Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: SD, not sure you saw post-here are results you asked for  (Read 3055 times)

0 Members and 1 Guest are viewing this topic.

debby

    Topic Starter


    Hopeful

    Thanked: 2
    SD, not sure you saw post-here are results you asked for
    « on: January 03, 2010, 05:23:37 PM »
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 01/02/2010 at 07:46 PM

    Application Version : 4.32.1000

    Core Rules Database Version : 4441
    Trace Rules Database Version: 2265

    Scan type       : Complete Scan
    Total Scan Time : 02:13:10

    Memory items scanned      : 368
    Memory threats detected   : 0
    Registry items scanned    : 5963
    Registry threats detected : 0
    File items scanned        : 237584
    File threats detected     : 146

    Adware.Tracking Cookie
       C:\Users\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Users\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Windows.old\Documents and Settings\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Documents and Settings\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\debby@doubleclick[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@123count[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@247realmedia[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@2o7[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adbrite[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adbureau[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adrevolver[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@advertising[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@alineamedia[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@apmebf[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@atdmt[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@bizrate[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@bravenet[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@chitika[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@clickbank[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@collective-media[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@dealtime[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@dmtracker[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@doubleclick[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@ez-tracks[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@fastclick[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@findyour-siding[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@gpstracklog[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@hitbox[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@imrworldwide[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@insightexpressai[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@interclick[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@invitemedia[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@lionadtrack[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@media6degrees[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@mediaonenetwork[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@mediaplex[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@nextag[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@oddcast[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@overture[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@qnsr[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@questionmarket[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@revsci[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@roiservice[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][4].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][6].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][7].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt

      C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][4].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@specificclick[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@specificmedia[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tacoda[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@testcountry[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@thefind[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@trackalyzer[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tradedoubler[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@trafficmp[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@traveladvertising[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tribalfusion[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tripod[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][10].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][11].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][4].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][5].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][6].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][7].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][8].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][9].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@xiti[1].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@yieldmanager[2].txt
       C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@zedo[2].txt
       C:\Windows.old\Users\Debby\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Windows.old\Users\Debby\Cookies\Low\[email protected][2].txt
       C:\Windows.old\Users\Debby\Cookies\Low\[email protected][3].txt
     

    Here's MBAM

    Malwarebytes' Anti-Malware 1.43
    Database version: 3485
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 7.0.6002.18005

    1/2/2010 10:12:40 PM
    mbam-log-2010-01-02 (22-12-40).txt

    Scan type: Quick Scan
    Objects scanned: 93356
    Time elapsed: 3 minute(s), 42 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     

    I'm not sure I did Hijack This correctly.  It didn't come up at all like the instructions given on Computer Hope page. I clicked install and save and it installed and ran scan right away.  This is what it said:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:24:51 PM, on 1/2/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
    C:\Windows\System32\rundll32.exe
    C:\PROGRA~1\Webshots\315~1.761\webshots.scr
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/mycomcast/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: agihelper.AGUtils - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - mscoree.dll (file missing)
    O1 - Hosts: ::1 localhost
    O2 - BHO: agihelper.AGUtils - {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll (file missing)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\3.1.5.7617\Launcher.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\4.2\AGCoreService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    --
    End of file - 6416 bytes
     

    kpac

    • Web moderator


    • Hacker

    • kpac®
    • Thanked: 184
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Computer: Specs
    • Experience: Expert
    • OS: Windows 7
    Re: SD, not sure you saw post-here are results you asked for
    « Reply #1 on: January 03, 2010, 05:26:18 PM »
    Please be patient. It's only been a day since you posted the logs in your other topic. Two topics at the same time only confuse things and remember this is a volunteer service.