1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Read Only mysteriously being applied to all my files

Discussion in 'Malware and Virus Removal Archive' started by jorjab, 2009/02/12.

  1. 2009/02/12
    jorjab Lifetime Subscription

    jorjab Well-Known Member Thread Starter

    Joined:
    2004/07/25
    Messages:
    366
    Likes Received:
    8
    [Resolved] Read Only mysteriously being applied to all my files

    I have just recently noticed that everyone of my files has had its properties changed to read only. I do not have any idea when this began but cannot update any files without removing read only property field.

    Even after I do this something? will soon set it back to read only.

    I use ZoneAlarm Pro, Norton Antivirus , and occasionally other adware and antivirus scanners - spybot currently running while I submit this.
    Windows XP SP2 -:confused:

    Hijack this file follows

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:53:56 PM, on 2/12/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINDOWS\system32\WDBtnMgr.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\My Book\WD Backup\uBBMonitor.exe
    C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\Office\1033\wfxmsrvr.exe
    C:\PROGRA~1\MICROS~2\Office\1033\OLFMOD32.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.mc560.mail.yahoo.com/mc/welcome?.rand=c6lsn9ppnc1f2
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.comcast.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    N3 - Netscape 7: user_pref( "browser.startup.homepage ", "http://www.yahoo.com/ "); (C:\Documents and Settings\myname\Application Data\Mozilla\Profiles\default\4wgwxe9l.slt\prefs.js)
    N3 - Netscape 7: user_pref( "browser.search.defaultengine ", " "); (C:\Documents and Settings\myname\Application Data\Mozilla\Profiles\default\4wgwxe9l.slt\prefs.js)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Documents and Settings\mynameApplication Data\LastPass\LPBar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe "
    O4 - HKLM\..\Run: [ShaPlus Bandwidth Meter] "C:\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter" /s
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKUS\S-1-5-21-682003330-1965331169-725345543-500\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'Administrator')
    O4 - Global Startup: Microsoft Office Shortcut Bar (2).lnk = ?
    O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
    O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: Copy to &Lightning Note - C:\Program Files\WordPerfect Office X4\WordPerfect Office X4\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O8 - Extra context menu item: Open with WordPerfect - c:\Program Files\WordPerfect Office X4\WordPerfect Office X4\Programs\WPLauncher.hta
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
    O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
    O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
    O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: Cookies - {2003a090-8521-11d6-b186-2eed50000000} - C:\Program Files\Iecv\iecv.exe (HKCU)
    O15 - Trusted Zone: http://www.apple.com
    O15 - Trusted Zone: www.comcast.net
    O15 - Trusted Zone: http://dynamic.abc.go.com
    O15 - Trusted Zone: *.intuit.com
    O15 - Trusted Zone: onecare.live.com
    O15 - Trusted Zone: http://www.redbookmag.com
    O15 - Trusted Zone: http://*.turbotax.com
    O15 - Trusted Zone: http://*.verizon.com
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - https://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
    O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222974142394
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
    O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: schmap-help - (no CLSID) - (no file)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 12163 bytes
     
  2. 2009/02/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi jorjab,

    Odd problem ......... and the HijackThis log doesn't suggest foul play, though HJT is hardly comprehensive enough these days. Please see this post then post the DDS logs here.
     

  3. to hide this advert.

  4. 2009/02/13
    jorjab Lifetime Subscription

    jorjab Well-Known Member Thread Starter

    Joined:
    2004/07/25
    Messages:
    366
    Likes Received:
    8
    Here they are from DDS

    I have a lot of wasted junk on my PC but everything looks to me like it should be there.

    DDS Attach


    DDS (Ver_09-02-01.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2/22/2007 7:27:51 PM
    System Uptime: 2/13/2009 11:45:08 AM (3 hours ago)

    Motherboard: Dell Inc. | | 0U7077
    Processor: Intel(R) Pentium(R) 4 CPU 3.60GHz | Microprocessor | 3591/800mhz
    Processor: Intel(R) Pentium(R) 4 CPU 3.60GHz | Microprocessor | 3591/800mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 144 GiB total, 23.452 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP208: 1/11/2009 10:52:45 AM - Installed TurboTax 2008 WinPerFedFormset
    RP209: 1/11/2009 10:53:12 AM - Installed TurboTax 2008 WinPerTaxSupport
    RP210: 1/11/2009 10:53:25 AM - Installed TurboTax 2008 WinPerProgramHelp
    RP211: 1/11/2009 10:53:42 AM - Installed TurboTax 2008 WinPerUserEducation
    RP212: 1/11/2009 10:53:48 AM - Installed AnswerWorks 5.0 English Runtime
    RP213: 1/12/2009 11:28:47 AM - System Checkpoint
    RP214: 1/12/2009 3:15:52 PM - Installed TurboTax 2008 wpaiper
    RP215: 1/13/2009 5:24:12 PM - System Checkpoint
    RP216: 1/16/2009 10:39:29 AM - System Checkpoint
    RP217: 1/16/2009 3:42:22 PM - Ad-Aware Restore Point 2009-01-16 15:42:17
    RP218: 1/18/2009 12:29:40 PM - Removed Microsoft SQL Server 2005 Compact Edition [ENU]
    RP219: 1/19/2009 1:04:34 PM - System Checkpoint
    RP220: 1/20/2009 6:39:03 PM - System Checkpoint
    RP221: 1/22/2009 10:29:50 AM - System Checkpoint
    RP222: 1/27/2009 12:46:12 PM - System Checkpoint
    RP223: 1/27/2009 4:06:04 PM - Installed QuickTime
    RP224: 1/29/2009 3:20:44 PM - System Checkpoint
    RP225: 1/31/2009 6:06:17 PM - System Checkpoint
    RP226: 2/1/2009 11:35:12 AM - Installed SPAMfighter.
    RP227: 2/1/2009 11:43:18 AM - Removed SPAMfighter.
    RP228: 2/2/2009 7:39:52 PM - System Checkpoint
    RP229: 2/6/2009 5:20:15 PM - System Checkpoint
    RP230: 2/8/2009 8:29:40 AM - System Checkpoint
    RP231: 2/9/2009 1:01:23 PM - System Checkpoint
    RP232: 2/10/2009 3:29:35 PM - System Checkpoint
    RP233: 2/11/2009 4:14:37 PM - System Checkpoint

    ==== Installed Programs ======================


    µTorrent
    123 Free Solitaire
    ABBYY FineReader 5.0 Sprint
    Acronis*True*Image*Home
    Active Security Monitor 2.0.0.18
    Ad-Aware
    Adobe Common File Installer
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Help Center 2.0
    Adobe Photoshop Elements 2.0
    Adobe Premiere Elements 2.0
    Adobe Reader 8.1.3
    AnswerWorks 5.0 English Runtime
    AnVir Task Manager
    APC PowerChute Personal Edition
    AppCore
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft Print Creations
    ArcSoft Print Creations - Album Page
    ArcSoft Print Creations - Funhouse
    ArcSoft Print Creations - Greeting Card
    ArcSoft Print Creations - Photo Book
    ArcSoft Print Creations - Photo Calendar
    ArcSoft Print Creations - Scrapbook
    ArcSoft Print Creations - Slimline Card
    ArcSoft Software Suite
    ATI - Software Uninstall Utility
    ATI Control Panel
    ATI Display Driver
    Avery® Wizard 2.1 forMicrosoft® Word 2000
    Bazooka Scanner
    Belarc Advisor 7.2
    Bonjour
    Broadcom Gigabit Integrated Controller
    CA Yahoo! Anti-Spy (remove only)
    ccCommon
    CCleaner (remove only)
    CDBurnerXP
    Component Framework
    ConvertHelper 2.2
    Corel WordPerfect Office - iFilter
    Crash Analysis Tool
    Dazzle Photo Editor
    Dazzle Software
    Dell Driver Reset Tool
    Dell ResourceCD
    Dell Support 3.1
    DNA
    DriveImage XML (Private Edition)
    Driver Detective
    DVD Shrink 3.2
    EasyCleaner
    EPSON Copy Utility
    EPSON PERF 3170Guide
    EPSON Photo Print
    EPSON Scan
    EPSON Smart Panel
    ESPNMotion
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESSini
    ESSPCD
    ESSTOOLS
    essvatgt
    EVEREST Home Edition v2.20
    Everything 1.1.4.301
    Family Tree Maker 2005
    Foxit PDF Editor
    GemMaster Mystic
    getPlus(R)_ocx
    Google Earth
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.0 (KB932471)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB888795)
    Hotfix for Windows XP (KB891593)
    Hotfix for Windows XP (KB895961)
    Hotfix for Windows XP (KB899337)
    Hotfix for Windows XP (KB899510)
    Hotfix for Windows XP (KB902841)
    Hotfix for Windows XP (KB906569)
    Hotfix for Windows XP (KB916089)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB932716-v2)
    Hotfix for Windows XP (KB945060-v3)
    hp deskjet 970c series (Remove only)
    hp photosmart printer series (Remove only)
    ieSpell
    Image Mender 1.1
    Intel Application Accelerator
    Intel(R) 537EP V9x DF PCI Modem
    iTunes
    Java Web Start
    Java(TM) 6 Update 11
    KC Softwares SUMo
    Kodak EasyShare software
    LastPass (uninstall only)
    LiveUpdate (Symantec Corporation)
    Logitech Desktop Messenger
    Logitech QuickCam
    Logitech QuickCam Driver Package
    Logitech Updater
    McAfee SiteAdvisor
    Microsoft .NET Framework 1.0 Hotfix (KB930494)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft .NET Framework 3.0 Service Pack 1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft ICE
    Microsoft Internet Explorer 5 PowerTweaks Web Accessory
    Microsoft Office 2000 SR-1 Professional
    Microsoft Photo Info
    Microsoft RAW Image Thumbnailer and Viewer for Windows XP Version 1.0 (Build 50)
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C Runtime
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Windows XP Video Decoder Checkup Utility
    MobileMe Control Panel
    Moffsoft FreeCalc
    Move Networks Media Player for Internet Explorer
    MozBackup 1.4.6
    Mozilla Firefox (3.0.6)
    Mozilla Thunderbird (2.0.0.16)
    MSXML 6.0 Parser (KB933579)
    My Family Health Portrait
    netbrdg
    Netscape (7.2)
    Nokia Connectivity Cable Driver
    Nokia Internet Tablet Software Update Wizard
    Norton AntiVirus
    Norton AntiVirus (Symantec Corporation)
    Norton AntiVirus Help
    Norton Protection Center
    NoteTab Light (Remove only)
    OfotoXMI
    OnDVD
    OneTouch Software
    Opera 9.63
    Otto
    PC Wizard 2007.1.73
    Photo Viewer 2.3
    Picasa 2
    PowerDVD 5.3
    PowerProducer
    Presto! BizCard 4.1 Eng
    PVR Plus
    Quicken 2008
    QuickTime
    RealPlayer
    Rhapsody Player Engine
    Roxio DLA
    Savings Bond Wizard
    ScanToWeb
    Secunia PSI
    Security Update for CAPICOM (KB931906)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928090)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB960714)
    SFR
    ShaPlus Bandwidth Meter 1.2
    SHASTA
    SIM Edit Tool
    skin0001
    SKINXSDK
    Skypeâ„¢ 3.8
    SolSuite 2007 v7.2
    Sonic MyDVD
    Sonic RecordNow!
    Sonic Update Manager
    SoundMAX
    SpamBayes 1.0.4
    SPBBC 32bit
    Spelling Dictionaries Support For Adobe Reader 8
    Spybot - Search & Destroy
    Spyware Doctor 5.5
    staticcr
    Symantec Real Time Storage Protection Component
    Symantec Technical Support Web Controls
    SymNet
    SyncBack
    SyncToy
    TEVION HIGH SPEED DVD MAKER WDM Drivers
    The Market Toolbox (remove only)
    Time Zone Data Update Tool for Microsoft Office Outlook
    Titan Backup
    tooltips
    TurboTax 2008
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wpaiper
    TurboTax 2008 wrapper
    Tweak UI
    Uniblue Quick Access
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB908531)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB951072)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    USB High-Speed Reader
    USB PC Camera (SN9C103)
    VC 9.0 Runtime
    Viewpoint Media Player (Remove Only)
    VLC media player 0.9.6
    VPRINTOL
    WD Backup
    WD Diagnostics
    WD Firewire HID Driver
    Webcast
    WebCyberCoach 3.2 Dell
    WebFldrs XP
    WebUpdate
    WexTech AnswerWorks
    Winamp
    Windows Defender
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Live installer
    Windows Live OneCare safety scanner
    Windows Live Photo Gallery
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player Firefox Plugin
    Windows Movie Maker 2.0
    Windows Presentation Foundation
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Windows XP Media Center Edition 2005 KB925766
    WinPatrol 2008
    WIRELESS
    Wondershare Movie Story GAOTD Edition 4.5.0
    WordPerfect Lightning
    WordPerfect Lightning - EN
    WordPerfect Lightning - IPM
    WordPerfect Lightning - Messages
    WordPerfect Lightning - MSOM
    WordPerfect Office 12
    WordPerfect Office X4
    WordPerfect Office X4 - Common
    WordPerfect Office X4 - Content
    WordPerfect Office X4 - EN
    WordPerfect Office X4 - Filters
    WordPerfect Office X4 - Graphics
    WordPerfect Office X4 - ICA
    WordPerfect Office X4 - IPM
    WordPerfect Office X4 - IPM EN
    WordPerfect Office X4 - MAIL
    WordPerfect Office X4 - Migration Manager
    WordPerfect Office X4 - PerfectExperts
    WordPerfect Office X4 - PR
    WordPerfect Office X4 - QP
    WordPerfect Office X4 - Skins
    WordPerfect Office X4 - System
    WordPerfect Office X4 - WP
    WordPerfect OfficeReady
    WordWeb
    WorldClock 3.0
    Xenu's Link Sleuth
    XML Paper Specification Shared Components Pack 1.0
    XnView 1.95.4
    Xvid 1.1.3 final uninstall
    ZoneAlarm Pro

    ==== Event Viewer Messages From Past Week ========

    2/6/2009 8:03:17 AM, error: Service Control Manager [7034] - The Protexis Licensing V2 service terminated unexpectedly. It has done this 1 time(s).
    2/9/2009 11:56:12 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service iPod Service with arguments " " in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
    2/9/2009 3:08:38 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).

    ==== End Of File ===========================

    DDS2


    DDS (Ver_09-02-01.01) - NTFSx86
    Run by my name at 14:42:59.72 on Fri 02/13/2009
    Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1292 [GMT -5:00]

    AV: Norton AntiVirus *On-access scanning enabled* (Updated)
    FW: Norton AntiVirus *enabled*
    FW: ZoneAlarm Pro Firewall *enabled*

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\WDBtnMgr.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\My Book\WD Backup\uBBMonitor.exe
    C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\Office\1033\wfxmsrvr.exe
    C:\PROGRA~1\MICROS~2\Office\1033\OLFMOD32.EXE
    C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
    C:\Documents and Settings\my name\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://us.mc560.mail.yahoo.com/mc/welcome?.rand=c6lsn9ppnc1f2
    uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    uWindow Title = Microsoft Internet Explorer provided by Comcast
    mStart Page = hxxp://www.comcast.net/
    mWindow Title = Microsoft Internet Explorer provided by Comcast
    uInternet Connection Wizard,ShellNext = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6261\SiteAdv.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
    BHO: LastPass Browser Helper Object: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - c:\documents and settings\my name\application data\lastpass\LPBar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6261\SiteAdv.dll
    uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
    mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe "
    mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
    mRun: [WD Button Manager] WDBtnMgr.exe
    mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
    mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe "
    mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe "
    mRun: [ShaPlus Bandwidth Meter] "c:\program files\shaplus bandwidth meter\ShaPlus Bandwidth Meter" /s
    mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe "
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\windows\installer\{00010409-78e1-11d2-b60f-006097c998e7}\misc.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wdback~1.lnk - c:\program files\my book\wd backup\uBBMonitor.exe
    IE: &Copy Location - c:\windows\web\graburl.htm
    IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
    IE: &WordWeb... - c:\windows\system32\wweb32.dll/lookup.html
    IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
    IE: Copy to &Lightning Note - c:\program files\wordperfect office x4\wordperfect office x4\wordperfect lightning\programs\WPLightningCopyToNote.hta
    IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
    IE: Open with WordPerfect - c:\program files\wordperfect office x4\wordperfect office x4\programs\WPLauncher.hta
    IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
    IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
    IE: {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - {C651A691-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
    IE: {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - {C651A693-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: apple.com\www
    Trusted Zone: comcast.net\www
    Trusted Zone: dell.com\support
    Trusted Zone: go.com\dynamic.abc
    Trusted Zone: intuit.com
    Trusted Zone: live.com\onecare
    Trusted Zone: microsoft.com\www
    Trusted Zone: redbookmag.com\www
    Trusted Zone: secunia.com\psi
    Trusted Zone: turbotax.com
    Trusted Zone: verizon.com
    Trusted Zone: yahoo.com\us.mc560.mail
    DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxps://support.dell.com/systemprofiler/SysPro.CAB
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=67633
    DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
    DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222974142394
    DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
    DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab
    Handler: AutorunsDisabled\belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6261\SiteAdv.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    LSA: Authentication Packages = msv1_0 relog_ap

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\georgi~1\applic~1\mozilla\firefox\profiles\bsf0qtce.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
    FF - component: c:\documents and settings\my name\application data\mozilla\firefox\profiles\bsf0qtce.default\extensions\kodak-companion@mozilla.com\platform\winnt_x86-msvc\components\mozFotofox.dll
    FF - component: c:\documents and settings\my name\application data\mozilla\firefox\profiles\bsf0qtce.default\extensions\speedtest@gotomyhelp.com\components\NetDiag.dll
    FF - component: c:\program files\siteadvisor\6261\ff\components\FFHook.dll
    FF - plugin: c:\documents and settings\my name\application data\mozilla\firefox\profiles\bsf0qtce.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp07076007.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npHiqVideo.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPMGWRAP.DLL
    FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
    FF - plugin: c:\program files\opera\program\plugins\npJoostPlugin.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

    ============= SERVICES / DRIVERS ===============

    R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-2-22 353680]
    R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
    R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
    R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
    R3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\drivers\atinewp2.sys [2007-2-22 485888]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-10-10 99376]
    R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090213.003\NAVENG.SYS [2009-2-13 89104]
    R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090213.003\NAVEX15.SYS [2009-2-13 876112]
    R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-8-25 1251720]
    S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2008-12-28 13568]
    S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888]
    S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2007-2-22 18864]
    S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2007-9-2 42376]
    S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2007-9-2 66952]
    S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2007-9-2 81288]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-11-18 7808]
    S4 0258331196464938mcinstcleanup;McAfee Application Installer Cleanup (0258331196464938);c:\docume~1\georgi~1\locals~1\temp\025833~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\georgi~1\locals~1\temp\025833~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
    S4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
    S4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
    S4 mcpromgr;McAfee Protection Manager;c:\progra~1\mcafee\msc\mcpromgr.exe [2007-11-30 493144]
    S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-3-15 747912]
    S4 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-3-15 948616]
    S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]

    =============== Created Last 30 ================

    2009-02-01 11:35 <DIR> --d----- c:\docume~1\georgi~1\applic~1\SPAMfighter
    2009-01-30 15:38 <DIR> --d----- c:\docume~1\georgi~1\applic~1\XnView
    2009-01-30 15:38 <DIR> --d----- c:\program files\XnView
    2009-01-24 14:16 <DIR> --d----- c:\docume~1\georgi~1\applic~1\LastPass
    2009-01-18 16:03 <DIR> --d----- c:\program files\DVD Shrink
    2009-01-18 10:25 <DIR> --d----- c:\program files\Easy Duplicate Finder
    2009-01-15 10:33 <DIR> --d----- c:\program files\Foxit Software

    ==================== Find3M ====================

    2009-02-13 13:42 0 a------- c:\windows\system32\drivers\lvuvc.hs
    2009-02-13 13:42 0 a------- c:\windows\system32\drivers\logiflt.iad
    2009-02-13 12:01 4,212 a---h--- c:\windows\system32\zllictbl.dat
    2009-01-28 13:17 1,682 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
    2009-01-09 10:06 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
    2009-01-09 10:06 60,808 a------- c:\windows\system32\S32EVNT1.DLL
    2009-01-09 10:06 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
    2009-01-09 10:06 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
    2008-12-28 16:33 13,568 a------- c:\windows\system32\drivers\USBCRFT.SYS
    2008-12-04 14:53 410,984 a------- c:\windows\system32\deploytk.dll
    2008-05-13 16:17 852 a------- c:\program files\keyfinder.exe.lnk
    1998-12-09 04:53 186,368 -------- c:\program files\common files\IRAREG.DLL
    1998-12-09 04:53 99,840 -------- c:\program files\common files\IRAABOUT.DLL
    1998-12-09 04:53 70,144 -------- c:\program files\common files\IRAMDMTR.DLL
    1998-12-09 04:53 48,640 -------- c:\program files\common files\IRALPTTR.DLL
    1998-12-09 04:53 31,744 -------- c:\program files\common files\IRAWEBTR.DLL
    1998-12-09 04:53 17,920 -------- c:\program files\common files\IRASRIAL.DLL

    ============= FINISH: 14:43:44.49 ===============
     
  5. 2009/02/13
    jorjab Lifetime Subscription

    jorjab Well-Known Member Thread Starter

    Joined:
    2004/07/25
    Messages:
    366
    Likes Received:
    8
    I think I just found the answer on windows BBS web site, Arie Post.

    Apparently this is way it works. Only affects when you look at folders, does not affect files.

    http://www.windowsbbs.com/windows-vista/79719-read-only-cant-cleared.html

    Sorry - but did not enter in the proper search terms when I first checked BBS site to see if prolbem had been reported before. .
     
  6. 2009/02/14
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    And I didn't realize since you talked about read-only files, not folders.
     
    Arie,
    #5
  7. 2009/02/14
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Incidentally, your logs look fine too. I'll mark this resolved.
     
  8. 2009/02/14
    jorjab Lifetime Subscription

    jorjab Well-Known Member Thread Starter

    Joined:
    2004/07/25
    Messages:
    366
    Likes Received:
    8
    Thanks

    Although I still don't know why a couple of my files initially were changed to read only. Posted only after I tried to change attributes via folders rather then the files. Can change attribute via file properties and then seems to stay that way.

    Yes consider closed. Hopefully I will not I suddenly find more files being changed to read only.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.