Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: MS Removal tool popup,cannot open anything!  (Read 6248 times)

0 Members and 1 Guest are viewing this topic.

spardawg

    Topic Starter


    Rookie

    MS Removal tool popup,cannot open anything!
    « on: April 18, 2011, 09:58:08 AM »
    My computer suddenly had a box popup from MS Removal Tool stating I have TONS of infections/Malware! It is trying to force me to buy protection from them. I HAD Avg on this PC now it will not run. I cannot even CNTL/ALT/ Delete..it tells me EVERYTHING I try is "infected"! What happened???? I tried to download some of the suggested malware apps but it tells me THEY are infected.
    Thank you!

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: MS Removal tool popup,cannot open anything!
    « Reply #1 on: April 18, 2011, 04:58:20 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    ******************************************************
    Please do this in this order. Boot in Safe Mode with NetWorking, download and run MBAM. Next, re-boot in Normal Mode and run MBAM again as well as SAS and DDS below and copy and paste the logs.

    Safe Mode
    **************************************************
    Please download Malwarebytes Anti-Malware from here.
    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
    ***********************************************
    SUPERAntiSpyware

    If you already have SUPERAntiSpyware be sure to check for updates before scanning!


    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to Update the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose Perform Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log somewhere you can easily find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post.
    ***************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.
    Windows 8 and Windows 10 dual boot with two SSD's

    spardawg

      Topic Starter


      Rookie

      Re: MS Removal tool popup,cannot open anything!
      « Reply #2 on: April 19, 2011, 01:56:16 PM »
      I am unable to open in Safe Mode...as the computer is restarting, I hit F8 and nothing happens. The screen stays black....any other thoughts on how to get there?
      Thanks

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: MS Removal tool popup,cannot open anything!
      « Reply #3 on: April 20, 2011, 01:36:02 PM »
      If you can boot in Normal Mode please download MBAM and SAS using one of the methods I described in my original post and transfer the programs to your computer and try running them. Run MBAM first.
      Windows 8 and Windows 10 dual boot with two SSD's

      spardawg

        Topic Starter


        Rookie

        Re: MS Removal tool popup,cannot open anything!
        « Reply #4 on: April 22, 2011, 09:19:56 AM »
        Here are my logs:

        Malwarebytes' Anti-Malware 1.50.1.1100
        www.malwarebytes.org

        Database version: 6407

        Windows 5.1.2600 Service Pack 2
        Internet Explorer 8.0.6001.18702

        4/21/2011 7:57:15 AM
        mbam-log-2011-04-21 (07-57-15).txt

        Scan type: Full scan (C:\|D:\|)
        Objects scanned: 401350
        Time elapsed: 9 hour(s), 27 minute(s), 49 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 5
        Registry Values Infected: 1
        Registry Data Items Infected: 2
        Folders Infected: 33
        Files Infected: 59

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_CLASSES_ROOT\CLSID\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\FunWebProductsInstaller.Start.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\FunWebProductsInstaller.Start (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

        Registry Values Infected:
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSE (Rogue.MySecurityEngine) -> Value: MSE -> Quarantined and deleted successfully.

        Registry Data Items Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Folders Infected:
        c:\documents and settings\all users\application data\Starware (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\contexts (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\browsersearch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\errorsearch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Games (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Layouts (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Manager (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\popupblocker (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\reference (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\relatedsearch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensavers (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensaversmarketingsitepager (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchassistplus (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchmatch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Toolbar (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarlogo (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarsearch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\travelsearch (Adware.Starware) -> Quarantined and deleted successfully.
        c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\program files\funwebproducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\program files\funwebproducts\Installr\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\installer (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\installer\bin (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst\bin (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst\Ready (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst\temp (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst\Upload (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\wallpaper (Adware.Comet) -> Quarantined and deleted successfully.

        Files Infected:
        c:\program files\funwebproducts\Installr\1.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\cdp24500dnpcm24500\cdp24500dnpcm24500.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        c:\documents and settings\compaq_owner.your-f78bf48ce2.000\Desktop\ccleaner.exe (Adware.Hotbar.Gen) -> Quarantined and deleted successfully.
        c:\documents and settings\compaq_owner.your-f78bf48ce2.000\local settings\Temp\packupdate_build107_241[1].exe (Rogue.Agent.Gen) -> Quarantined and deleted successfully.
        c:\documents and settings\compaq_owner.your-f78bf48ce2.000\local settings\temporary internet files\Content.IE5\JNTOYWUS\pcfix-v303-en[1].exe (Adware.PCFixCleaner) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\cursorcafe.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\cursorcafea.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\games.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\gamesA.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\screensaver.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\buttons\screensavera.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\contexts\travel.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\productmessagingconfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\productmessagingconfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\simpleupdateconfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\simpleupdateconfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\timermanagerconfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\all users\application data\Starware\simpleupdate\timermanagerconfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\browsersearch\browsersearch.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\browsersearch\browsersearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\errorsearch\errorsearchoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\errorsearch\errorsearchoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Games\gamesoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Games\gamesoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Layouts\preferenceslayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Layouts\preferenceslayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Layouts\toolbarlayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Layouts\toolbarlayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Manager\manageroptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Manager\manageroptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\popupblocker\popupblockeroptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\popupblocker\popupblockeroptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\reference\referenceoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\reference\referenceoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\relatedsearch\relatedsearchoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\relatedsearch\relatedsearchoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensavers\screensaversoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensavers\screensaversoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensaversmarketingsitepager\screensaversmarketingsitepageroptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\screensaversmarketingsitepager\screensaversmarketingsitepageroptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchassistplus\searchassistplusoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchassistplus\searchassistplusoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchmatch\searchmatchoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\searchmatch\searchmatchoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Toolbar\tbproductsoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\Toolbar\tbproductsoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarlogo\toolbarlogooptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarlogo\toolbarlogooptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarsearch\toolbarsearchoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\toolbarsearch\toolbarsearchoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\travelsearch\travelsearchoptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        c:\documents and settings\localservice\application data\Starware\travelsearch\travelsearchoptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        c:\program files\funwebproducts\Installr\1.bin\F3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\program files\funwebproducts\Installr\1.bin\NPFUNWEB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\SSSInst\bin\sssuninst.exe (Adware.Comet) -> Quarantined and deleted successfully.
        c:\program files\screensavers.com\wallpaper\perfect leaf.jpg (Adware.Comet) -> Quarantined and deleted successfully.



        SUPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 04/21/2011 at 11:51 AM

        Application Version : 4.50.1002

        Core Rules Database Version : 6885
        Trace Rules Database Version: 4697

        Scan type       : Quick Scan
        Total Scan Time : 01:07:46

        Memory items scanned      : 450
        Memory threats detected   : 0
        Registry items scanned    : 1683
        Registry threats detected : 0
        File items scanned        : 14715
        File threats detected     : 396

        Adware.Tracking Cookie
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@statcounter[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adecn[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@legolas-media[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@insightexpressai[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@imrworldwide[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@serving-sys[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@pointroll[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@invitemedia[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@fastclick[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@kanoodle[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@yieldmanager[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@trafficmp[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adviva[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@a2zwordfinder[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][6].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@2o7[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@pro-market[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@yieldmanager[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@realmedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@media6degrees[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@ru4[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@eliteskills[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@apmebf[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@atwola[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@smartadserver[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@tribalfusion[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@revsci[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@media6degrees[4].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@questionmarket[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@specificmedia[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@casalemedia[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@atdmt[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@collective-media[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@douglascountylibraries[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@lfstmedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@tacoda[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@overture[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@dmtracker[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@247realmedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@advertise[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@zedo[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@doubleclick[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@mediaplex[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@hookedmediagroup[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@douglascountyschools[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@teennick[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@specificclick[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@eyewonder[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@interclick[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@liveperson[6].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adlegend[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@advertising[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adecn[4].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adbrite[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@burstbeacon[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@nextag[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@liveperson[7].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adtech[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@fbannersusers[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@mediabrandsww[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@roiservice[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adinterax[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@adxpose[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@kontera[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@burstnet[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@ticketsnow[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@tourtracker[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@tns-counter[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][6].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@realmedia[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@andomedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@azjmp[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@liveperson[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@liveperson[5].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@mmstat[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@lucidmedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@fbanners[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@specificmedia[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@edgeadx[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@yadro[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@revenue[3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\compaq_owner@tradedoubler[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Cookies\[email protected][1].txt
           2mdn.net [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           adbureau.net [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           adx.starbanner.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           bannerfarm.ace.advertising.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           cdn.euroclick.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           cdn4.specificclick.net [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           content.oddcast.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           core.insightexpressai.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           enhance.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           files.adbrite.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           host-d.oddcast.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           interclick.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           m1.2mdn.net [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.jambocast.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.katu.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.mtvnservices.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.resulthost.org [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.scanscout.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.subwayfreshbuzz.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.tattomedia.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.thewb.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media.vmixcore.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media01.kyte.tv [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           media1.clubpenguin.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           msnbcmedia.msn.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           objects.tremormedia.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           oddcast.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           pointroll.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           serving-sys.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           spe.atdmt.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           speed.pointroll.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           static.sexsearch.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           traffic.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           udn.specificclick.net [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           www.blogsmithmedia.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           yo.static.presidiomedia.com [ C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Flash Player\#SharedObjects\Z38D9Z2R ]
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@chitika[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@dmtracker[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@interclick[3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@collective-media[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@burstnet[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@specificclick[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adbrite[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@questionmarket[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@interclick[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@tribalfusion[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@tacoda[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@serving-sys[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@revsci[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@roiservice[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][5].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@mediaplex[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@bizrate[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@eyewonder[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][5].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][5].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@imrworldwide[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@247realmedia[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@advertising[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@realmedia[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@doubleclick[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atdmt[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@zedo[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@azjmp[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@xiti[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@fastclick[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@specificmedia[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@apmebf[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@media6degrees[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@statcounter[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@lfstmedia[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@apmebf[3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@apmebf[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@insightexpressai[3].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atwola[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@a2zwordfinder[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atwola[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@invitemedia[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@invitemedia[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@kontera[2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@linksynergy[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@pointroll[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@optimost[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@casalemedia[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@2o7[1].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][4].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@insightexpressai[2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@specificclick[2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@specificmedia[1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@statcounter[1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@atwola[1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@kontera[2].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
           adimages.scrippsnetworks.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Macromedia\Flash Player\#SharedObjects\TUC5HV3R ]
           bannerfarm.ace.advertising.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Macromedia\Flash Player\#SharedObjects\TUC5HV3R ]
           interclick.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Macromedia\Flash Player\#SharedObjects\TUC5HV3R ]
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@chitika[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@dmtracker[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@collective-media[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@superstats[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@interclick[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@nextag[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@countrydoor[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@findarticles[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@imrworldwide[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@specificmedia[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@adecn[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@azjmp[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@xiti[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@lynxtrack[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@media6degrees[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@atwola[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@b5media[1].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\compaq_owner@media303[2].txt
           C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Cookies\[email protected][1].txt
           90degreemedia.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           a.ads2.msads.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           ads2.msads.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           b.ads2.msads.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           cdn4.specificclick.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           core.insightexpressai.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           ia.media-imdb.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           macromedia.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           media.kyte.tv [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           media.mtvnservices.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           media.scanscout.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           s0.2mdn.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           secure-us.imrworldwide.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           udn.specificclick.net [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]
           vidego-http.multicastmedia.com [ C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2.000\Application Data\Macromedia\Flash Player\#SharedObjects\6TSJ7VZA ]

        Trojan.Agent/Gen-FakeAlert[Local]
           C:\DOCUMENTS AND SETTINGS\COMPAQ_OWNER\LOCAL SETTINGS\APPLICATION DATA\WILDTANGENT\CDACACHE\7729BD8F-00A4-4249-8436-3626BA58E18E\TRADEWINDS.EXE

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: MS Removal tool popup,cannot open anything!
        « Reply #5 on: April 22, 2011, 09:58:22 AM »
        Ok. Let's see if you can run these scans.

        Download DDS from HERE or HERE and save it to your desktop.

        Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

        * XP users Double click on dds to run it.
        * If your antivirus or firewall try to block DDS then please allow it to run.
        * When finished DDS will open two (2) logs.

        1) DDS.txt
        2) Attach.txt

        * Save both logs to your desktop.
        * Please copy and paste the entire contents of both logs in your next reply.

        Note: DDS will instruct you to post the Attach.txt log as an attachment.
        Please just post it as you would any other log by copy and pasting it into the reply.
        ***********************************************************
        Download Security Check by screen317 from one of the following links and save it to your desktop.

        Link 1
        Link 2

        * Unzip SecurityCheck.zip and a folder named Security Check should appear.
        * Open the Security Check folder and double-click Security Check.bat
        * Follow the on-screen instructions inside of the black box.
        * A Notepad document should open automatically called checkup.txt
        * Post the contents of that document in your next reply.

        Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
        Windows 8 and Windows 10 dual boot with two SSD's

        spardawg

          Topic Starter


          Rookie

          Re: MS Removal tool popup,cannot open anything!
          « Reply #6 on: April 23, 2011, 10:36:22 AM »
          dds:

          AV: AVG Internet Security 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
          FW: AVG Firewall *Enabled*
          .
          ============== Running Processes ===============
          .
          C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
          C:\WINDOWS\system32\svchost -k DcomLaunch
          svchost.exe
          C:\WINDOWS\System32\svchost.exe -k netsvcs
          svchost.exe
          svchost.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\LEXPPS.EXE
          svchost.exe
          C:\Program Files\AVG\AVG10\avgfws.exe
          C:\Program Files\AVG\AVG10\avgwdsvc.exe
          C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
          C:\WINDOWS\system32\svchost.exe -k HPService
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\System32\svchost.exe -k HPZ12
          C:\WINDOWS\System32\svchost.exe -k HPZ12
          C:\WINDOWS\system32\svchost.exe -k imgsvc
          C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\AVG\AVG10\avgam.exe
          C:\Program Files\AVG\AVG10\avgnsx.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\RunDLL32.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\AVG\AVG10\avgtray.exe
          C:\Program Files\Gamesbar\SearchEngineProtection.exe
          C:\Program Files\Creative\Shared Files\CamTray.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\AVG\AVG10\avgcsrvx.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
          C:\Program Files\Common Files\Java\Java Update\jucheck.exe
          C:\PROGRA~1\AVG\AVG10\avgrsx.exe
          C:\Program Files\AVG\AVG10\avgcsrvx.exe
          C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          K:\dds.pif
          .
          ============== Pseudo HJT Report ===============
          .
          uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
          uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
          uStart Page = hxxp://www.aol.com/
          uInternet Connection Wizard,ShellNext = iexplore
          uSearchURL,(Default) = hxxp://search.alot.com/web?q=&pr=auto&client_id=CF92159001CA987A00ACD934&src_id=11009&camp_id=861&tb_version=2.5.7002.477
          mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
          uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
          uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
          mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
          BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
          BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
          BHO: ALOT Toolbar Helper: {14ceeaff-96dd-4101-ae37-d5ecdc23c3f6} - c:\program files\alot\bin\bho\alotBHO.dll
          BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
          BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
          BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
          BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
          BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
          BHO: GamesBarBHO Class: {cb0d163c-e9f4-4236-9496-0597e24b23a5} - c:\program files\gamesbar\2.0.1.59\oberontb.dll
          BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
          BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
          BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
          TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
          TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
          TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
          TB: GamesBar: {6f282b65-56bf-4bd1-a8b2-a4449a05863d} - c:\program files\gamesbar\2.0.1.59\oberontb.dll
          TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
          TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
          EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
          uRun: [SearchEngineProtection] c:\program files\gamesbar\SearchEngineProtection.exe
          uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
          uRun: [Yahoo! Pager] c:\progra~1\yahoo!\messen~1\ypager.exe -quiet
          uRun: [Creative WebCam Tray] "c:\program files\creative\shared files\CamTray.exe"
          uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
          mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
          mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
          mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
          mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
          mRun: [iTunesHelper] c:\program files\itunes\iTunesHelper.exe
          mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
          mRun: [PD0630 STISvc] RunDLL32.exe P0630Pin.dll,RunDLL32EP 513
          mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
          mRun: [PCFix] c:\program files\pcfix\PCFix.exe
          mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
          StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
          IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
          IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
          IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\progra~1\yahoo!\messen~1\YPager.exe
          IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
          IE: {1A93C934-025B-4c3a-B38E-9654A7003239} - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - c:\program files\gamesbar\2.0.1.59\oberontb.dll
          IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
          IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
          IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
          DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1289850532296
          DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
          DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
          DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
          DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
          DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
          Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
          Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
          SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
          .
          ============= SERVICES / DRIVERS ===============
          .
          R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
          R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
          R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
          R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
          R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
          R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
          R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2011-2-8 2707512]
          R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-2-15 7421280]
          R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
          R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]
          R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
          R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
          R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
          S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
          S2 SAVRTPEL;SAVRTPEL;\??\c:\program files\norton internet security\norton antivirus\savrtpel.sys --> c:\program files\norton internet security\norton antivirus\SAVRTPEL.SYS [?]
          S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-20 947528]
          S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]
          S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20050309.032\NAVENG.Sys [2005-5-10 73728]
          S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20050309.032\NavEx15.Sys [2005-5-10 631040]
          S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [2011-2-11 91841]
          S3 SAVRT;SAVRT;\??\c:\program files\norton internet security\norton antivirus\savrt.sys --> c:\program files\norton internet security\norton antivirus\SAVRT.SYS [?]
          .
          =============== Created Last 30 ================
          .
          2011-04-21 15:42:58   --------   d-----w-   c:\docume~1\compaq~1.000\applic~1\SUPERAntiSpyware.com
          2011-04-21 15:42:58   --------   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
          2011-04-21 15:41:05   --------   d-----w-   c:\program files\SUPERAntiSpyware
          2011-04-20 20:17:56   --------   d-----w-   c:\docume~1\compaq~1.000\applic~1\Malwarebytes
          2011-04-20 20:17:46   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
          2011-04-20 20:17:44   --------   d-----w-   c:\docume~1\alluse~1\applic~1\Malwarebytes
          2011-04-20 20:17:40   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
          2011-04-20 20:17:39   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
          2011-04-20 19:27:07   --------   d-----w-   c:\docume~1\compaq~1.000\applic~1\AVG10
          2011-04-20 19:25:03   --------   d--h--w-   c:\docume~1\alluse~1\applic~1\Common Files
          2011-04-20 19:20:40   --------   d-----w-   c:\windows\system32\drivers\AVG
          2011-04-20 19:20:40   --------   d-----w-   c:\docume~1\alluse~1\applic~1\AVG10
          2011-04-20 19:13:36   --------   d-----w-   c:\docume~1\alluse~1\applic~1\MFAData
          2011-04-20 18:25:41   --------   d-----w-   c:\docume~1\compaq~1.000\applic~1\PCFix
          2011-04-20 18:25:33   --------   d-----w-   c:\program files\PCFix
          2011-04-16 23:48:56   --------   d-----w-   c:\docume~1\alluse~1\applic~1\cDp24500dNpCm24500
          2011-04-14 09:39:02   103864   ----a-w-   c:\program files\internet explorer\plugins\nppdf32.dll
          2011-04-14 02:27:57   --------   d-----w-   c:\docume~1\compaq~1.000\applic~1\Wal-Mart
          2011-03-30 23:17:22   134480   ----a-w-   c:\windows\system32\drivers\AVGIDSDriver.sys
          .
          ==================== Find3M  ====================
          .
          2011-03-05 23:51:05   398760   ----a-r-   c:\windows\cpnprt2.cid
          2011-03-05 23:51:03   398760   ------w-   c:\windows\system32\cpnprt2.cid
          2010-11-15 00:26:08   441   ----a-w-   c:\program files\1114201017260871.bat
          2004-08-10 03:30:22   40960   -c--a-w-   c:\program files\Uninstall_CDS.exe
          2002-08-15 16:54:38   3198976   -c--a-w-   c:\program files\ViewSonicregistration.exe
          .
          ============= FINISH:  9:24:43.78 ===============



          DDS (Ver_11-03-05.01)
          .
          Microsoft Windows XP Home Edition
          Boot Device: \Device\HarddiskVolume2
          Install Date: 12/21/2009 12:57:41 PM
          System Uptime: 4/21/2011 1:00:53 PM (44 hours ago)
          .
          Motherboard: ASUSTek Computer INC. |  | Salmon
          Processor: AMD Athlon(tm) 64 Processor 3400+ | Socket 754 | 2411/200mhz
          .
          ==== Disk Partitions =========================
          .
          C: is FIXED (NTFS) - 180 GiB total, 131.849 GiB free.
          D: is FIXED (FAT32) - 6 GiB total, 0.977 GiB free.
          E: is CDROM ()
          F: is CDROM ()
          G: is Removable
          H: is Removable
          I: is Removable
          J: is Removable
          K: is Removable
          .
          ==== Disabled Device Manager Items =============
          .
          ==== System Restore Points ===================
          .
          RP232: 1/23/2011 2:10:57 PM - Installed Java(TM) 6 Update 23
          RP233: 1/24/2011 2:19:01 PM - System Checkpoint
          RP234: 1/25/2011 3:19:06 PM - System Checkpoint
          RP235: 1/26/2011 4:18:59 PM - System Checkpoint
          RP236: 1/27/2011 5:18:59 PM - System Checkpoint
          RP237: 1/30/2011 8:23:51 PM - System Checkpoint
          RP238: 1/31/2011 9:00:32 PM - System Checkpoint
          RP239: 2/1/2011 10:00:31 PM - System Checkpoint
          RP240: 2/2/2011 11:00:31 PM - System Checkpoint
          RP241: 2/4/2011 12:00:32 AM - System Checkpoint
          RP242: 2/5/2011 5:44:36 PM - System Checkpoint
          RP243: 2/6/2011 6:43:32 PM - System Checkpoint
          RP244: 2/7/2011 6:44:37 PM - System Checkpoint
          RP245: 2/8/2011 7:27:32 PM - System Checkpoint
          RP246: 2/9/2011 3:00:19 AM - Software Distribution Service 3.0
          RP247: 2/10/2011 3:27:39 AM - System Checkpoint
          RP248: 2/11/2011 4:27:31 AM - System Checkpoint
          RP249: 2/11/2011 5:55:02 PM - Installed Engine Installer
          RP250: 2/11/2011 5:55:22 PM - Installed Creative WebCam Center
          RP251: 2/11/2011 5:55:55 PM - Installed Advanced Video FX Utility
          RP252: 2/11/2011 5:56:10 PM - Installed Creative WebCam Features
          RP253: 2/11/2011 5:56:24 PM - Installed Creative Photo Manager
          RP254: 2/11/2011 5:57:20 PM - Installed Get Yahoo! Messenger
          RP255: 2/11/2011 6:02:39 PM - Installed Creative WebCam Live!
          RP256: 2/11/2011 6:03:14 PM - Installed Windows Media Player 10
          RP257: 2/11/2011 6:07:04 PM - Installed Creative WebCam NX
          RP258: 2/11/2011 6:08:15 PM - Installed WebCam Live! Product Registration
          RP259: 2/12/2011 6:22:30 PM - System Checkpoint
          RP260: 2/13/2011 3:00:19 AM - Software Distribution Service 3.0
          RP261: 2/14/2011 3:22:24 AM - System Checkpoint
          RP262: 2/15/2011 4:22:24 AM - System Checkpoint
          RP263: 2/16/2011 5:22:24 AM - System Checkpoint
          RP264: 2/17/2011 6:22:24 AM - System Checkpoint
          RP265: 2/18/2011 7:22:24 AM - System Checkpoint
          RP266: 2/19/2011 8:22:24 AM - System Checkpoint
          RP267: 2/20/2011 8:22:37 AM - System Checkpoint
          RP268: 2/21/2011 9:22:36 AM - System Checkpoint
          RP269: 2/22/2011 10:22:36 AM - System Checkpoint
          RP270: 2/23/2011 11:22:36 AM - System Checkpoint
          RP271: 2/27/2011 5:07:22 PM - System Checkpoint
          RP272: 2/28/2011 5:10:00 PM - System Checkpoint
          RP273: 3/1/2011 6:13:56 PM - System Checkpoint
          RP274: 3/2/2011 7:10:00 PM - System Checkpoint
          RP275: 3/3/2011 8:23:02 PM - System Checkpoint
          RP276: 3/4/2011 10:07:18 PM - System Checkpoint
          RP277: 3/5/2011 10:21:46 PM - System Checkpoint
          RP278: 3/7/2011 1:31:33 PM - System Checkpoint
          RP279: 3/8/2011 1:41:01 PM - System Checkpoint
          RP280: 3/9/2011 2:41:01 PM - System Checkpoint
          RP281: 3/10/2011 3:00:20 AM - Software Distribution Service 3.0
          RP282: 3/11/2011 3:41:01 AM - System Checkpoint
          RP283: 3/12/2011 4:41:01 AM - System Checkpoint
          RP284: 3/13/2011 6:41:01 AM - System Checkpoint
          RP285: 3/13/2011 3:25:54 PM - Printer Driver HP Officejet 4500 G510n-z fax Installed
          RP286: 3/14/2011 3:41:44 PM - System Checkpoint
          RP287: 3/15/2011 3:43:27 PM - System Checkpoint
          RP288: 3/16/2011 4:43:26 PM - System Checkpoint
          RP289: 3/17/2011 5:43:27 PM - System Checkpoint
          RP290: 3/18/2011 6:43:27 PM - System Checkpoint
          RP291: 4/7/2011 11:29:28 AM - System Checkpoint
          RP292: 4/8/2011 11:54:39 AM - System Checkpoint
          RP293: 4/9/2011 11:55:55 AM - System Checkpoint
          RP294: 4/10/2011 1:08:09 PM - System Checkpoint
          RP295: 4/11/2011 1:54:39 PM - System Checkpoint
          RP296: 4/12/2011 2:54:39 PM - System Checkpoint
          RP297: 4/13/2011 3:54:50 PM - System Checkpoint
          RP298: 4/14/2011 4:54:52 PM - System Checkpoint
          RP299: 4/15/2011 3:01:30 AM - Software Distribution Service 3.0
          RP300: 4/16/2011 3:54:40 AM - System Checkpoint
          RP301: 4/17/2011 1:18:14 PM - System Checkpoint
          RP302: 4/18/2011 2:50:10 PM - System Checkpoint
          RP303: 4/19/2011 3:16:48 PM - System Checkpoint
          RP304: 4/20/2011 1:18:56 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
          RP305: 4/20/2011 1:19:15 PM - Installed AVG 2011
          RP306: 4/20/2011 1:20:15 PM - Installed AVG 2011
          RP307: 4/21/2011 1:38:47 PM - System Checkpoint
          RP308: 4/22/2011 2:07:18 PM - System Checkpoint
          .
          ==== Installed Programs ======================
          .
          32 Bit HP CIO Components Installer
          4500_G510nz_Help
          4500G510nz
          4500G510nz_Software_Min
          Adobe AIR
          Adobe Flash Player 10 ActiveX
          Adobe Reader 9.4.4
          Advanced Video FX Utility
          ALOT Toolbar
          AVG 2011
          Big Fish Games: Game Manager
          Blackhawk Striker 2 from Compaq (remove only)
          Blasterball 2 from Compaq (remove only)
          Blasterball 2 Holidays from Compaq (remove only)
          Blasterball 2 Remix from Compaq (remove only)
          Bounce Symphony from Compaq (remove only)
          BufferChm
          Compaq Connections
          Compaq Organize
          Compatibility Pack for the 2007 Office system
          Coupon Printer for Windows
          Creative Photo Manager
          Creative WebCam Center
          Creative WebCam Live! Driver (1.02.03.0606)
          Creative WebCam Live! User's Guide (English)
          Crystal Maze from Compaq (remove only)
          Destinations
          DeviceDiscovery
          DocMgr
          DocProc
          Easy Internet Sign-up
          Escape Whisper Valley
          Fax
          Final Drive Nitro from Compaq (remove only)
          GamesBar 2.0.1.59
          Get Yahoo! Messenger
          Google Toolbar for Internet Explorer
          GPBaseService2
          Help and Support Additions
          Hidden Mysteries Titanic
          Hotfix for Windows XP (KB952287)
          Hotfix for Windows XP (KB976098-v2)
          Hotfix for Windows XP (KB979306)
          Hotfix for Windows XP (KB981793)
          HP Boot Optimizer
          HP Customer Participation Program 13.0
          HP Document Manager 2.0
          HP Help and Support 4.0
          HP Imaging Device Functions 13.0
          HP Officejet 4500 G510n-z
          HP Product Detection
          HP Smart Web Printing 4.5
          HP Solution Center 13.0
          HP Update
          HPProductAssistant
          HpSdpAppCoreApp
          HPSSupply
          InterVideo WinDVD Player
          iTunes
          Java Auto Updater
          Java(TM) 6 Update 23
          KBD
          Lexibox Deluxe from Compaq (remove only)
          Lexmark X6100 Series
          LiveReg (Symantec Corporation)
          Malwarebytes' Anti-Malware
          MarketResearch
          Microsoft .NET Framework 1.1
          Microsoft .NET Framework 1.1 Security Update (KB979906)
          Microsoft Office 2007 Service Pack 2 (SP2)
          Microsoft Office Excel MUI (English) 2007
          Microsoft Office Home and Student 2007
          Microsoft Office OneNote MUI (English) 2007
          Microsoft Office PowerPoint MUI (English) 2007
          Microsoft Office Proof (English) 2007
          Microsoft Office Proof (French) 2007
          Microsoft Office Proof (Spanish) 2007
          Microsoft Office Proofing (English) 2007
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
          Microsoft Office Shared MUI (English) 2007
          Microsoft Office Shared Setup Metadata MUI (English) 2007
          Microsoft Office Standard Edition 2003
          Microsoft Office Word MUI (English) 2007
          Microsoft Office XP Standard for Students and Teachers
          Microsoft Plus! Dancer LE
          Microsoft Plus! Digital Media Edition Installer
          Microsoft Plus! Photo Story 2 LE
          Microsoft Software Update for Web Folders  (English) 12
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
          Microsoft Works
          Motorola SM56 Speakerphone Modem
          MSXML 4.0 SP2 (KB954430)
          MSXML 4.0 SP2 (KB973688)
          Network
          Norton AntiVirus 2005
          Norton Internet Security
          OCR Software by I.R.I.S. 13.0
          Overball from Compaq (remove only)
          PCFix
          Phoenix Assault from Compaq (remove only)
          Polar Bowler from Compaq (remove only)
          Polar Golfer from Compaq (remove only)
          PS2
          Python 2.2 pywin32 extensions (build 203)
          Python 2.2.3
          QuickTime
          RealPlayer
          Remove Adobe Photoshop Album 2.0 Starter Edition installer
          Remove Microsoft Money 2005 installer
          Remove Quicken New User Edition installer
          Remove WeatherBug installer
          Scan
          Security Update for 2007 Microsoft Office System (KB2288621)
          Security Update for 2007 Microsoft Office System (KB2288931)
          Security Update for 2007 Microsoft Office System (KB2345043)
          Security Update for 2007 Microsoft Office System (KB2466156)
          Security Update for 2007 Microsoft Office System (KB2509488)
          Security Update for 2007 Microsoft Office System (KB969559)
          Security Update for 2007 Microsoft Office System (KB976321)
          Security Update for CAPICOM (KB931906)
          Security Update for Microsoft Office Excel 2007 (KB2464583)
          Security Update for Microsoft Office InfoPath 2007 (KB979441)
          Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
          Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
          Security Update for Microsoft Office system 2007 (972581)
          Security Update for Microsoft Office system 2007 (KB974234)
          Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
          Security Update for Microsoft Office Word 2007 (KB2344993)
          Security Update for Step By Step Interactive Training (KB923723)
          Security Update for Windows Internet Explorer 8 (KB971961)
          Security Update for Windows Internet Explorer 8 (KB976325)
          Security Update for Windows Internet Explorer 8 (KB978207)
          Security Update for Windows Internet Explorer 8 (KB981332)
          Security Update for Windows Internet Explorer 8 (KB982381)
          Security Update for Windows Media Player (KB952069)
          Security Update for Windows Media Player (KB954155)
          Security Update for Windows Media Player (KB968816)
          Security Update for Windows Media Player (KB973540)
          Security Update for Windows Media Player (KB978695)
          Security Update for Windows XP (KB2229593)
          Security Update for Windows XP (KB923561)
          Security Update for Windows XP (KB941569)
          Security Update for Windows XP (KB944338-v2)
          Security Update for Windows XP (KB946648)
          Security Update for Windows XP (KB950762)
          Security Update for Windows XP (KB950974)
          Security Update for Windows XP (KB951376-v2)
          Security Update for Windows XP (KB951748)
          Security Update for Windows XP (KB952004)
          Security Update for Windows XP (KB952954)
          Security Update for Windows XP (KB955069)
          Security Update for Windows XP (KB956572)
          Security Update for Windows XP (KB956802)
          Security Update for Windows XP (KB956803)
          Security Update for Windows XP (KB956844)
          Security Update for Windows XP (KB957097)
          Security Update for Windows XP (KB958470)
          Security Update for Windows XP (KB958644)
          Security Update for Windows XP (KB958687)
          Security Update for Windows XP (KB958869)
          Security Update for Windows XP (KB959426)
          Security Update for Windows XP (KB960803)
          Security Update for Windows XP (KB960859)
          Security Update for Windows XP (KB961371-v2)
          Security Update for Windows XP (KB961501)
          Security Update for Windows XP (KB969059)
          Security Update for Windows XP (KB969947)
          Security Update for Windows XP (KB970238)
          Security Update for Windows XP (KB970430)
          Security Update for Windows XP (KB971468)
          Security Update for Windows XP (KB971486)
          Security Update for Windows XP (KB971557)
          Security Update for Windows XP (KB971633)
          Security Update for Windows XP (KB971657)
          Security Update for Windows XP (KB971961)
          Security Update for Windows XP (KB972270)
          Security Update for Windows XP (KB973507)
          Security Update for Windows XP (KB973525)
          Security Update for Windows XP (KB973869)
          Security Update for Windows XP (KB974112)
          Security Update for Windows XP (KB974318)
          Security Update for Windows XP (KB974571)
          Security Update for Windows XP (KB975025)
          Security Update for Windows XP (KB975467)
          Security Update for Windows XP (KB975560)
          Security Update for Windows XP (KB975561)
          Security Update for Windows XP (KB975562)
          Security Update for Windows XP (KB975713)
          Security Update for Windows XP (KB976325)
          Security Update for Windows XP (KB977165)
          Security Update for Windows XP (KB977816)
          Security Update for Windows XP (KB977914)
          Security Update for Windows XP (KB978037)
          Security Update for Windows XP (KB978251)
          Security Update for Windows XP (KB978262)
          Security Update for Windows XP (KB978338)
          Security Update for Windows XP (KB978542)
          Security Update for Windows XP (KB978601)
          Security Update for Windows XP (KB978706)
          Security Update for Windows XP (KB979309)
          Security Update for Windows XP (KB979482)
          Security Update for Windows XP (KB979559)
          Security Update for Windows XP (KB979683)
          Security Update for Windows XP (KB980195)
          Security Update for Windows XP (KB980218)
          Security Update for Windows XP (KB980232)
          Shooting Stars Pool from Compaq (remove only)
          Shop for HP Supplies
          SightSpeed
          SiS VGA Utilities
          Slyder from Compaq (remove only)
          SmartWebPrinting
          SolutionCenter
          Sonic Express Labeler
          Sonic MyDVD Plus
          Sonic RecordNow Audio
          Sonic RecordNow Copy
          Sonic RecordNow Data
          Sonic Update Manager
          Status
          Super Granny from Compaq (remove only)
          SUPERAntiSpyware
          Toolbox
          Tradewinds from Compaq (remove only)
          TrayApp
          Update for 2007 Microsoft Office System (KB967642)
          Update for Microsoft Office OneNote 2007 (KB980729)
          Update for Windows Internet Explorer 8 (KB975364)
          Update for Windows Internet Explorer 8 (KB976662)
          Update for Windows XP (KB898461)
          Update for Windows XP (KB955759)
          Update for Windows XP (KB967715)
          Update for Windows XP (KB968389)
          Update for Windows XP (KB971737)
          Update for Windows XP (KB973687)
          Update for Windows XP (KB973815)
          WebCam Live! Product Registration
          WebFldrs XP
          WebReg
          Windows Genuine Advantage Validation Tool (KB892130)
          Windows Installer 3.1 (KB893803)
          Windows Internet Explorer 8
          Windows Media Format Runtime
          Windows Media Player 10
          Windows XP Hotfix - KB867282
          Windows XP Hotfix - KB873339
          Windows XP Hotfix - KB883667
          Windows XP Hotfix - KB885250
          Windows XP Hotfix - KB885835
          Windows XP Hotfix - KB885836
          Windows XP Hotfix - KB885884
          Windows XP Hotfix - KB887472
          Windows XP Hotfix - KB887742
          Windows XP Hotfix - KB888113
          Windows XP Hotfix - KB888239
          Windows XP Hotfix - KB890175
          Windows XP Hotfix - KB891781
          Yahoo! Messenger
          Yahoo! Toolbar
          .
          ==== Event Viewer Messages From Past Week ========
          .
          4/22/2011 9:07:57 AM, information: Windows File Protection [64002]  - File replacement was attempted on the protected system file c:\windows\system32\wiafbdrv.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.0.
          4/22/2011 9:01:46 AM, error: Service Control Manager [7000]  - The SASDIFSV service failed to start due to the following error:  Cannot create a file when that file already exists.
          4/21/2011 8:13:22 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  fasttx2k
          4/21/2011 1:05:25 PM, error: System Error [1003]  - Error code 000000f4, parameter1 00000003, parameter2 84a3e3e0, parameter3 84a3e554, parameter4 805c77d0.
          4/20/2011 1:31:18 PM, error: Service Control Manager [7034]  - The AVG WatchDog service terminated unexpectedly.  It has done this 2 time(s).
          4/20/2011 1:31:15 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the AVG Firewall service to connect.
          4/20/2011 1:31:15 PM, error: Service Control Manager [7000]  - The AVG Firewall service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
          4/20/2011 1:31:14 PM, error: Service Control Manager [7034]  - The AVG Firewall service terminated unexpectedly.  It has done this 1 time(s).
          4/20/2011 1:31:14 PM, error: Service Control Manager [7031]  - The AVG WatchDog service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
          4/20/2011 1:31:10 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the AVGIDSAgent service to connect.
          4/20/2011 1:31:10 PM, error: Service Control Manager [7000]  - The AVGIDSAgent service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
          4/19/2011 9:39:22 AM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
          4/19/2011 9:39:22 AM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service iPodService with arguments "-Service" in order to run the server: {7A7FB085-6068-4898-8CCA-480A9187277C}
          4/19/2011 8:29:18 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 23 time(s).
          4/19/2011 8:29:13 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 22 time(s).
          4/19/2011 8:29:12 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 21 time(s).
          4/19/2011 8:28:40 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 20 time(s).
          4/19/2011 8:28:34 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 19 time(s).
          4/19/2011 3:02:02 PM, error: Service Control Manager [7000]  - The IMAPI CD-Burning COM Service service failed to start due to the following error:  The pipe has been ended.
          4/19/2011 2:05:25 PM, error: Service Control Manager [7022]  - The Java Quick Starter service hung on starting.
          4/19/2011 2:03:56 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Windows User Mode Driver Framework service to connect.
          4/19/2011 2:03:56 PM, error: Service Control Manager [7000]  - The Windows User Mode Driver Framework service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
          4/19/2011 11:59:31 AM, error: Service Control Manager [7000]  - The IMAPI CD-Burning COM Service service failed to start due to the following error:  The pipe state is invalid.
          4/19/2011 1:41:50 PM, error: DCOM [10000]  - Unable to start a DCOM Server: {31371420-098D-4C0E-A11E-EBEC2305DD01}. The error: "%5" Happened while starting this command: "C:\Program Files\Yahoo!\Companion\Installs\cpn\ytbb.exe" -Embedding
          4/18/2011 3:20:24 PM, error: System Error [1003]  - Error code 000000f4, parameter1 00000003, parameter2 846935d0, parameter3 84693744, parameter4 805c77d0.
          4/18/2011 2:27:56 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 18 time(s).
          4/18/2011 2:27:50 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 17 time(s).
          4/18/2011 2:27:49 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 16 time(s).
          4/18/2011 2:27:43 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 15 time(s).
          4/18/2011 2:27:42 PM, error: atapi [9]  - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
          4/18/2011 2:27:35 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 14 time(s).
          4/18/2011 11:54:26 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 13 time(s).
          4/18/2011 11:54:20 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 12 time(s).
          4/18/2011 11:54:20 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 11 time(s).
          4/18/2011 11:54:08 AM, error: Service Control Manager [7011]  - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service.
          4/18/2011 10:00:36 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 10 time(s).
          4/18/2011 10:00:29 AM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 9 time(s).
          4/17/2011 6:15:05 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 8 time(s).
          4/17/2011 6:14:59 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 7 time(s).
          4/17/2011 12:55:50 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the LexBce Server service to connect.
          4/17/2011 12:55:50 PM, error: Service Control Manager [7000]  - The LexBce Server service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
          4/17/2011 12:55:44 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 4 time(s).
          4/17/2011 12:55:44 PM, error: Service Control Manager [7000]  - The LexBce Server service failed to start due to the following error:  The pipe state is invalid.
          4/17/2011 12:55:43 PM, error: PlugPlayManager [12]  - The device 'IDE-CD   CROM6048' (IDE\CdRomIDE-CD___CROM6048_______________________HC02____\5&36942936&0&0.1.0) disappeared from the system without first being prepared for removal.
          4/17/2011 1:32:53 PM, error: Service Control Manager [7034]  - The IMAPI CD-Burning COM Service service terminated unexpectedly.  It has done this 1 time(s).
          4/17/2011 1:03:27 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 6 time(s).
          4/17/2011 1:03:21 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 5 time(s).
          4/17/2011 1:00:31 PM, error: DCOM [10000]  - Unable to start a DCOM Server: {641B9FB0-C2B1-41BD-8563-5F484E3BE84A}. The error: "%5" Happened while starting this command: "C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe" -Embedding
          4/17/2011 1:00:12 PM, error: Service Control Manager [7034]  - The Indexing Service service terminated unexpectedly.  It has done this 1 time(s).
          4/17/2011 1:00:12 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
          4/17/2011 1:00:12 PM, error: Service Control Manager [7000]  - The IMAPI CD-Burning COM Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
          4/17/2011 1:00:10 PM, error: Service Control Manager [7000]  - The SAVRTPEL service failed to start due to the following error:  The system cannot find the path specified.
          4/17/2011 1:00:10 PM, error: Service Control Manager [7000]  - The Machine Debug Manager service failed to start due to the following error:  The pipe state is invalid.
          4/16/2011 6:01:17 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 3 time(s).
          4/16/2011 6:01:11 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 2 time(s).
          4/16/2011 5:58:35 PM, error: Service Control Manager [7034]  - The Windows User Mode Driver Framework service terminated unexpectedly.  It has done this 1 time(s).
          4/16/2011 5:58:35 PM, error: Service Control Manager [7034]  - The Machine Debug Manager service terminated unexpectedly.  It has done this 1 time(s).
          4/16/2011 5:58:35 PM, error: Service Control Manager [7034]  - The LexBce Server service terminated unexpectedly.  It has done this 1 time(s).
          4/16/2011 5:58:35 PM, error: Service Control Manager [7034]  - The Java Quick Starter service terminated unexpectedly.  It has done this 1 time(s).
          4/16/2011 5:58:35 PM, error: Service Control Manager [7034]  - The iPod Service service terminated unexpectedly.  It has done this 1 time(s).
          .
          ==== End Of File ===========================


           Results of screen317's Security Check version 0.99.10 
           Windows XP Service Pack 2 
           Out of date service pack!!
           Internet Explorer 8 
          ``````````````````````````````
          Antivirus/Firewall Check:

           Windows Firewall Disabled! 
           AVG 2011     
           Norton AntiVirus 2005   
           Norton Internet Security   
          ```````````````````````````````
          Anti-malware/Other Utilities Check:

           Malwarebytes' Anti-Malware   
           Java(TM) 6 Update 23 
           Out of date Java installed!
           Adobe Flash Player   
          Adobe Reader 9.4.4
          Out of date Adobe Reader installed!
          ````````````````````````````````
          Process Check: 
          objlist.exe by Laurent

           AVG avgwdsvc.exe
           AVG avgtray.exe
           AVG avgrsx.exe
           AVG avgnsx.exe
           AVG avgemc.exe
          ``````````End of Log````````````


          My firewall is back on....  Thank you again!!!!!

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: MS Removal tool popup,cannot open anything!
          « Reply #7 on: April 23, 2011, 12:00:20 PM »
          The Security Check shows that you are possibly running more than one Anti-virus programs; AVG 2011, Norton AntiVirus 2005 and Norton Internet Security. Only one AV program should be enabled on your computer at any time. Make sure there is only one enabled.

          Update Your Java (JRE)

          Old versions of Java have vulnerabilities that malware can use to infect your system.


          First Verify your Java Version

          If there are any other version(s) installed then update now.

          Get the new version (if needed)

          If your version is out of date install the newest version of the Sun Java Runtime Environment.

          Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

          Be sure to close ALL open web browsers before starting the installation.

          Remove any old versions

          1. Download JavaRa and unzip the file to your Desktop.
          2. Open JavaRA.exe and choose Remove Older Versions
          3. Once complete exit JavaRA.
          4. Run CCleaner.

          Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
          ***********************************************
          Please download the newest version of Adobe Acrobat Reader from Adobe.com

          Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
          Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
          Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

          Once old versions are gone, please install the newest version.
          ****************************************************
          Please download ComboFix from BleepingComputer.com

          Alternate link: GeeksToGo.com

          and save it to your Desktop.
          It would be easiest to download using Internet Explorer.
          If you insist on using Firefox, make sure that your download settings are as follows:

          * Tools->Options->Main tab
          * Set to "Always ask me where to Save the files".

          Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
          Double click ComboFix.exe & follow the prompts.
          As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
          Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

          Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

          Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


          Click on Yes, to continue scanning for malware.
          When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

          If you have problems with ComboFix usage, see How to use ComboFix
          Windows 8 and Windows 10 dual boot with two SSD's