McAfee, Inc.)

C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)

* C:\Windows\System32\spoolsv.exe (Microsoft Corporation)

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe

* C:\Windows\system32\taskeng.exe (Microsoft Corporation)

* C:\Windows\system32\taskeng.exe (Microsoft Corporation)

* C:\Windows\system32\taskeng.exe (Microsoft Corporation)

C:\Program Files\VideoLAN\VLC\vlc.exe

* audiodg.exe (Microsoft Corporation)

* C:\Windows\Explorer.EXE (Microsoft Corporation)

* C:\Windows\explorer.exe (Microsoft Corporation)

* C:\Windows\system32\rundll32.exe (Microsoft Corporation)

* C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)

* C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)

* C:\Windows\system32\winlogon.exe (Microsoft Corporation)

* C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

* C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)

* c:\windows\System32\smss.exe (Microsoft Corporation)

* C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)

* C:\Windows\system32\wininit.exe (Microsoft Corporation)

Unrated items

-------------

002 * C:\Program Files\Common Files\AOL\1261151017\ee\AOLSoftware.exe (AOL Inc.)

002 * C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)

002 C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)

003 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)

003 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

003 * C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

004 C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE

007 C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE

008 C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel v2.1\GoTrusted Secure Tunnel.exe (GoTrusted.com)

009 C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel v2.1\GoTrusted Secure Tunnel.exe (GoTrusted.com)

010 * C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL Connectivity Service)

010 * C:\Program Files\a-squared Free\a2service.exe (a-squared Service)

010 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Emma Device Management Service)

010 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Emma Update Management Service)

010 * C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService)

010 * c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (SiteAdvisor)

010 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe (SupServ.exe)

011 * C:\Windows\system32\DRIVERS\GEARAspiWDM.sys (CD DVD Filter)

011 C:\Windows\system32\DRIVERS\e1e6032.sys (Intel® PRO/1000 Adapter NDIS 6 deserialized driver)

011 * C:\Windows\System32\Drivers\pcouffin.sys (low level access layer for CD/DVD/BD devices)

011 * C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys (RapportKE)

011 * C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG)

011 * C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SASDIFSV.SYS)

011 * C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SASENUM.SYS)

011 * C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS)

011 C:\Windows\system32\DRIVERS\seehcri.sys (seehcri Driver)

011 * C:\Windows\system32\DRIVERS\ggsemc.sys (SEMC USB Flash Driver)

011 * C:\Windows\system32\DRIVERS\ggflt.sys (SEMC USB Flash Driver Filter)

011 * C:\Windows\system32\DRIVERS\s0017bus.sys (Sony Ericsson Device 0017 Driver)

011 * C:\Windows\system32\DRIVERS\s0017unic.sys (Sony Ericsson Device 0017 USB Ethernet Emulation)

011 * C:\Windows\system32\DRIVERS\s0017nd5.sys (Sony Ericsson Device 0017 USB Ethernet Emulation (NDIS 5 Miniport))

011 * C:\Windows\system32\DRIVERS\s0017mgmt.sys (Sony Ericsson Device 0017 USB WMC Device Management Driver)

011 * C:\Windows\system32\DRIVERS\s0017mdfl.sys (Sony Ericsson Device 0017 USB WMC Modem Filter Driver)

011 * C:\Windows\system32\DRIVERS\s0017mdm.sys (Sony Ericsson Device 0017 USB WMC Modem WDM Driver)

011 * C:\Windows\system32\DRIVERS\s0017obex.sys (Sony Ericsson Device 0017 USB WMC OBEX Interface Device Driver)

031 * c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) {5513F07E-936B-4E52-9B00-067394E91CC5}

031 * c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) {5513F07E-936B-4E52-9B00-067394E91CC5}

040 * C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc) {f0e98552-8e47-4c6c-9b3a-11ab0549f94d}

040 * c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}

041 * C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc) {ba00b7b1-0351-477a-b948-23e3ee5a73d4}

041 * c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}

045 * C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc) {BA00B7B1-0351-477A-B948-23E3EE5A73D4}

047 Zone: objects.aol.com : *.objects.aol.com

050 C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}

052 GUID / CLSID not found {02478D38-C3F9-4efb-9B51-7695ECA05670}

052 GUID / CLSID not found {5C255C8A-E604-49b4-9D64-90988571CECB}

052 * C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc) {3ef64538-8b54-4573-b48f-4d34b0238ab2}

052 * c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) {B164E929-A1B6-4A06-B104-2CD0E90A88FF}

061 C:\Program Files\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}

061 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}

061 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) {087B3AE3-E237-4467-B8DB-5A38AB959AC9}

061 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) {63542C48-9552-494A-84F7-73AA6A7C99C1}

061 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) {3B092F0C-7696-40E3-A80F-68D74DA84210}

062 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}

067 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)

073 AWC Startup.job : C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)

100 Start Page HKCU : http://www.aol.co.uk

104 GUID / CLSID not found {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

105 E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

105 Google Sidewiki... : res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

107 C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

173 C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL (SUPERAntiSpyware.com) SUPERAntiSpyware Context Menu

221 C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL (SUPERAntiSpyware.com) SUPERAntiSpyware Context Menu

223 C:\Program Files\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}

223 * C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

225 C:\Program Files\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}

225 C:\Program Files\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}

225 * C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

225 * C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

227 C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL (SUPERAntiSpyware.com) SUPERAntiSpyware Context Menu

231 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) OpenOffice.org Column Handler

Missing files

-------------

010 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

011 c:\windows\system32\DRIVERS\GUCI_AVS.sys

011 c:\windows\system32\DRIVERS\ipinip.sys

011 c:\windows\system32\DRIVERS\nwlnkflt.sys

011 c:\windows\system32\DRIVERS\nwlnkfwd.sys

011 c:\windows\system32\drivers\RTKVHDA.sys

032 rdpclip

10 were in red.

Link to post
Share on other sites

Item: 010 HKLM\SYSTEM\CurrentControlSet\Services (Services)

Description: NBService.exe

Path: C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

MD5: File not found

FileDescription: NBService.exe

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nero BackItUp Scheduler 4.0

Certificate: File not found

Item: 011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)

Description: GUCI_AVS.sys

Path: c:\windows\system32\DRIVERS\GUCI_AVS.sys

MD5: File not found

FileDescription: GUCI_AVS.sys

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GUCI_AVS

Certificate: File not found

Item: 011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)

Description: RTKVHDA.sys

Path: c:\windows\system32\drivers\RTKVHDA.sys

MD5: File not found

FileDescription: RTKVHDA.sys

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntcAzAudAddService

Certificate: File not found

Item: 011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)

Description: ipinip.sys

Path: c:\windows\system32\DRIVERS\ipinip.sys

MD5: File not found

FileDescription: ipinip.sys

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp

Certificate: File not found

Item: 011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)

Description: nwlnkflt.sys

Path: c:\windows\system32\DRIVERS\nwlnkflt.sys

MD5: File not found

FileDescription: nwlnkflt.sys

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt

Certificate: File not found

Item: 011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)

Description: nwlnkfwd.sys

Path: c:\windows\system32\DRIVERS\nwlnkfwd.sys

MD5: File not found

FileDescription: nwlnkfwd.sys

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd

Certificate: File not found

Item: 032 HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms

Description: rdpclip

Path: rdpclip

MD5: File not found

FileDescription: rdpclip

Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd

Registry value: StartupPrograms

Certificate: File not found

Item: 052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

Description: {02478D38-C3F9-4efb-9B51-7695ECA05670}

Path: GUID / CLSID not found

MD5: NA

Registry path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}

Item: 052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

Description: {5C255C8A-E604-49b4-9D64-90988571CECB}

Path: GUID / CLSID not found

MD5: NA

Registry path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}

Item: 104 HKLM\Software\Microsoft\Code Store Database\Distribution Units

Description: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

Path: GUID / CLSID not found

MD5: NA

Registry path: HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}

These are the ones that were in red

Link to post
Share on other sites

C:\Users\retread\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\

You need to empty your Deleted items in Windows Mail.

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these Files (if present):

C:\Users\retread\Downloads\Nero-9.4.12.3d_free.exe

C:\Program Files\AOL Toolbar\uninstall.exe

Also, I would like you to generate a "Add/Remove Software list" log using the HijackThis application. Here is how you can do this:

To get an Uninstall List from HijackThis:

  • Open HijackThis, click Config, click Misc Tools
  • Click "Open Uninstall Manager"
  • Click "Save List" (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.

Link to post
Share on other sites

I don't see any Windows updates in your list Jake.

Please run the MGA Diagnostic Tool and post back the report it creates:

  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.

Link to post
Share on other sites

And the MGA Diagnostic Tool?

I have all the updates it says when i go to windows updates

Diagnostic Report (1.9.0027.0):

-----------------------------------------

Windows Validation Data-->

Validation Status: Genuine

Validation Code: 0

Cached Online Validation Code: 0x0

Windows Product Key: *****-*****-F4GJK-KG77H-B9HD2

Windows Product Key Hash: iJAth4TbScMi8HdcPurlASXdEkw=

Windows Product ID: 89578-OEM-7332157-00204

Windows Product ID Type: 2

Windows License Type: OEM SLP

Windows OS version: 6.0.6002.2.00010300.2.0.003

ID: {63035F6C-E17C-42E3-8B97-E9DF83DDF6E3}(1)

Is Admin: Yes

TestCab: 0x0

LegitcheckControl ActiveX: N/A, hr = 0x80070002

Signed By: N/A, hr = 0x80070002

Product Name: Windows Vista Home Premium

Architecture: 0x00000000

Build lab: 6002.vistasp2_gdr.100218-0019

TTS Error:

Validation Diagnostic:

Resolution Status: N/A

Vista WgaER Data-->

ThreatID(s): N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->

Cached Result: N/A, hr = 0x80070002

File Exists: No

Version: N/A, hr = 0x80070002

WgaTray.exe Signed By: N/A, hr = 0x80070002

WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

OGAExec.exe Signed By: N/A, hr = 0x80070002

OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->

Office Status: 109 N/A

OGA Version: N/A, 0x80070002

Signed By: N/A, hr = 0x80070002

Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->

Proxy settings: N/A

User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)

Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe

Download signed ActiveX controls: Prompt

Download unsigned ActiveX controls: Disabled

Run ActiveX controls and plug-ins: Allowed

Initialize and script ActiveX controls not marked as safe: Disabled

Allow scripting of Internet Explorer Webbrowser control: Disabled

Active scripting: Allowed

Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->

Office Details: <GenuineResults><MachineData><UGUID>{63035F6C-E17C-42E3-8B97-E9DF83DDF6E3}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-B9HD2</PKey><PID>89578-OEM-7332157-00204</PID><PIDType>2</PIDType><SID>S-1-5-21-4129996429-4084743265-3494710908</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Inspiron 530</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>1.0.15</Version><SMBIOSVersion major="2" minor="5"/><Date>20080620000000.000000+000</Date></BIOS><HWID>67333507018400FA</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL </OEMID><OEMTableID>FX09 </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->

Software licensing service version: 6.0.6002.18005

Name: Windows Vista, HomePremium edition

Description: Windows Operating System - Vista, OEM_SLP channel

Activation ID: bffdc375-bbd5-499d-8ef1-4f37b61c895f

Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f

Extended PID: 89578-00146-321-500204-02-2057-6001.0000-3472009

Installation ID: 016734741451702495117762890913099466525835888234361505

Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473

Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474

Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476

Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475

Partial Product Key: B9HD2

License Status: Licensed

Windows Activation Technologies-->

N/A

HWID Data-->

HWID Hash Current: OgAAAAEABAABAAEAAQACAAAABAABAAEAeqj+v9K/8nu2WWT+iP26k+xQ8vREJVFUkKCsVkwBotgqhQ==

OEM Activation 1.0 Data-->

N/A

OEM Activation 2.0 Data-->

BIOS valid for OA 2.0: yes

Windows marker version: 0x20000

OEMID and OEMTableID Consistent: yes

BIOS Information:

ACPI Table Name OEMID Value OEMTableID Value

APIC DELL FX09

FACP DELL FX09

HPET DELL FX09

MCFG DELL FX09

SLIC DELL FX09

DMY2 DELL FX09

SSDT PmRef CpuPm

Link to post
Share on other sites

Download and install Revo Uninstaller FREE at: http://www.revouninstaller.com/revo_uninst...e_download.html

Double click the Revo Uninstaller icon on your desktop to start the program

Scroll through the listed programs and Right Click on Advanced SystemCare 3

you wish to uninstall

From the pop out menu choose Uninstall

Click Yes to the confirmation dialogue

In the next window select the Advanced mode

Click Next to start uninstalling the program

Answer Yes to confirm the uninstall

When the program has completed the four steps, click Next to allow the program to search for leftovers

Once complete, click Next, then Finish

Note: You should remove

Link to post
Share on other sites

From the pop out menu choose Uninstall

Click Yes to the confirmation dialogue

In the next window select the Advanced mode

Click Next to start uninstalling the program

Answer Yes to confirm the uninstall

When the program has completed the four steps, click Next to allow the program to search for leftovers

Once complete, click Next, then Finish

Do I delete the HKEY Local machine, software, iobit and systemcare all leftovers it finds?

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.