Hi
I noticed after I attempted to update Firefox, via the Firefox updater tool, that Firefox would not display any pages. I was getting a standard error message along the lines of, “Unable to connect.” I then tried to launch IE and it is the only browser that now works. I uninstalled and tried to re-install Firefox, and now it does not even load. I also tried to download Chrome, but that won’t even install for some reason.
A separate, but maybe connected issue: a few weeks back the tech support guy at my ISP told me to uninstall all anti-virus software, in an attempt to resolve a problem with my modem and router. At that time, I tried to uninstall all Norton Internet Security/Symantec stuff. However, the uninstall is incomplete. I tried to download the uninstall tool from Symantec directly and the computer won’t let me (ha!). I get an error message that says, “unable to connect to server.”
So, I tried to download McAfee which my ISP provides free to its subscribers. I get almost all the way through the download but then it stops and gives me an error that there’s no internet connection, which obviously that’s not the case. On my other laptop I have successfully used Spybot Search & Destroy, so I tried to download and install it to this laptop. However, I get partially through the initial setup and am then given the error message as a weird looking popup that says “Error Sending Request. A connection to the server could not be established.” So, I called my ISP again and was told I have some kind of virus that’s blocking my ports.
Long story short: only IE works, sometimes it blocks a few webpages (like, eBay, Food Network, and Huffington Post). And, I can’t run any anti-virus software. I tried doing an online scan on Panda Security but my computer runs so hot that it shuts down after getting to about 26%. I tried using the Microsoft Security Essentials scan and it found nothing, so did Malwarebytes (because my computer won't let it update, I think). My machine runs Vista, but not even SP1 because the update won’t install (I think because, again, my computer runs too hot). I have a used HP Pavilion laptop.
Please, please help! Have zero ideas at this point...and cannot afford for McAfee to take remote control of my computer to fix it.
Hi,
I realized that I did not include the DDS report regarding the issue I requested help for: http://forums.spybot.info/showthread.php?t=64052
Totally not trying to make this any harder than it needs to be, my apologies. A little too stressed to be more precise. Can this be merged with my prior post? Not trying to bump at all!
Here's the report. Ever so grateful for your review. Thanks,
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6000.16982 BrowserJavaVersion: 1.6.0_26
Run by KLB at 14:54:57 on 2011-10-03
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.833 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\FaxTalk Trial\FTclctrl.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\FaxTalk Trial\FTmsgsvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [hpqSRMon]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [FaxTalk FaxCenter Pro 8] "c:\program files\faxtalk trial\FTClCtrl.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\klb\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: EnableLUA = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\npjpi160_26.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{80C29B12-5FE1-4137-B7E4-2E25574E3145} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{9BF7A8D0-0218-4926-A7BA-12AEE79A3EBA} : DhcpNameServer = 192.168.1.1
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\klb\appdata\roaming\mozilla\firefox\profiles\y3scdo80.default\
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\klb\appdata\roaming\mozilla\plugins\npatgpc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2011-10-1 28552]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20110629.002\IDSvix86.sys [2011-7-1 287792]
R2 FaxTalk FaxCenter Pro 8;FaxTalk FaxCenter Pro 8;c:\program files\faxtalk trial\FTmsgsvc.exe [2011-5-19 33120]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2006-11-2 16896]
S4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2011-5-10 149352]
S4 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2011-5-10 1251720]
.
=============== Created Last 30 ================
.
2011-10-03 14:27:14 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{99cba211-fbd9-466b-92ab-255096b81ead}\offreg.dll
2011-10-02 20:26:45 -------- d-----w- c:\users\klb\appdata\local\Seven Zip
2011-10-02 04:05:52 -------- d-----w- c:\users\klb\appdata\roaming\Malwarebytes
2011-10-02 04:05:31 -------- d-----w- c:\programdata\Malwarebytes
2011-10-01 23:31:11 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2011-10-01 22:55:20 -------- d-----w- c:\users\klb\HijackThis
2011-10-01 21:58:26 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{99cba211-fbd9-466b-92ab-255096b81ead}\mpengine.dll
2011-10-01 18:58:58 -------- d-----w- c:\program files\Panda Security
2011-10-01 18:45:44 -------- d-----w- C:\TEMP
2011-10-01 14:59:33 -------- d-----w- c:\users\klb\appdata\local\Deployment
2011-09-04 16:02:58 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-09-04 16:02:58 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-09-04 16:02:58 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-09-04 16:02:52 713728 ----a-w- c:\windows\system32\timedate.cpl
2011-09-04 16:02:49 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2011-09-04 16:02:49 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-09-04 15:59:25 311296 ----a-w- c:\windows\system32\unregmp2.exe
2011-09-04 15:59:25 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
2011-09-04 15:59:24 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-09-04 15:59:24 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-09-04 15:59:24 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-09-04 15:59:24 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-09-04 15:59:24 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2011-09-04 15:59:24 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2011-09-04 15:59:23 8147968 ----a-w- c:\windows\system32\wmploc.DLL
.
==================== Find3M ====================
.
2011-07-22 21:07:38 413760 ----a-w- c:\windows\system32\MPG4c32.dll
2011-07-22 21:07:38 239888 ----a-w- c:\windows\system32\MPG4ds32.ax
2011-07-22 20:51:50 94208 ----a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 14:55:15.78 ===============
I noticed after I attempted to update Firefox, via the Firefox updater tool, that Firefox would not display any pages. I was getting a standard error message along the lines of, “Unable to connect.” I then tried to launch IE and it is the only browser that now works. I uninstalled and tried to re-install Firefox, and now it does not even load. I also tried to download Chrome, but that won’t even install for some reason.
A separate, but maybe connected issue: a few weeks back the tech support guy at my ISP told me to uninstall all anti-virus software, in an attempt to resolve a problem with my modem and router. At that time, I tried to uninstall all Norton Internet Security/Symantec stuff. However, the uninstall is incomplete. I tried to download the uninstall tool from Symantec directly and the computer won’t let me (ha!). I get an error message that says, “unable to connect to server.”
So, I tried to download McAfee which my ISP provides free to its subscribers. I get almost all the way through the download but then it stops and gives me an error that there’s no internet connection, which obviously that’s not the case. On my other laptop I have successfully used Spybot Search & Destroy, so I tried to download and install it to this laptop. However, I get partially through the initial setup and am then given the error message as a weird looking popup that says “Error Sending Request. A connection to the server could not be established.” So, I called my ISP again and was told I have some kind of virus that’s blocking my ports.
Long story short: only IE works, sometimes it blocks a few webpages (like, eBay, Food Network, and Huffington Post). And, I can’t run any anti-virus software. I tried doing an online scan on Panda Security but my computer runs so hot that it shuts down after getting to about 26%. I tried using the Microsoft Security Essentials scan and it found nothing, so did Malwarebytes (because my computer won't let it update, I think). My machine runs Vista, but not even SP1 because the update won’t install (I think because, again, my computer runs too hot). I have a used HP Pavilion laptop.
Please, please help! Have zero ideas at this point...and cannot afford for McAfee to take remote control of my computer to fix it.
Hi,
I realized that I did not include the DDS report regarding the issue I requested help for: http://forums.spybot.info/showthread.php?t=64052
Totally not trying to make this any harder than it needs to be, my apologies. A little too stressed to be more precise. Can this be merged with my prior post? Not trying to bump at all!
Here's the report. Ever so grateful for your review. Thanks,
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6000.16982 BrowserJavaVersion: 1.6.0_26
Run by KLB at 14:54:57 on 2011-10-03
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.833 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\FaxTalk Trial\FTclctrl.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\FaxTalk Trial\FTmsgsvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [hpqSRMon]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [FaxTalk FaxCenter Pro 8] "c:\program files\faxtalk trial\FTClCtrl.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\klb\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: EnableLUA = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\npjpi160_26.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{80C29B12-5FE1-4137-B7E4-2E25574E3145} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{9BF7A8D0-0218-4926-A7BA-12AEE79A3EBA} : DhcpNameServer = 192.168.1.1
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\klb\appdata\roaming\mozilla\firefox\profiles\y3scdo80.default\
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\klb\appdata\roaming\mozilla\plugins\npatgpc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2011-10-1 28552]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20110629.002\IDSvix86.sys [2011-7-1 287792]
R2 FaxTalk FaxCenter Pro 8;FaxTalk FaxCenter Pro 8;c:\program files\faxtalk trial\FTmsgsvc.exe [2011-5-19 33120]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2006-11-2 16896]
S4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2011-5-10 149352]
S4 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2011-5-10 1251720]
.
=============== Created Last 30 ================
.
2011-10-03 14:27:14 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{99cba211-fbd9-466b-92ab-255096b81ead}\offreg.dll
2011-10-02 20:26:45 -------- d-----w- c:\users\klb\appdata\local\Seven Zip
2011-10-02 04:05:52 -------- d-----w- c:\users\klb\appdata\roaming\Malwarebytes
2011-10-02 04:05:31 -------- d-----w- c:\programdata\Malwarebytes
2011-10-01 23:31:11 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2011-10-01 22:55:20 -------- d-----w- c:\users\klb\HijackThis
2011-10-01 21:58:26 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{99cba211-fbd9-466b-92ab-255096b81ead}\mpengine.dll
2011-10-01 18:58:58 -------- d-----w- c:\program files\Panda Security
2011-10-01 18:45:44 -------- d-----w- C:\TEMP
2011-10-01 14:59:33 -------- d-----w- c:\users\klb\appdata\local\Deployment
2011-09-04 16:02:58 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-09-04 16:02:58 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-09-04 16:02:58 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-09-04 16:02:52 713728 ----a-w- c:\windows\system32\timedate.cpl
2011-09-04 16:02:49 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2011-09-04 16:02:49 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-09-04 15:59:25 311296 ----a-w- c:\windows\system32\unregmp2.exe
2011-09-04 15:59:25 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
2011-09-04 15:59:24 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-09-04 15:59:24 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-09-04 15:59:24 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-09-04 15:59:24 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-09-04 15:59:24 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2011-09-04 15:59:24 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2011-09-04 15:59:23 8147968 ----a-w- c:\windows\system32\wmploc.DLL
.
==================== Find3M ====================
.
2011-07-22 21:07:38 413760 ----a-w- c:\windows\system32\MPG4c32.dll
2011-07-22 21:07:38 239888 ----a-w- c:\windows\system32\MPG4ds32.ax
2011-07-22 20:51:50 94208 ----a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 14:55:15.78 ===============
Last edited by a moderator: