WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Ah my apologies I thought I gave you instructions before.

Download OTL.exe by OldTimer to your Desktop.
  • Close all windows and double click OTL.exe.
  • Click Run Scan and let the program run uninterrupted.
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Here is the extras OTL scan log. The OTL scan is on the first post.

Thanks again

OTL Extras logfile created on: 8/12/2010 11:49:44 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\John\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.71 Gb Total Space | 341.66 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.24 Gb Free Space | 52.35% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 391.33 Gb Free Space | 84.02% Space Free | Partition Type: NTFS
Drive G: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN-PC
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{C3BF82DF-CE5A-4955-A2E0-534AC577CD9F}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{C5D83982-7225-4062-A97B-0427479B451F}" = lport=86 | protocol=6 | dir=in | name=broadcam web server |
"{C723FADE-7085-4FC6-96A6-10AEFE3902B8}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1BE1D5EC-ADCC-4A1E-B3FD-6AF19A888F84}" = protocol=6 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\ttax.exe |
"{211893D5-7B50-49FC-86FF-A2085D00C716}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{234C5622-3DF7-4E16-9027-6E8DFD2D9916}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{27EF8BD5-1010-44AB-9EDB-6CEB740AD121}" = protocol=17 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\updatemgr.exe |
"{303D5885-183A-464E-BBC0-4C4B75D043E6}" = protocol=17 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\ttax.exe |
"{368109EE-B321-4FF6-8AAC-9ADF0C60C388}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{37398C07-3C3D-4650-AAB1-A55633C387CF}" = protocol=6 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\updatemgr.exe |
"{3AC36FB7-39CB-4847-9D55-05A5A57F168D}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{9086F673-6224-4306-BE6E-E4B9E288F79D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{90DDBB83-17C4-4544-B108-DE8CA3D5DE3F}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{CB2CF4AC-6980-43D9-B647-B641C323A8BA}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F215EE0F-EED4-453B-BDA9-D6EE178B718F}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{F5F7A60B-F5C1-4685-9D1A-BB2688E41362}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{08C151C6-98C9-4015-87A3-C836D093A408}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{120F7E7F-AD63-47C3-A6D4-0599DD97ECA9}C:\program files\thinktda\usergui\1613\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1613\ieembed.exe |
"TCP Query User{1E385DC6-055F-4D34-9675-24386ACA5228}C:\program files\thinktda\usergui\1611\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1611\ieembed.exe |
"TCP Query User{378E8393-4C88-43DD-AA85-37CF914E7A5A}C:\program files\thinktda\usergui\1644\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1644\ieembed.exe |
"TCP Query User{43340F0E-F6BF-4E31-81F9-B38718A24364}C:\program files\thinktda\usergui\1614\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1614\ieembed.exe |
"TCP Query User{83429BF1-2711-43F3-BEF6-B34BC4242DD9}C:\program files\thinktda\usergui\1675\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1675\ieembed.exe |
"TCP Query User{AC94E1F6-044B-4D69-B249-29F830A4A87D}C:\program files\thinktda\usergui\1588\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1588\ieembed.exe |
"TCP Query User{B30FED32-ECE3-47F0-BD52-11A4291C4766}C:\program files\thinktda\usergui\1646\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1646\ieembed.exe |
"TCP Query User{B3861E82-BDE7-43E3-8C93-662251906301}C:\program files\thinktda\usergui\1585\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1585\ieembed.exe |
"TCP Query User{D15748B0-4A18-47AF-AD5A-B304525CB7FF}C:\program files\thinktda\usergui\1640\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1640\ieembed.exe |
"TCP Query User{D300BEDD-6F13-4411-B26B-7C0C0B37DEF1}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"TCP Query User{D92E3C52-49AB-422D-9BDB-A40563E390AA}C:\program files\thinktda\usergui\1643\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1643\ieembed.exe |
"TCP Query User{DD497446-821A-4EB6-B833-F9DB19B74020}C:\program files\thinktda\usergui\1642\ieembed.exe" = protocol=6 | dir=in | app=c:\program files\thinktda\usergui\1642\ieembed.exe |
"UDP Query User{061EB3CD-B7B7-4205-AEFF-FD4BDA8323CB}C:\program files\thinktda\usergui\1644\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1644\ieembed.exe |
"UDP Query User{0C191387-AE36-43EE-86B4-0596812F36AC}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1DF50405-21AC-40F8-9C66-8B10938E9F0E}C:\program files\thinktda\usergui\1588\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1588\ieembed.exe |
"UDP Query User{2903ABDB-8FBF-4940-9EA3-76BAE92E9C6B}C:\program files\thinktda\usergui\1613\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1613\ieembed.exe |
"UDP Query User{332F6A2F-B4EF-4C14-9BB7-994640B66886}C:\program files\thinktda\usergui\1614\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1614\ieembed.exe |
"UDP Query User{61145E22-EA95-4406-B6E2-AD11699314E8}C:\program files\thinktda\usergui\1646\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1646\ieembed.exe |
"UDP Query User{6FBDB0C4-B27F-463C-9EE8-A19CB6B4A5B3}C:\program files\thinktda\usergui\1643\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1643\ieembed.exe |
"UDP Query User{8D84F65E-D04E-46FC-9F0E-4BC823D5D630}C:\program files\thinktda\usergui\1642\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1642\ieembed.exe |
"UDP Query User{8F3D2CD9-EB71-4E44-9910-72001EA7ACB1}C:\program files\thinktda\usergui\1675\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1675\ieembed.exe |
"UDP Query User{9E3B7CE6-9CCD-4D20-B8A1-CBF00C4928B9}C:\program files\thinktda\usergui\1611\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1611\ieembed.exe |
"UDP Query User{AA435583-13FB-4330-9441-1C4F2C9859DD}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{B09D9A4F-C8EE-4ABF-9C1F-35764E472B10}C:\program files\thinktda\usergui\1640\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1640\ieembed.exe |
"UDP Query User{DA4B526E-6B81-40C6-86C4-A0136E545DE7}C:\program files\thinktda\usergui\1585\ieembed.exe" = protocol=17 | dir=in | app=c:\program files\thinktda\usergui\1585\ieembed.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Catalyst Media Center
"{2758691A-2CDE-4942-A4AC-0E8F61FE2067}" = USB Video Driver
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4D36E953-4456-4F8F-BC44-90BC4AA59889}" = Maxtor Manager
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{5B30AA25-BF39-4BE4-8FEE-51938BAB214D}" = TurboTax 2008 wcaiper
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.11.0
"{7AA9AC5F-E6E2-4310-9DE5-8282748C0A90}" = Nitro PDF Professional
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C3E98E64-683E-4271-9D39-88B1AAB1AE7B}" = L7600
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CCFF1E13-77A2-4032-8B12-7566982A27DF}" = Internet Service Offers Launcher
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skypeâ„¢ 4.2
"{D7769185-9A7C-48D4-8874-5388743A1DE2}" = Music, Photos & Videos Launcher
"{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}" = U3Launcher
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F95F178B-56AD-4fab-87F8-FA81E66C7D68}" = Network
"{FC4F90EC-B1DA-11D9-9D77-000129760D75}" = Catalyst Media Center DVD Authoring Module
"69083DC58646DE46A09847A522A1CC487F918039" = Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA (08/31/2007 5.7.0831.0)
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG9Uninstall" = AVG Free 9.0
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Google Desktop" = Google Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"PrimoPDF" = PrimoPDF -- brought to you by Nitro PDF Software
"PROSetDX" = Intel(R) PRO Network Connections 12.1.11.0
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"thinkorswim from TD AMERITRADE" = thinkorswim from TD AMERITRADE
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"WS_FTP Pro" = Ipswitch WS_FTP Pro

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1764452266-3460967335-3339530625-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/21/2009 1:12:55 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/21/2009 3:17:40 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/22/2009 1:36:55 AM | Computer Name = John-PC | Source = EventSystem | ID = 4622
Description =

Error - 9/22/2009 1:36:55 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/22/2009 5:57:42 PM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/23/2009 3:20:28 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/23/2009 8:09:41 PM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/24/2009 3:39:25 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/25/2009 8:10:51 PM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/28/2009 3:00:08 AM | Computer Name = John-PC | Source = EventSystem | ID = 4621
Description =

[ Broadcom Wireless LAN Events ]
Error - 6/27/2010 3:51:00 PM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 12:50:59, Sun, Jun 27, 10 Error - Unable to gain access to user store


Error - 8/9/2010 2:05:52 AM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 23:05:52, Sun, Aug 08, 10 Error - Unable to gain access to user store


Error - 8/9/2010 2:43:03 AM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 23:43:03, Sun, Aug 08, 10 Error - Unable to gain access to user store


Error - 8/10/2010 12:46:50 AM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 21:46:50, Mon, Aug 09, 10 Error - Unable to gain access to user store


Error - 8/10/2010 3:11:29 PM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 12:11:29, Tue, Aug 10, 10 Error - Unable to gain access to user store


Error - 8/10/2010 3:58:10 PM | Computer Name = John-PC | Source = WLAN-Tray | ID = 0
Description = 12:58:10, Tue, Aug 10, 10 Error - Unable to gain access to user store


[ Media Center Events ]
Error - 5/30/2008 4:27:20 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/1/2008 1:24:36 AM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/6/2008 11:26:20 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/8/2008 6:04:47 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 11/10/2008 3:05:23 AM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 1/1/2009 2:37:59 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 2/1/2009 2:49:31 AM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 3/8/2009 11:43:11 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/11/2009 3:37:15 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/11/2009 11:44:10 PM | Computer Name = John-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 9/8/2009 11:28:28 PM | Computer Name = John-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 534
seconds with 300 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 8/12/2010 5:15:53 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/12/2010 5:15:53 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/12/2010 5:15:54 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/12/2010 5:15:54 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/12/2010 6:02:19 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/12/2010 6:02:19 PM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/13/2010 1:55:48 AM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/13/2010 1:55:48 AM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/13/2010 2:49:59 AM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.

Error - 8/13/2010 2:49:59 AM | Computer Name = John-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OneTouch 4.


< End of report >

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Hi,

Please go Start>Run type regedit

Look under the following key:

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\INIFilemapping

If you see a value named autorun.inf, which has a value "@SYS: DoesNotExist" please delete it

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Hi,

No, it did not have that value.
It has "@SYS:Software\Swearware\dump"

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Hi,

Can you delete that value please?

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Hi Chris,

That value is deleted and the USB flash drive appears to be working correctly once again. Thank you so much for your help and I have purchased a quick tips book from this site to support your hard work!

Thanks again

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Hooray!

Any more issues I can help with?

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Nope! Big Grin

Everything is running swell again. Thanks for all your help. If I have any more issues, I'll be sure to contact you.

Thanks again

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
Beautiful Smile...

Congratulations!! Your PC is all clean! Big Grin
To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall

AntiVirus Popups - Page 1 Combofix_uninstall_image

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.


There are many things you can do to keep this from happening again. You can think of a computer like a car. It requires basic maintenance to keep in tip top shape and ready to go. Would you drive your car 100,000 miles without changing the oil? The same principle applies here.

Cleaning

Now that your PC is free of malware, it is important to clean up your PC. There are several good free cleaners available. You should make sure to clean up your temp files regularly, at least once a week.

ATF Cleaner
CCleaner

Defragmenting Your Hard Disk

Over time your PC can become fragmented, Windows comes with a defragmenting utility, however, it is very slow, and there are other options available.

To use the defragmenter included with Windows either go to Start/Run and type dfrg.msc, hit enter; or
right-click My Computer, choose Manage, Storage, Disk Defragmenter.

In the Defragmenter utility, select your main partition/HD, generally C:\ and select analyze . The analysis report will tell you whether or not your disk needs to be defragmented, if it does, click defragment. Be patient, this can take a long time.

Repeat for multiple partitions/hard disks.

System Restore Cleanup Instructions

If you are using Windows ME or XP then it is good to disable and re-enable system restore to make sure there are no infected files left in a restore point. (All restore points will be deleted that way)
You can find instructions on how to disable and re-enable system restore here:

Windows ME System Restore Guide

Windows XP System Restore Guide

Reading Tip:
Computer Health
Keep Your System Updated

Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Please ensure that you visit the following websites regularly or do update your system regularly.

Install the updates immediately, if they are found. Reboot your computer if necessary, revisit Windows Update and Office update sites until there are no more updates to be installed.

To update Windows and office

Go to Start > All Programs > Microsoft Update

Alternatively, you can visit the link below to update Windows and Office products.

Microsoft Update

If you are forgetful, you can change some settings so that you will be informed of updates. Here's how:

1. Go to Start > Control Panel > Automatic Updates
2. Select Automatic (recommended) radio button if you want the updates to be downloaded and installed without prompting you.
3. Select Download updates for me, but let me chose when to install them radio button if you want the updates to be downloaded automatically but to be installed at another time.4. Select Notify me but don't automatically download or install them radio button if you want to be notified of the updates.

Please make sure that you update your antivirus, firewall and anti-spyware programs at least once a week.

Be careful when opening attachments and downloading files.

1. Never open email attachments, not even if they are from someone you know. If you need to open them, scan them with your antivirus program before opening.
2. Never open emails from unknown senders.
3. Beware of emails that warn about viruses that are spreading, especially those from antivirus vendors. These are called hoaxes. The email addresses used in the hoaxes can be easily spoofed. Check the antivirus vendor websites to be sure.
4. Be careful of what you download. Only download files from known sources. Also, avoid cracked programs. If you need a particular program that costs too much for you, try finding free alternatives on Sourceforge or Pricelessware.

Surf safely

Many security exploits on websites are directed to users of Internet Explorer and Firefox.

If you use Firefox, try the No-script Add On - which, by default, disables all scripts on all websites. If you trust the website, you can manually allow scripts to work.

Backup regularly

You never know when your PC will become unstable or become so infected that you can't recover it. Follow this Microsoft Article to learn how to backup. Follow This Article by Microsoft to restore your backups.

Alternatively, you can use 3rd-party programs to back up your data. Examples of these can be found at
Bleeping Computer

Avoid P2P

I see you have P2P software installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

Prevent A Re-infection

1. Winpatrol

Winpatrol is a heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features Here

You can get a Free Copy of Winpatrol or use the Plus Version for more features.

You can read Win Patrol FAQ if you run into problems.

2. Hosts File

A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your PC will look up the website's IP address before you can view the website.

Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to 127.0.0.1.

Here are some Hosts files:
MVPS Hosts File
Blue Tack’s Hosts File
Blue Tack’s Hosts Manager

3. Spybot Search and Destroy

Spybot Search & Destroy is another program for scanning spyware and adware. You are strongly encouraged to run a scan at least once per week.

Spybot Search & Destroy can be downloaded from here.

If you need help in using Spybot Search & Destroy, you can read Spybot Search and Destroy tutorial at Bleeping Computer.

4. SiteHound Toolbar

SiteHound is a toolbar that warns you if you go to a site that is known to scam people, that has potentially lots of viruses or spyware or other questionable content. If you know the site, you can enter it; if you don't, it will bring you back to the previous page. Currently, SiteHound works for Internet Explorer and Firefox only.

====

Stand Up and Be Counted ---> Malware Complaints<--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
============================================================
See this page for more info about malware and prevention.
Thank you for choosing GeekPolice. Please see this page if you would like to leave feedback or contribute to our site.
Before the thread is archived, do you have any more questions?

Happy surfing and stay clean!

descriptionAntiVirus Popups - Page 1 EmptyRe: AntiVirus Popups

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum