1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive virus [Antivirus 2009]

Discussion in 'Malware and Virus Removal Archive' started by kimmy, 2009/01/25.

  1. 2009/01/25
    kimmy

    kimmy Inactive Thread Starter

    Joined:
    2009/01/25
    Messages:
    2
    Likes Received:
    0
    [Inactive] virus [Antivirus 2009]

    i have a virus i believe is from microsoft anti virus 2009. it pops up and crashes my computer, well my internet goes off with out warning. internet as well as IM lag or wont work most of the time. I also have various pop ups from internet explorer now. i thinks it's a virus from the nicrosoft anti virus 2009. how do i fix it or get it off my computer? I'm using windows xp with media player and i use internet explorer for internet browsing. i have rebooted my computer several times and this anti virus 2009 keeps comng back up causing the computer to have pop ups. my computer is a gateway and i have had it for about 3 years now. i use charter security suite for protection but it's not helping me. i also have a pop up of something telling me i need to turn on the filtering? please help me.
    LESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-01-19.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/26/2008 6:53:57 PM
    System Uptime: 1/25/2009 8:37:48 AM (3 hours ago)

    Motherboard: Intel Corporation | | D915GAG
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | | 3000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 182 GiB total, 150.679 GiB free.
    D: is FIXED (FAT32) - 4 GiB total, 1.698 GiB free.
    E: is CDROM (CDFS)
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description: Audio Device on High Definition Audio Bus
    Device ID: HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1000\5&2AA694B9&0&0001
    Manufacturer:
    Name: Audio Device on High Definition Audio Bus
    PNP Device ID: HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1000\5&2AA694B9&0&0001
    Service:

    DDS (Ver_09-01-19.01) - NTFSx86
    Run by Owner at 11:21:19.42 on Sun 01/25/2009
    Internet Explorer: 7.0.5730.13
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.46 [GMT -8:00]

    AV: Charter Security Suite 8.00 *On-access scanning enabled* (Updated)
    FW: Charter Security Suite 8.00 *enabled*

    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Digital Media Reader\shwiconem.exe
    C:\WINDOWS\zHotkey.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\Charter Security Suite\Common\FSM32.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Windows Live\Family Safety\fssui.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\COMMON~1\AOL\122775~1\EE\AOLHOS~1.EXE
    C:\PROGRA~1\COMMON~1\AOL\122775~1\EE\AOLServiceHost.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
    C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
    C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE
    C:\Program Files\Charter Security Suite\Common\FSMB32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Charter Security Suite\Common\FCH32.EXE
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Charter Security Suite\Anti-Virus\fsqh.exe
    C:\Program Files\Charter Security Suite\Common\FAMEH32.EXE
    C:\Program Files\Charter Security Suite\FSPC\fspc.exe
    C:\Program Files\Charter Security Suite\FSGUI\fsguidll.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe
    C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Charter Security Suite\FSAUA\program\fsus.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe
    C:\Program Files\Charter Security Suite\FSGUI\scanwizard.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\WINDOWS\system32\1hAHKstk.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Windows Live Toolbar\msn_sl.exe
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8UO7BY3C\dds[1].scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uWindow Title = Windows Internet Explorer provided by MySpace
    uDefault_Page_URL = hxxp://www.myspace.com/
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    mDefault_Page_URL = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: NoExplorer - No File
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
    BHO: Windows Live OneCare Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
    BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
    BHO: NoExplorer - No File
    BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0983.0\msneshellx.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
    TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0983.0\msneshellx.dll
    TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
    uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
    uRun: [Cognac] c:\docume~1\owner\locals~1\temp\1FB0.tmp.exe
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
    mRun: [<NO NAME>]
    mRun: [CHotkey] zHotkey.exe
    mRun: [HostManager] c:\program files\common files\aol\1227753156\ee\AOLHostManager.exe
    mRun: [AOL Spyware Protection] "c:\progra~1\common~1\aol\aolspy~1\AOLSP Scheduler.exe "
    mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe "
    mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AlcWzrd] ALCWZRD.EXE
    mRun: [Alcmtr] ALCMTR.EXE
    mRun: [F-Secure Manager] "c:\program files\charter security suite\common\FSM32.EXE" /splash
    mRun: [F-Secure TNB] "c:\program files\charter security suite\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [fssui] "c:\program files\windows live\family safety\fssui.exe" -autorun
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
    dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bigfix.lnk - c:\program files\bigfix\BigFix.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\instal~1.lnk - c:\program files\sifxinst\SIFXINST.EXE
    IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
    IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
    IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {200DB664-75B5-47c0-8B45-A44ACCF73C00} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\charter security suite\fspc\fspcmsie.dll
    IE: {200DB664-75B5-47c0-8B45-A44ACCF73F01} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\charter security suite\fspc\fspcmsie.dll
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    LSP: c:\program files\charter security suite\fsps\program\FSLSP.DLL
    DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://download-games.pogo.com/online2/pogo/diner_dash_2/DinerDash2.1.0.0.53.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
    DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} - hxxp://tagged.oberon-media.com/online/online2/wedding_dash/WeddingDash.1.0.0.47.cab
    Notify: AtiExtEvent - Ati2evxx.dll

    ============= SERVICES / DRIVERS ===============

    R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2008-11-26 33408]
    R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-11-26 79904]
    R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\charter security suite\hips\drivers\fshs.sys [2008-11-26 66720]
    R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\charter security suite\anti-virus\minifilter\fsgk.sys [2008-11-26 84096]
    R3 FSORSPClient;F-Secure ORSP Client;c:\program files\charter security suite\orsp client\fsorsp.exe [2008-11-26 55904]
    R4 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\charter security suite\anti-virus\fsgk32st.exe [2008-11-26 215648]
    R4 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-1-1 43816]
    R4 fsssvc;Windows Live OneCare Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2007-12-17 523816]
    S4 F-Secure Filter;F-Secure File System Filter;c:\program files\charter security suite\anti-virus\win2k\fsfilter.sys [2008-11-26 39776]
    S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\charter security suite\anti-virus\win2k\fsrec.sys [2008-11-26 25184]

    =============== Created Last 30 ================

    2009-01-24 20:55 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes
    2009-01-24 18:58 15,504 a------- c:\windows\system32\drivers\mbam.sys
    2009-01-24 18:58 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-01-24 18:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-01-24 18:58 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-01-23 00:01 1,907 a------- C:\error.fstmp
    2009-01-23 00:01 873 a------- C:\infect.fstmp
    2009-01-22 14:14 72,192 a------- c:\windows\system32\1hAHKstk.exe
    2009-01-19 00:15 <DIR> --d----- c:\windows\osu!
    2009-01-19 00:15 <DIR> --d----- c:\program files\osu!
    2009-01-14 06:22 <DIR> --d----- c:\program files\Saga
    2009-01-12 22:27 268 a---h--- C:\sqmdata19.sqm
    2009-01-12 22:27 244 a---h--- C:\sqmnoopt19.sqm
    2009-01-11 22:31 244 a---h--- C:\sqmnoopt18.sqm
    2009-01-11 22:31 232 a---h--- C:\sqmdata18.sqm
    2009-01-11 19:19 244 a---h--- C:\sqmnoopt17.sqm
    2009-01-11 19:19 232 a---h--- C:\sqmdata17.sqm
    2009-01-11 14:01 244 a---h--- C:\sqmnoopt16.sqm
    2009-01-11 14:01 232 a---h--- C:\sqmdata16.sqm
    2009-01-10 21:05 244 a---h--- C:\sqmnoopt15.sqm
    2009-01-10 21:05 232 a---h--- C:\sqmdata15.sqm
    2009-01-10 16:13 268 a---h--- C:\sqmdata14.sqm
    2009-01-10 16:13 244 a---h--- C:\sqmnoopt14.sqm
    2009-01-10 15:54 <DIR> --d----- c:\program files\NCSoft
    2009-01-09 07:46 244 a---h--- C:\sqmnoopt13.sqm
    2009-01-09 07:46 232 a---h--- C:\sqmdata13.sqm
    2009-01-08 23:14 244 a---h--- C:\sqmnoopt12.sqm
    2009-01-08 23:14 232 a---h--- C:\sqmdata12.sqm
    2009-01-08 15:12 232 a---h--- C:\sqmdata11.sqm
    2009-01-08 15:12 244 a---h--- C:\sqmnoopt11.sqm
    2009-01-08 13:19 268 a---h--- C:\sqmdata10.sqm
    2009-01-08 13:19 244 a---h--- C:\sqmnoopt10.sqm
    2009-01-08 12:22 268 a---h--- C:\sqmdata09.sqm
    2009-01-08 12:22 244 a---h--- C:\sqmnoopt09.sqm
    2009-01-08 07:17 268 a---h--- C:\sqmdata08.sqm
    2009-01-08 07:17 244 a---h--- C:\sqmnoopt08.sqm
    2009-01-07 23:00 268 a---h--- C:\sqmdata07.sqm
    2009-01-07 23:00 244 a---h--- C:\sqmnoopt07.sqm
    2009-01-07 22:00 268 a---h--- C:\sqmdata06.sqm
    2009-01-07 22:00 244 a---h--- C:\sqmnoopt06.sqm
    2009-01-07 18:09 268 a---h--- C:\sqmdata05.sqm
    2009-01-07 18:09 244 a---h--- C:\sqmnoopt05.sqm
    2009-01-07 12:20 <DIR> --d----- c:\program files\Guild Wars
    2009-01-07 07:20 268 a---h--- C:\sqmdata04.sqm
    2009-01-07 07:20 244 a---h--- C:\sqmnoopt04.sqm
    2009-01-06 20:09 <DIR> --d----- c:\program files\Perfect World Entertainment
    2009-01-06 20:00 <DIR> --d----- c:\program files\BitComet
    2009-01-06 12:36 <DIR> --d----- c:\docume~1\owner\applic~1\MSNInstaller
    2009-01-06 12:10 172 a---h--- C:\sqmnoopt03.sqm
    2009-01-06 12:10 172 a---h--- C:\sqmdata03.sqm
    2009-01-05 22:44 268 a---h--- C:\sqmdata02.sqm
    2009-01-05 22:44 244 a---h--- C:\sqmnoopt02.sqm
    2009-01-05 13:45 0 a------- c:\windows\ativpsrm.bin
    2009-01-05 13:40 593,920 -------- c:\windows\system32\ati2sgag.exe
    2009-01-05 13:40 <DIR> --d----- c:\program files\ATI Technologies
    2009-01-05 13:38 <DIR> --d----- C:\ATI
    2009-01-05 13:22 <DIR> --d----- c:\windows\Logs
    2009-01-05 13:16 <DIR> --d----- c:\program files\Zemi Interactive
    2009-01-04 16:48 <DIR> --d----- C:\Downloads
    2009-01-04 16:46 <DIR> --d----- c:\program files\FlashGet
    2009-01-04 14:24 <DIR> --d----- c:\program files\ASIO4ALL v2
    2009-01-04 14:23 225,280 a------- c:\windows\system32\rewire.dll
    2009-01-04 14:23 <DIR> --d----- c:\program files\VstPlugins
    2009-01-04 14:23 1,294,336 a------- c:\windows\system32\vorbis.acm
    2009-01-04 14:23 <DIR> --d----- c:\program files\Outsim
    2009-01-04 14:20 <DIR> --d----- c:\program files\Image-Line
    2009-01-04 14:09 268 a---h--- C:\sqmdata01.sqm
    2009-01-04 14:09 244 a---h--- C:\sqmnoopt01.sqm
    2009-01-04 14:07 268 a---h--- C:\sqmdata00.sqm
    2009-01-04 14:07 244 a---h--- C:\sqmnoopt00.sqm
    2009-01-03 03:02 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
    2009-01-02 14:20 208,744 a------- c:\windows\system32\muweb.dll
    2009-01-02 14:20 268,648 a------- c:\windows\system32\mucltui.dll
    2009-01-02 14:20 27,496 a------- c:\windows\system32\mucltui.dll.mui
    2009-01-01 23:28 <DIR> --d----- c:\documents and settings\owner\Contacts
    2009-01-01 23:27 43,816 a------- c:\windows\system32\drivers\fssfltr.sys
    2009-01-01 23:26 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
    2009-01-01 23:25 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
    2009-01-01 23:25 <DIR> --d----- c:\program files\Windows Live Toolbar
    2009-01-01 23:25 <DIR> --d----- c:\program files\Windows Live Favorites
    2009-01-01 23:22 <DIR> -cdsh--- c:\program files\common files\WindowsLiveInstaller
    2008-12-30 04:23 3,727,720 a------- c:\windows\system32\d3dx9_35.dll
    2008-12-27 14:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Blizzard
    2008-12-27 14:23 <DIR> --d----- c:\program files\common files\Blizzard Entertainment
    2008-12-26 21:51 <DIR> --d----- c:\documents and settings\owner\.narya
    2008-12-26 21:48 <DIR> --d----- c:\docume~1\owner\applic~1\bang
    2008-12-26 14:17 <DIR> --d----- c:\program files\Dofus

    ==================== Find3M ====================

    2009-01-22 12:08 33,408 a------- c:\windows\system32\drivers\fsbts.sys
    2008-12-18 22:16 31 a------- c:\documents and settings\owner\jagex_runescape_preferences.dat
    2008-12-11 03:57 333,184 a------- c:\windows\system32\drivers\srv.sys
    2008-12-01 14:13 3,452,928 a------- c:\windows\system32\drivers\ati2mtag.sys
    2008-12-01 12:52 425,984 a------- c:\windows\system32\ATIDEMGX.dll
    2008-12-01 12:51 318,464 a------- c:\windows\system32\ati2dvag.dll
    2008-12-01 12:46 11,304,960 a------- c:\windows\system32\atioglxx.dll
    2008-12-01 12:41 188,416 a------- c:\windows\system32\atipdlxx.dll
    2008-12-01 12:40 147,456 a------- c:\windows\system32\Oemdspif.dll
    2008-12-01 12:40 26,112 a------- c:\windows\system32\Ati2mdxx.exe
    2008-12-01 12:40 43,520 a------- c:\windows\system32\ati2edxx.dll
    2008-12-01 12:40 143,360 a------- c:\windows\system32\ati2evxx.dll
    2008-12-01 12:38 598,016 a------- c:\windows\system32\ati2evxx.exe
    2008-12-01 12:37 53,248 a------- c:\windows\system32\ATIDDC.DLL
    2008-12-01 12:27 4,120,384 a------- c:\windows\system32\ati3duag.dll
    2008-12-01 12:19 307,200 a------- c:\windows\system32\atiiiexx.dll
    2008-12-01 12:11 2,495,360 a------- c:\windows\system32\ativvaxx.dll
    2008-12-01 12:11 3,107,788 a------- c:\windows\system32\ativvaxx.dat
    2008-12-01 12:11 3,107,788 a------- c:\windows\system32\ativva5x.dat
    2008-12-01 12:11 887,724 a------- c:\windows\system32\ativva6x.dat
    2008-12-01 11:57 48,640 a------- c:\windows\system32\amdpcom32.dll
    2008-12-01 11:53 401,408 a------- c:\windows\system32\atikvmag.dll
    2008-12-01 11:53 45,056 a------- c:\windows\system32\amdcalrt.dll
    2008-12-01 11:53 45,056 a------- c:\windows\system32\amdcalcl.dll
    2008-12-01 11:52 86,016 a------- c:\windows\system32\atiadlxx.dll
    2008-12-01 11:52 17,408 a------- c:\windows\system32\atitvo32.dll
    2008-12-01 11:51 53,248 a------- c:\windows\system32\drivers\ati2erec.dll
    2008-12-01 11:50 286,720 a------- c:\windows\system32\atiok3x2.dll
    2008-12-01 11:50 3,252,224 a------- c:\windows\system32\Amdcaldd.dll
    2008-12-01 11:45 577,536 a------- c:\windows\system32\ati2cqag.dll
    2008-11-27 11:23 73,728 a------- c:\windows\ALCFDRTM.EXE
    2008-11-26 18:40 86,811 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2008-11-26 18:33 8,552 a------- c:\windows\system32\drivers\asctrm.sys
    2008-11-10 05:43 410,984 a------- c:\windows\system32\deploytk.dll
    2008-10-30 06:45 180,720 a------- c:\windows\system32\atiicdxx.dat

    ============= FINISH: 11:22:35.82 ===============
    jus to let you know .i know nothing about computers.
     
  2. 2009/01/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS kimmy :)

    Please visit the following webpage for instructions for downloading and running ComboFix

    How to use ComboFix


    Download ComboFix by sUBs from here, saving the file to your desktop.


    Disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click ComboFix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall

    **NOTE - I recommend you allow the Recovery Console to be downloaded and installed if or when prompted.
     

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.