PDA

View Full Version : can I get a recomendation for anti-virus software?



jrtking73
2006-02-04, 10:17
Hey wiser folks, can I get a recomendation for anti-spyware software. I am wondering what does what and how well. Do I even need it if I have spybot, adaware and a firewall? Feel free to wax eloquent as I am a newbie to this stuff. Thanks
Jeremy

stevek
2006-02-04, 13:14
Read your post-not sure if you are looking for anti-virus or anti-spyware. I am not an expert, but I do have a few suggestions, based upon my reading here and at other sites.

If you do not have anti-virus, I think you will need it-there are several good anti-virus programs-including free ones-but I am not experienced enough to tell you which one is best.

I would suggest these 3 freeware programs which offer real time protection(prevent spyware from being installed)
WinPatrol, SpywareBlaster and Spyware Guard
These products are well known and widely used.

Also Microsoft Anit-Spyware beta (also free right now) offers real time protection as well as scanning for spyware infections.

Another free product is CWShredder-which removes CoolWebSearch.

I have all of these(including Spybot and Adaware-and some paid programs) and they do not conflict-except that Adaware plus, with Ad-watch does have some initial small conflicts.

There is some overlapping in coverage between these, but between them you will be well covered against spyware.

I would also suggest you look at the Spyware Warrior site-they have info and advice about about these issues as well as listings of "anti-spyware" to stay away from.

Hope this helps.

Zenobia
2006-02-04, 13:59
If you do not have anti-virus, I think you will need it-there are several good anti-virus programs-including free ones

There's a couple of the free antivirus programs listed here(down at number 10.):
http://forums.spybot.info/showthread.php?t=279

jadinolf
2006-02-05, 03:24
I have Norton Antivirus on all three of my computers BUT if I were to use a free one, I would use avast! since it likes to work with my browser Mozilla/SeaMonkey. :bigthumb:

Danny
2006-02-05, 14:05
Hello
Me too i am a little bit confuse about your request....
if you need a antivirus....
Bit Defender is super
Norton is very good
NOD 32 also
....in free software,Antivir seem to be the best choice(take this one and save your $$)
Bye
edit:
http://www.free-av.com/

jrtking73
2006-02-06, 09:36
sorry for the mess up on the post, I am asking about anti-virus software. I already run spybot and ad-aware and have a firewall, now do I need antivirus, which are good and any to stay away from?:

jrtking73
2006-02-06, 10:23
I tried to download avast, avg and anti-vir and none were able to get onto my computer. My computer couldn't see any security stuff with them so it wouldn't let it on my computer. Then I saved to desktop and that worked but when I tried to run it it said "an error 1006 (000003EE) has occured. Last performed operation was:opening the self-extract archive." Weird, why can't I download this stuff. I have a new computer, run nvidia firewall, spybot, windows xp and a cable connection. Any thoughts?

jrtking73
2006-02-06, 10:38
Ok now anti vir wont work, arrgh!!! I got it to save to desktop and here is what it said when I tried to run it: ZIP damaged: file C:\DOCUM~1\Jeremy\LOCALS~1\Temp\WZSE0.tmp\basic\antivir0.vdf:Bad CRC 1376c1b3 (should be dd45fd23). Possible cause: file transfer error.
Sorry to harrass you guys but I don't know who to ask about this. Thanks.

Danny
2006-02-06, 13:05
Hi
Before any moves,try a scan online
http://www.bitdefender.com/scan8/ie.html
Maybe you have some pests ...
Bye
edit:Clean all your disks(temp &cie)

tashi
2006-02-06, 17:13
Hello jrtking73.

If you did not have an Anti Virus Program on your computer (even if it is brand new) once you got on the internet you could have picked up an infection.


Open SpyBot, check for and get any updates available.
Close all browsers, check for problems and fix everything found in red
Then on the toolbar menu select mode and switch to advanced mode, on the left lower down select tools, and view report, ensure all the options are selected near the bottom except

Uncheck[ ] do not report disabled or known legitimate Items.
uncheck[ ] Include a list of services in report.
Uncheck[ ] Include uninstall list in report.

Now select (near the top) view report.
Press export in the save in box choose a place such as your my documents folder, then in your next post near the bottom select the "browse" button; navigate to and attach or post that report please.

Cheers.

jrtking73
2006-02-06, 19:19
here is the report:
--- Search result list ---
Congratulations!: No immediate threats were found. ()



--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-01-16 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-03 Includes\Cookies.sbi (*)
2006-02-03 Includes\Dialer.sbi (*)
2006-02-03 Includes\Hijackers.sbi (*)
2006-02-03 Includes\Keyloggers.sbi (*)
2006-02-03 Includes\Malware.sbi (*)
2006-02-03 Includes\PUPS.sbi (*)
2006-02-03 Includes\Revision.sbi (*)
2006-02-03 Includes\Security.sbi (*)
2006-02-03 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-02-03 Includes\Trojans.sbi (*)



--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)


--- Startup entries list ---
Located: HK_LM:Run,
command:
file:

Located: HK_LM:Run, ASUS Probe
command: C:\Program Files\ASUS\Asus Probe\AsusProb.exe
file: C:\Program Files\ASUS\Asus Probe\AsusProb.exe
size: 617984
MD5: b7e260f00988380f72ff06d2fe181d70

Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 102448
MD5: 9eb989d83225f2e6d9ecfdccdd0db0ca

Located: HK_LM:Run, nTrayFw
command: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
file: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
size: 266240
MD5: dd42915e9b83fc52d559692b6889a123

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, NVIDIA nTune
command: "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
file: C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe
size: 532480
MD5: ab3a373596c983f3b6827582636cbcad

Located: HK_LM:Run, NvMediaCenter
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1519616
MD5: 60d44ef1cb5f41160e9d0a7e637cc8aa

Located: HK_LM:Run, SoundMan
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 77824
MD5: ff86e640e4e0fd18cfb4696b38867222

Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8

Located: HK_CU:Run, ResChanger 2005
command: C:\Program Files\ResChanger 2005\ResChanger2005.exe
file: C:\Program Files\ResChanger 2005\ResChanger2005.exe
size: 885248
MD5: 969e2ebd9a986dff168b6d8e38e122e6

Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496eee0ddbe485f658693826f44d38

Located: Startup (common), Adobe Reader Speed Launch.lnk
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: deb88aef013dd1eefb462d7cad642166

Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll

Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll

Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll

Located: System.ini, ScCertProp
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, Schedule
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll

Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll

Located: System.ini, termsrv
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, wlballoon
command: wlnotify.dll
file: wlnotify.dll



--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
BHO name:
CLSID name: AcroIEHlprObj Class
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link: http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Adobe\Acrobat 7.0\ActiveX\
Long name: AcroIEHelper.dll
Short name: ACROIE~1.DLL
Date (created): 12/14/2004 1:56:50 AM
Date (last access): 2/6/2006 9:26:50 AM
Date (last write): 12/14/2004 1:56:50 AM
Filesize: 63136
Attributes: archive
MD5: 42729C3DE75A7A51FC6F9EF6546C9199
CRC32: 4D60BD07
Version: 7.0.0.1333

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 1/16/2006 5:35:26 PM
Date (last access): 2/6/2006 9:26:50 AM
Date (last write): 5/31/2005 1:04:00 AM
Filesize: 853672
Attributes: archive
MD5: 250D787A5712D7768DDC133B3E477759
CRC32: D4589A41
Version: 1.4.0.0



--- ActiveX list ---
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Installer: C:\WINDOWS\Downloaded Program Files\opuc.inf
Codebase: http://office.microsoft.com/officeupdate/content/opuc3.cab
description:
classification: Legitimate
known filename: opuc.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 11/17/2005 11:12:26 PM
Date (last access): 2/6/2006 9:50:36 AM
Date (last write): 11/17/2005 11:12:26 PM
Filesize: 533504
Attributes: archive
MD5: 24F3058766D5FC3FD0F37F6D6EE6FE9B
CRC32: F1FAEDE3
Version: 12.0.3208.1014

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
Codebase: http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137475470828
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 5/26/2005 4:19:32 AM
Date (last access): 2/6/2006 1:42:22 AM
Date (last write): 5/26/2005 4:19:32 AM
Filesize: 178408
Attributes: archive
MD5: EE37AA2C0700221CD8B02FADCD4C7FB5
CRC32: F5494B06
Version: 5.8.0.2469



--- Process list ---
PID: 0 ( 0) [System]
PID: 596 ( 4) \SystemRoot\System32\smss.exe
PID: 660 ( 596) \??\C:\WINDOWS\system32\csrss.exe
PID: 684 ( 596) \??\C:\WINDOWS\system32\winlogon.exe
PID: 728 ( 684) C:\WINDOWS\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 740 ( 684) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 892 ( 728) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 952 ( 728) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1048 ( 728) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1100 ( 728) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1224 ( 728) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1500 ( 728) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 1616 (1584) C:\WINDOWS\Explorer.EXE
size: 1032192
MD5: A0732187050030AE399B241436565E64
PID: 1692 (1616) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
size: 266240
MD5: DD42915E9B83FC52D559692B6889A123
PID: 1740 (1616) C:\WINDOWS\SOUNDMAN.EXE
size: 77824
MD5: FF86E640E4E0FD18CFB4696B38867222
PID: 1756 (1616) C:\Program Files\ASUS\Asus Probe\AsusProb.exe
size: 617984
MD5: B7E260F00988380F72FF06D2FE181D70
PID: 1792 (1616) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 102448
MD5: 9EB989D83225F2E6D9ECFDCCDD0DB0CA
PID: 1804 (1616) C:\Program Files\ResChanger 2005\ResChanger2005.exe
size: 885248
MD5: 969E2EBD9A986DFF168B6D8E38E122E6
PID: 1812 (1616) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496EEE0DDBE485F658693826F44D38
PID: 1820 (1616) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8
PID: 196 ( 728) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
size: 53248
MD5: 435D862E96FE19612093177CF6618F4E
PID: 216 ( 728) C:\Program Files\Alwil Software\Avast4\ashServ.exe
size: 102448
MD5: 0839B8BFDF17DAC8C9B083009768400E
PID: 256 ( 728) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
size: 20543
MD5: B81F8778F5BB485F3B75114F0C99A49F
PID: 296 ( 728) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 340 ( 728) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
size: 131136
MD5: CF0FA7F8366002692BF7E46805F531B9
PID: 628 ( 728) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
size: 57412
MD5: ACE9C161B76C066288A17FEA4BB7BFFC
PID: 1024 ( 728) C:\WINDOWS\system32\nvsvc32.exe
size: 131139
MD5: 0B24AB7CC5B7ED2AA7F438A4072459F4
PID: 1276 ( 728) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
size: 139264
MD5: B47576825F0A397E1C807C7EC23E1560
PID: 1556 ( 256) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
size: 20543
MD5: B81F8778F5BB485F3B75114F0C99A49F
PID: 3060 ( 728) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
size: 241712
MD5: A7A61A9FFE49102C0ECDC259C915BDB9
PID: 3340 ( 728) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
size: 364592
MD5: 1E898FA5EA0C8CB3BF053997516BB2C0
PID: 3644 ( 728) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 1420 ( 876) C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
size: 176176
MD5: 0560A71DC80152DCA0A283894DC99E2B
PID: 1996 (1616) C:\Program Files\Internet Explorer\IEXPLORE.EXE
size: 93184
MD5: E7484514C0464642BE7B4DC2689354C8
PID: 3056 (1812) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 4 ( 0) System


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 2/6/2006 10:04:29 AM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.comcast.net/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


--- Winsock Layered Service Provider list ---
Protocol 0: NVIDIA App Filter over [MSAFD Tcpip [TCP/IP]]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 1: NVIDIA App Filter over [MSAFD Tcpip [UDP/IP]]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 2: NVIDIA App Filter over [MSAFD Tcpip [RAW/IP]]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 3: NVIDIA App Filter over [RSVP UDP Service Provider]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 4: NVIDIA App Filter over [RSVP TCP Service Provider]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 5: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDA978EB-4C6E-4E0C-BA3A-2E7B6CFFE3A6}] SEQPACKET 0]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

jrtking73
2006-02-06, 19:20
Hi I cant put up attachments or text longer than 20000 characters for some reason so here is the rest:
Protocol 6: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDA978EB-4C6E-4E0C-BA3A-2E7B6CFFE3A6}] DATAGRAM 0]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 7: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{1F182AB0-F26E-49F9-B6C6-1B7F74FB295A}] SEQPACKET 1]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 8: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{1F182AB0-F26E-49F9-B6C6-1B7F74FB295A}] DATAGRAM 1]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 9: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{A06F4491-D89C-495F-AF05-61BD7926F202}] SEQPACKET 2]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 10: NVIDIA App Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{A06F4491-D89C-495F-AF05-61BD7926F202}] DATAGRAM 2]
GUID: {F05B916E-2448-4C07-89B7-AAD9CBF9C007}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 11: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 12: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 13: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 14: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 15: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDA978EB-4C6E-4E0C-BA3A-2E7B6CFFE3A6}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDA978EB-4C6E-4E0C-BA3A-2E7B6CFFE3A6}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1F182AB0-F26E-49F9-B6C6-1B7F74FB295A}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1F182AB0-F26E-49F9-B6C6-1B7F74FB295A}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A06F4491-D89C-495F-AF05-61BD7926F202}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A06F4491-D89C-495F-AF05-61BD7926F202}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 22: NVIDIA App Filter
GUID: {561A1E9F-D78B-40E3-866D-4CE5CF6BB83F}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace


thanks again everybody, learning this stuff is like learning a new language and culture. I appreciate the help.
Jeremy

Subratam
2006-02-06, 19:40
Would you kindly download ewido from www.ewido.net/en and go to safe mode ( press F8 repeatedly on startup) and then try to install ewido in safe mode. If it installs , run a complete scan in safe mode itself and report back

jrtking73
2006-02-07, 07:11
ok here is the report:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 10:05:08 PM, 2/6/2006
+ Report-Checksum: 344034E2

+ Scan result:

C:\Documents and Settings\Jeremy\Cookies\squirrel@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup


::Report End
It worked the second time I downloaded it, weird huh? Is it possible that downloading too fast creates errors and that is my prob? Any and all feedback is totally appreciated.
Jeremy King