Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: ? Fake Microsoft Message  (Read 5131 times)

0 Members and 1 Guest are viewing this topic.

gerry7

    Topic Starter


    Beginner

    ? Fake Microsoft Message
    « on: April 26, 2009, 04:31:23 AM »
    Whilst browsing the internet, a window suddenly popped up purporting to come from Windows. It said that my computer showed signs of virus infection and invited me to allow a scan. I did nothing but I then got a message saying there were 72 signs of infection. I suspect that this is not a genuine Microsoft message.
    I now have a message from Spybot-Search and Destroy:
    Category: Browser Helper Object
    Change: Value Deleted
    Entry: (C 84D72FE-E17D-4195-BB24-76CO2E2E74CE

    the option to deny change is greyed out which makes me very suspicious. 

    I am running a Malawarebytes scan but meanwhile would like to know please if anyone has any experience of this.

    gerry7

      Topic Starter


      Beginner

      Re: ? Fake Microsoft Message firewall
      « Reply #1 on: April 26, 2009, 05:59:38 AM »
      Since sending the last post, I have tried using the Computer Hope hijackthis analysis tool. It reported that I do not have a firewall running. However, according to my control panel, the Windows firewall is on.
      Which of them is likely to be correct?

      Helpmeh



        Guru

      • Roar.
      • Thanked: 123
        • Yes
        • Yes
      • Computer: Specs
      • Experience: Familiar
      • OS: Windows 8
      Re: ? Fake Microsoft Message
      « Reply #2 on: April 26, 2009, 06:39:13 AM »
      Since sending the last post, I have tried using the Computer Hope hijackthis analysis tool. It reported that I do not have a firewall running. However, according to my control panel, the Windows firewall is on.
      Which of them is likely to be correct?
      I'm not an expert, but there is a chance that a virus is making your system think that it has a firewall running, and hijackthis is seeing the truth.


      But to ensure that you get the proper help you need, go to http://www.computerhope.com/forum/index.php/topic,46313.0.html and follow all the instructions.
      « Last Edit: April 26, 2009, 09:30:23 AM by Helpmeh »
      Where's MagicSpeed?
      Quote from: 'matt'
      He's playing a game called IRL. Great graphics, *censored* gameplay.

      gerry7

        Topic Starter


        Beginner

        Re: ? Fake Microsoft Message
        « Reply #3 on: April 26, 2009, 09:30:01 AM »
        Thanks. How can I find out?

        The scan is showing no viruses or other malaware.

        Helpmeh



          Guru

        • Roar.
        • Thanked: 123
          • Yes
          • Yes
        • Computer: Specs
        • Experience: Familiar
        • OS: Windows 8
        Re: ? Fake Microsoft Message
        « Reply #4 on: April 26, 2009, 09:30:51 AM »
        Thanks. How can I find out?

        The scan is showing no viruses or other malaware.
        See my post (I just added the link).
        Where's MagicSpeed?
        Quote from: 'matt'
        He's playing a game called IRL. Great graphics, *censored* gameplay.

        gerry7

          Topic Starter


          Beginner

          Re: ? Fake Microsoft Message
          « Reply #5 on: April 26, 2009, 11:58:15 AM »
          I have done all that and installed SP3 [which I had been reluctant to do because I read of associated problems]. The HJT Tool is still showing no firewall. Security settings shows Windows Firewall & Auto updates 'ON'.

          harry 48



            Egghead

          • lay back , relax and chill out
          • Thanked: 129
            • Yes
            • Yes
            • Yes
            • Dribbling Pensioner
          • Certifications: List
          • Experience: Familiar
          • OS: Windows 7
          Re: ? Fake Microsoft Message
          « Reply #6 on: April 26, 2009, 01:49:27 PM »
          GERRY7 do as helpmeh said go to his post and post all 3 logs here for an expert , harry

          Helpmeh



            Guru

          • Roar.
          • Thanked: 123
            • Yes
            • Yes
          • Computer: Specs
          • Experience: Familiar
          • OS: Windows 8
          Re: ? Fake Microsoft Message
          « Reply #7 on: April 26, 2009, 02:55:56 PM »
          I have done all that and installed SP3 [which I had been reluctant to do because I read of associated problems]. The HJT Tool is still showing no firewall. Security settings shows Windows Firewall & Auto updates 'ON'.
          You need to post the logs here (like the link says).
          Where's MagicSpeed?
          Quote from: 'matt'
          He's playing a game called IRL. Great graphics, *censored* gameplay.

          gerry7

            Topic Starter


            Beginner

            Re: ? Fake Microsoft Message
            « Reply #8 on: April 27, 2009, 06:23:04 AM »

            Thank you for this advice. The three logs are as follows:

            Spybot

            --- Report generated: 2009-04-27 12:24 ---

            MyWay.MyWebSearch: [SBI $D952D8BB] Class ID (Registry key, fixed)
              HKEY_CLASSES_ROOT\CLSID\{B15FD82E-85BC-430d-90CB-65DB1B030510}

            MyWay.MyWebSearch: [SBI $590CA7CC] Class ID (Registry key, fixed)
              HKEY_CLASSES_ROOT\CLSID\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $2E33E144] Class ID (Registry key, fixed)
              HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $ACCE370C] Class ID (Registry key, fixed)
              HKEY_CLASSES_ROOT\CLSID\{F0D4B23B-DA4B-4daf-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $16DF808B] Interface (Registry key, fixed)
              HKEY_CLASSES_ROOT\Interface\{F0D4B23A-DA4B-4DAF-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $0B105129] Interface (Registry key, fixed)
              HKEY_CLASSES_ROOT\Interface\{F0D4B23C-DA4B-4DAF-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $DCB82066] Type library (Registry key, fixed)
              HKEY_CLASSES_ROOT\TypeLib\{F0D4B230-DA4B-4DAF-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $CD97DE2F] Browser helper object (Registry key, fixed)
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}

            MyWay.MyWebSearch: [SBI $9B0AB1A3] Settings (Registry key, fixed)
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F0D4B23B-DA4B-4daf-81E4-DFEE4931A4AA}


            --- Spybot - Search & Destroy version: 1.6.2  (build: 20090126) ---

            2009-01-26 blindman.exe (1.0.0.8)
            2008-01-28 SDDelFile.exe (1.0.2.4)
            2009-01-26 SDFiles.exe (1.6.1.7)
            2009-01-26 SDMain.exe (1.0.0.6)
            2009-01-26 SDShred.exe (1.0.2.5)
            2009-01-26 SDUpdate.exe (1.6.0.12)
            2008-01-28 SDWinSec.exe (1.0.0.11)
            2009-01-26 SpybotSD.exe (1.6.2.46)
            2009-03-05 TeaTimer.exe (1.6.6.32)
            2009-04-22 unins001.exe (51.49.0.0)
            2009-01-26 Update.exe (1.6.0.7)
            2009-01-26 advcheck.dll (1.6.2.15)
            2007-04-02 aports.dll (2.1.0.0)
            2008-06-14 DelZip179.dll (1.79.11.1)
            2009-01-26 SDHelper.dll (1.6.2.14)
            2008-06-19 sqlite3.dll
            2009-01-26 Tools.dll (2.1.6.10)
            2009-01-16 UninsSrv.dll (1.0.0.0)
            2009-03-25 Includes\Adware.sbi (*)
            2009-04-21 Includes\AdwareC.sbi (*)
            2009-01-22 Includes\Cookies.sbi (*)
            2009-03-31 Includes\Dialer.sbi (*)
            2009-04-21 Includes\DialerC.sbi (*)
            2009-01-22 Includes\HeavyDuty.sbi (*)
            2009-04-21 Includes\Hijackers.sbi (*)
            2009-04-21 Includes\HijackersC.sbi (*)
            2009-03-17 Includes\Keyloggers.sbi (*)
            2009-04-21 Includes\KeyloggersC.sbi (*)
            2004-11-29 Includes\LSP.sbi (*)
            2009-04-07 Includes\Malware.sbi (*)
            2009-04-21 Includes\MalwareC.sbi (*)
            2009-03-25 Includes\PUPS.sbi (*)
            2009-03-31 Includes\PUPSC.sbi (*)
            2009-01-22 Includes\Revision.sbi (*)
            2009-01-13 Includes\Security.sbi (*)
            2009-04-21 Includes\SecurityC.sbi (*)
            2008-06-03 Includes\Spybots.sbi (*)
            2008-06-03 Includes\SpybotsC.sbi (*)
            2009-04-07 Includes\Spyware.sbi (*)
            2009-04-21 Includes\SpywareC.sbi (*)
            2009-04-07 Includes\Tracks.uti
            2009-04-21 Includes\Trojans.sbi (*)
            2009-04-21 Includes\TrojansC.sbi (*)
            2008-03-04 Plugins\Chai.dll
            2008-03-05 Plugins\Fennel.dll
            2008-02-26 Plugins\Mate.dll
            2007-12-24 Plugins\TCPIPAddress.dll






            Malwarebytes' Anti-Malware 1.36
            Database version: 2047
            Windows 5.1.2600 Service Pack 3

            27/04/2009 13:08:15
            mbam-log-2009-04-27 (13-08-15).txt

            Scan type: Quick Scan
            Objects scanned: 102044
            Time elapsed: 5 minute(s), 12 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            (No malicious items detected)


            I have tried to remove the two 023AVG entries on several occasions without success. I un installed AVG many months ago. There remains a folder in my program Files which contains one file. Grisoft/AVGfree/avgs. dll. Is it safe for me simply to delete this folder?
            HijackThis 

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 13:13:51, on 27/04/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\system32\crypserv.exe
            C:\Program Files\HistorySweep\HSSvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Kontiki\KService.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
            C:\WINDOWS\system32\vmnat.exe
            C:\WINDOWS\system32\fxssvc.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\vmnetdhcp.exe
            C:\Program Files\VMware\VMware Player\vmware-authd.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Canon\CAL\CALMAIN.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\TalkTalk\bin\sprtcmd.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\Mgboss\mgboss.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Eraser\eraser.exe
            C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
            C:\Program Files\Kontiki\KHost.exe
            C:\Program Files\Skype\Phone\Skype.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
            C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
            C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
            C:\Program Files\ViaVoice\BIN\speechbar.exe
            C:\Program Files\ViaVoice\bin\engine.exe
            C:\Program Files\ViaVoice\Bin\vvuiman.exe
            C:\Program Files\ViaVoice\bin\NavCentral.EXE
            C:\Program Files\ViaVoice\bin\MSAADMN.EXE
            C:\Program Files\ViaVoice\Bin\voicepad.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mama.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.supanet.com/search/iepanel/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Abel Internet
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
            O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
            O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\msconfig.exe /auto
            O4 - HKLM\..\Run: [EfreeSoft Boss Key] C:\Program Files\Mgboss\mgboss.exe -min
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Al"
            O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
            O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
            O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKCU\..\Run: [Rapportexe] "C:\Program Files\Trusteer\Rapport\bin\RapportService.exe" -start -after_boot
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
            O4 - Global Startup: Corel Family and Friends Reminders.lnk = C:\Program Files\Corel\Print House Magic\cffrem.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O9 - Extra button: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
            O9 - Extra 'Tools' menuitem: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
            O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://home.abelgratis.co.uk
            O16 - DPF: FirstViewer - http://barnet.documentretrieval.co.uk/alchemyweb/Components/FirstVwr.CAB
            O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/da/PCPitStop.CAB
            O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} - https://signup.msn.com/pages/MsnInstC.cab
            O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
            O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
            O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
            O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
            O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
            O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HistorySweepService - Unknown owner - C:\Program Files\HistorySweep\HSSvc.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
            O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
            O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
            O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
            O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
            O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
            O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
            O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
            O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
            O24 - Desktop Component 0: (no name) - http://images.thetimes.co.uk/images/TIMESHeadBGLogo_1.gif

            --
            End of file - 15038 bytes

            gerry7

              Topic Starter


              Beginner

              Re: ? Fake Microsoft Message
              « Reply #9 on: May 05, 2009, 02:55:41 AM »
              Have I done something wrong?
              I posted these logs as invited 8 days ago but there has been no feedback.
              I would be very grateful if someone would look at them and solve the firewall mystery which is so worrying.

              harry 48



                Egghead

              • lay back , relax and chill out
              • Thanked: 129
                • Yes
                • Yes
                • Yes
                • Dribbling Pensioner
              • Certifications: List
              • Experience: Familiar
              • OS: Windows 7
              Re: ? Fake Microsoft Message
              « Reply #10 on: May 05, 2009, 08:22:28 AM »
              nothing wrong sometimes the experts miss one topic it depends who is on and what time , harry

              gerry7

                Topic Starter


                Beginner

                Re: ? Fake Microsoft Message
                « Reply #11 on: May 06, 2009, 06:34:02 AM »
                Thanks. Is there any way I can tactfully remind them?

                Helpmeh



                  Guru

                • Roar.
                • Thanked: 123
                  • Yes
                  • Yes
                • Computer: Specs
                • Experience: Familiar
                • OS: Windows 8
                Re: ? Fake Microsoft Message
                « Reply #12 on: May 06, 2009, 02:59:10 PM »
                Thanks. Is there any way I can tactfully remind them?
                Evilfantasy is just one person, and as you can see in the forum, LOTS of people need his help. Just click the !notify button () and when there is a reply, check back.
                Where's MagicSpeed?
                Quote from: 'matt'
                He's playing a game called IRL. Great graphics, *censored* gameplay.