Gokul New Member Date Joined Dec 2007 Total Posts : 14 Posted 9-1-2008 6:43 (GMT +1) HELLO, HI ALL ...........HERE IS MY LOG......... Windows Explorer has encountered a problem and needs to close., Error message when trying to delete a file. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 09/01/2008 at 11:09 AM Application Version : 4.20.1046 Core Rules Database Version : 3552 Trace Rules Database Version: 1540 Scan type : Complete Scan Total Scan Time : 00:52:02 Memory items scanned : 427 Memory threats detected : 0 Registry items scanned : 5986 Registry threats detected : 23 File items scanned : 19543 File threats detected : 2 Adware.Vundo Variant HKLM\Software\Classes\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF} HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF} HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF} HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\InprocServer32 HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\InprocServer32#ThreadingModel HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\ProgID HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\Programmable HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\TypeLib HKCR\CLSID\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF}\VersionIndependentProgID HKCR\Skype.Control.1 HKCR\Skype.Control HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E} HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E}\1.0 HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E}\1.0\0 HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E}\1.0\0\win32 HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E}\1.0\FLAGS HKCR\TypeLib\{B3878BF0-95A7-4157-B32E-BE7FAEA62F9E}\1.0\HELPDIR C:\WINDOWS\SYSTEM32\SKYPECOMM.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9018F6A8-2495-45DF-9F16-C738F8F3C8FF} HKCR\Interface\{2883C34C-1C7B-43CC-B4CC-93B581E87BE1} HKCR\Interface\{2883C34C-1C7B-43CC-B4CC-93B581E87BE1}\ProxyStubClsid HKCR\Interface\{2883C34C-1C7B-43CC-B4CC-93B581E87BE1}\ProxyStubClsid32 HKCR\Interface\{2883C34C-1C7B-43CC-B4CC-93B581E87BE1}\TypeLib HKCR\Interface\{2883C34C-1C7B-43CC-B4CC-93B581E87BE1}\TypeLib#Version Rogue.AntiSpyBoss-FakeThreats C:\WINDOWS\SOFTWAREDISTRIBUTION\DOWNLOAD\86A5D4EC598B957D3E4D2A7951B2C258\SP2GDR\XPSP3RES.DLL --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ComboFix 08-08-31.01 - Goks 2008-09-01 22:50:22.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.596 [GMT 5.5:30] Running from: C:\Documents and Settings\Goks\Desktop\ComboFix.exe * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 ))))))))))))))))))))))))))))))) . 2008-09-01 22:22 . 2008-09-01 22:22 <DIR> d-------- C:\Program Files\Trend Micro 2008-09-01 16:57 . 2008-09-01 16:55 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-09-01 16:55 . 2008-09-01 19:10 <DIR> d-------- C:\Documents and Settings\Goks\.housecall6.6 2008-09-01 16:16 . 2008-09-01 16:40 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-09-01 15:18 . 2008-09-01 15:18 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-09-01 15:18 . 2008-09-01 15:18 <DIR> d-------- C:\Documents and Settings\Goks\Application Data\Malwarebytes 2008-09-01 15:18 . 2008-09-01 15:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-09-01 15:18 . 2008-08-17 15:05 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-09-01 15:18 . 2008-08-17 15:05 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-08-31 18:23 . 2008-08-31 18:23 <DIR> d-------- C:\Program Files\Arcade Classic Pack 2008-08-30 14:16 . 2008-08-30 14:16 18,538 --a------ C:\WINDOWS\system32\mstmpxmlfun.xml 2008-08-30 09:18 . 2008-08-30 09:18 <DIR> d-------- C:\Program Files\gBurner 2008-08-28 23:07 . 2008-08-28 23:07 <DIR> d-------- C:\Program Files\SUPERAntiSpyware 2008-08-28 23:07 . 2008-08-28 23:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-08-28 23:07 . 2008-08-28 23:07 <DIR> d-------- C:\Documents and Settings\Goks\Application Data\SUPERAntiSpyware.com 2008-08-28 23:07 . 2008-08-28 23:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-08-28 22:21 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll 2008-08-28 16:50 . 2008-08-28 16:50 <DIR> d-------- C:\WINDOWS\system32\CatRoot2-Old 2008-08-28 14:22 . 2008-08-28 14:22 <DIR> d-------- C:\Program Files\Windows Installer Clean Up 2008-08-28 14:22 . 2008-08-28 14:22 <DIR> d-------- C:\Program Files\MSECACHE 2008-08-28 13:22 . 2001-08-17 22:36 35,840 --a------ C:\WINDOWS\system32\sens.dll 2008-08-28 00:28 . 2008-08-31 13:11 121 --a------ C:\WINDOWS\bdagent.INI 2008-08-28 00:26 . 2008-08-28 00:26 839 --a------ C:\WINDOWS\system32\ProductTweaks.xml 2008-08-28 00:26 . 2008-08-28 00:26 289 --a------ C:\WINDOWS\system32\user_gensett.xml 2008-08-27 23:44 . 2008-08-31 12:41 <DIR> d-------- C:\temp\msn 2008-08-27 23:41 . 2008-08-31 13:13 <DIR> d-------- C:\Program Files\BitDefender 2008-08-27 23:41 . 2008-08-31 13:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-08-27 23:39 . 2008-08-27 23:39 <DIR> d-------- C:\WINDOWS\system32\URTTEMP 2008-08-27 23:37 . 2008-08-27 23:41 <DIR> d-------- C:\Program Files\Common Files\BitDefender 2008-08-27 17:17 . 2008-08-27 17:19 <DIR> d-------- C:\Program Files\RegCure 2008-08-27 12:10 . 2008-08-27 12:13 <DIR> d-------- C:\WINDOWS\system32\QVJGTGljZW5zZUluZm8= 2008-08-27 12:10 . 2008-09-01 16:14 <DIR> d-------- C:\Program Files\Advanced Registry Fix 2008-08-25 23:20 . 2008-08-25 23:20 <DIR> d-------- C:\OEMSettings 2008-08-25 15:26 . 2008-08-25 15:26 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-08-25 14:55 . 2008-08-25 15:25 <DIR> d-------- C:\Program Files\NETGEAR 2008-08-19 17:47 . 2008-08-19 17:47 <DIR> d-------- C:\Documents and Settings\Goks\Application Data\vlc 2008-08-16 17:11 . 2008-08-16 17:11 <DIR> d-------- C:\Program Files\ABBYY FineReader 5.0 Sprint 2008-08-11 11:15 . 2008-08-11 11:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-08-11 11:15 . 2008-08-13 09:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-08-11 10:41 . 2008-08-11 10:41 <DIR> d-------- C:\Program Files\AMUST 2008-08-11 10:41 . 2006-11-09 19:32 149,248 --a------ C:\WINDOWS\system32\RegCompact.dll 2008-08-08 12:48 . 2008-08-08 12:48 <DIR> d-------- C:\Program Files\iTunes 2008-08-08 12:48 . 2008-08-08 12:48 <DIR> d-------- C:\Program Files\iPod 2008-08-08 11:46 . 2008-08-08 11:46 <DIR> d-------- C:\Program Files\Apple Software Update 2008-08-06 16:11 . 2008-01-03 11:28 <DIR> d-a------ C:\RingThis 2008-08-03 14:04 . 2008-08-03 14:04 <DIR> d-------- C:\Program Files\Cucusoft 2008-08-02 11:12 . 2004-08-04 00:56 815,104 --a------ C:\WINDOWS\system32\mmc.exe 2008-08-02 11:12 . 2004-08-04 00:56 815,104 --a--c--- C:\WINDOWS\system32\dllcache\mmc.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-09-01 16:44 --------- d-----w C:\Program Files\YPOPs 2008-09-01 11:10 --------- d-----w C:\Program Files\FlashGet 2008-09-01 10:44 --------- d-----w C:\Program Files\MegauploadToolbar 2008-09-01 09:21 3,982 ---ha-w C:\WINDOWSkj01d.sys 2008-08-27 18:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-08-27 11:39 --------- d-----w C:\Documents and Settings\Goks\Application Data\MegauploadToolbar 2008-08-27 11:37 --------- d-----w C:\Program Files\Symantec 2008-08-25 17:51 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-08-25 12:02 --------- d-----w C:\Program Files\Opera 2008-08-19 12:05 --------- d-----w C:\Program Files\VideoLAN 2008-08-19 11:56 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-08-09 23:38 --------- d-----w C:\Documents and Settings\Goks\Application Data\U3 2008-08-07 10:15 --------- d-----w C:\Documents and Settings\Goks\Application Data\dvdcss 2008-08-04 23:40 --------- d--h--w C:\Documents and Settings\All Users\Application Data\Symantec 2008-07-30 12:12 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-07-30 11:58 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-07-30 11:58 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat 2008-07-29 07:51 --------- d-----w C:\Program Files\Norton AntiVirus 2008-07-22 15:02 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys 2008-07-18 04:05 --------- d-----w C:\Program Files\WinXMedia 2008-07-17 11:16 --------- d-----w C:\Program Files\Common Files\Adobe 2008-07-15 05:02 --------- d-----w C:\Program Files\Sun 2008-07-15 05:01 --------- d-----w C:\Program Files\Java 2008-07-12 17:34 --------- d-----w C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter 2008-07-12 05:59 --------- d-----w C:\Documents and Settings\Goks\Application Data\Apple Computer 2008-07-04 14:58 --------- d-----w C:\Program Files\Safari 2008-07-04 14:34 --------- d-----w C:\Program Files\QuickTime 2007-12-28 09:32 287,232 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys 2007-12-28 09:29 342,528 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys 2007-11-27 12:23 63,488 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv64.exe 2007-11-27 12:22 32,768 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe 2006-12-15 06:00 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe 2006-12-15 06:00 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe 2006-12-15 06:00 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe 2006-12-15 06:00 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe 2006-12-15 06:00 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE . ------- Sigcheck ------- 2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\FlyakiteOSX\Backup\wininet.dll 2008-02-16 14:29 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\SoftwareDistribution\Download\4f34fed83363df83031761e8fceb73ae\sp2gdr\wininet.dll 2008-02-16 15:02 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\SoftwareDistribution\Download\4f34fed83363df83031761e8fceb73ae\sp2qfe\wininet.dll 2004-08-04 00:56 677376 d866a8e7ce1c2f09c2c4276f9a615c0a C:\WINDOWS\system32\wininet.dll 2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys 2004-08-03 23:14 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys 2004-08-04 00:56 1364480 5de8ffe4acd3c0a3c0166a6129a12241 C:\WINDOWS\explorer.exe 2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\FlyakiteOSX\Backup\explorer.exe 2004-08-04 00:56 1364480 5de8ffe4acd3c0a3c0166a6129a12241 C:\WINDOWS\system32\dllcache\explorer.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "TransBar"="C:\Documents and Settings\Goks\Local Settings\Application Data\AKSoftware\TransBar\TransBar.exe" [2005-06-02 01:11 65536] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 23:34 1576176] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040] "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-12 11:25 26248] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 98304] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-12 11:36 84640] "nForce Tray Options"="sstray.exe" [2003-06-17 17:18 73728 C:\WINDOWS\system32\sstray.exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe] "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe] C:\Documents and Settings\Goks\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\onenotem.exe [2006-10-26 20:24:54 72008] Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-02-18 16:33:15 3450608] YPOPs.lnk - C:\Program Files\YPOPs\YPOPs.exe [2008-07-01 11:38:06 1355776] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-08-30 14:03:19 805392] NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2008-07-01 10:34:48 2326528] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\RegCompact] 2006-11-09 19:32 149248 C:\WINDOWS\system32\RegCompact.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKey HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung Common SM HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alt+Q Hotkey Tool] --a------ 2005-12-19 00:44 27648 C:\WINDOWS\Alt+Q Hotkey.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2006-03-01 19:43 90112 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk] --a------ 2007-01-02 02:52 3739648 C:\Program Files\Google\Google Talk\googletalk.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] --a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] --a------ 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2004-08-04 01:06 1659392 C:\Program Files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RK Launcher] --a------ 2005-10-19 13:10 393216 C:\Program Files\RK Launcher\RKLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Files Updater] --a------ 2006-02-26 05:11 118485 C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UberIcon] --a------ 2006-02-24 06:02 188416 C:\Program Files\UberIcon\UberIcon Manager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yz Shadow] --a------ 2006-02-24 08:21 172032 C:\Program Files\YzShadow\YzShadow.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSLAGENTEXE] --a------ 2002-05-02 11:15 16384 C:\WINDOWS\system32\dslagent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSICONEXE] --a------ 2002-05-02 11:12 90112 C:\WINDOWS\system32\gsicon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ERSvc"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "C:\\Program Files\\FlashGet\\flashget.exe"= "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2007-10-09 13:13] R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-12-28 15:02] S0 MFX;MFX;C:\WINDOWS\system32\drivers\MFX.sys [2008-02-18 00:48] S2 gafwload;GlobespanVirata USB ADSL Loader;C:\WINDOWS\system32\DRIVERS\gafwload.sys [2002-03-22 06:31] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{405af5e0-ddbe-11dc-a8ef-000779300101}] \Shell\AutoRun\command - J:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb28d9a5-debb-11dc-a8f6-000779300101}] \Shell\AutoRun\command - J:\LaunchU3.exe -a *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Documents and Settings\Goks\Application Data\Mozilla\Firefox\Profiles\zo13yxh9.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-01 22:52:47 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\x___x C:\WINDOWS\system32\drivers\MFX.sys 20780 bytes executable scan completed successfully hidden files: 2 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe -> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll . Completion time: 2008-09-01 22:56:20 ComboFix-quarantined-files.txt 2008-09-01 17:25:37 Pre-Run: 2,556,915,712 bytes free Post-Run: 2,558,959,616 bytes free 251 --- E O F --- 2008-05-01 03:49:47 ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:02:44 PM, on 9/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Microsoft Office\Office12\onenotem.exe C:\Program Files\Stardock\ObjectDock\ObjectDock.exe C:\Program Files\YPOPs\YPOPs.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\progra~1\micros~2\office12\outlook.exe C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file) O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TransBar] C:\Documents and Settings\Goks\Local Settings\Application Data\AKSoftware\TransBar\TransBar.exe /s O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\onenotem.exe O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Startup: YPOPs.lnk = ? O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab O16 - DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} - O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe -- End of file - 9715 bytes ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ THANKS THANKS Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 14350 Posted 9-2-2008 5:09 (GMT +1) Hello
Please download Malwarebytes' Anti-Malware:
Or here:
to your desktop .
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan , then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location.
Copy and Paste that log into your next reply, along with fresh hijackthis log.
NB : If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Do NOT post your problem in someone elses thread.
Back to Top
Gokul New Member Date Joined Dec 2007 Total Posts : 14 Posted 9-2-2008 10:41 (GMT +1) Malwarebytes' Anti-Malware 1.25 Database version: 1102 Windows 5.1.2600 Service Pack 2 3:08:32 PM 9/2/2008 mbam-log-09-02-2008 (15-08-32).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|) Objects scanned: 143968 Time elapsed: 2 hour(s), 7 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Advanced Registry Fix\Interop.IWshRuntimeLibrary.dll (Rogue.ErrorEraser) -> Quarantined and deleted successfully. C:\Program Files\Advanced Registry Fix\RegistryOptimization.dll (Rogue.ErrorEraser) -> Quarantined and deleted successfully. F:\Goks\Mobile\Pocket Pc_1\System Tools\Phone Utilities\Sms-Manager\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. F:\Goks\Mobile\Pocket Pc_1\3\Spb Software House\spb diary 1.0\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. F:\Goks\Mobile\Pocket Pc_1\3\Omega one\1-calc 2.1\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. F:\Goks\Mobile\Pocket Pc_1\Game Packs\Tomb Raider for Pocket PC\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. F:\Goks\Mobile\Pocket PC Crap_3\Spb Full Screen Keyboard v3.0 Regged-corepda\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:10:11 PM, on 9/2/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Microsoft Office\Office12\onenotem.exe C:\Program Files\Stardock\ObjectDock\ObjectDock.exe C:\Program Files\YPOPs\YPOPs.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\FlashGet\flashget.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file) O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TransBar] C:\Documents and Settings\Goks\Local Settings\Application Data\AKSoftware\TransBar\TransBar.exe /s O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\onenotem.exe O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Startup: YPOPs.lnk = ? O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab O16 - DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} - O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe -- End of file - 9858 bytes ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Back to Top
Gokul New Member Date Joined Dec 2007 Total Posts : 14 Posted 9-2-2008 8:36 (GMT +1) hi thanks for the reply.. if i open a folder in my F Drive. An window pop's up and says this "Windows Explorer has encountered a problem and needs to close. We are sorry for the inconvenience." and then all the wondow's closes. Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 14350 Posted 9-3-2008 6:02 (GMT +1) Ok. Open Malwarebytes' Anti-Malware - quarantine tab, click/mark the log from Yesterday 10:41 - Restore it.
See if you still get this message - "Windows Explorer has encountered a problem."
If you don´t, run Malwarebytes' Anti-Malware again, and uncheck F: drive
Do NOT post your problem in someone elses thread.
Back to Top
Gokul New Member Date Joined Dec 2007 Total Posts : 14 Posted 9-3-2008 6:35 (GMT +1) there is no change.. if i open a folder in F drive.. again same error. Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 14350 Posted 9-3-2008 7:01 (GMT +1) Ok, check for missing or corrupted system files -
To do this simply go to the Run box on the Start Menu and type/copy in:
sfc /scannow
This command will immediately initiate the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem.
Reboot
Do NOT post your problem in someone elses thread.
Back to Top
Forum Information Currently it is Saturday, January 10, 2009 1:23 AM (GMT +1) There are a total of 66.010 posts in 16.187 threads. In the last 3 days there were 18 new threads and 109 reply posts. View Active Threads Who's Online This forum has 27805 registered members. Please welcome our newest member, atwitsend . 33 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads