Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: program files 86 problems  (Read 8948 times)

0 Members and 1 Guest are viewing this topic.

Tubbz

    Topic Starter


    Greenhorn

    • Experience: Beginner
    • OS: Unknown
    program files 86 problems
    « on: March 26, 2012, 09:55:35 AM »
    I recently caught malware on my laptop and tried to remove it myself and ended up making it worse.
    Combo fix was infected and so was Norton. I did a full recovery and restored it back to factory settings and now im having problems.
    When I install Progams they are placed in a folder called program files 86, I am worried also that I haven't got rid of the malware properly.
    I would post a log but I dont know how.
    I would greatly appreciate it if somebody could help me. Thank you for reading this post.

    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Re: program files 86 problems
    « Reply #1 on: March 26, 2012, 10:09:15 AM »
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: program files 86 problems
    « Reply #2 on: March 26, 2012, 10:46:48 AM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    SUPERAntiSpyware

    If you already have SUPERAntiSpyware be sure to check for updates before scanning!


    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to Update the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose Perform Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log somewhere you can easily find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post.
    *********************************************
    Please download Malwarebytes Anti-Malware from here.
    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
    *************************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.
    * Save both reports to your desktop.
    * The instructions here ask you to attach the Attach.txt.



    1) DDS.txt
    2) Attach.txt
    Instead of attaching, please copy/past both logs into your Thread

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copying and pasting it into the reply.

    •Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
    Windows 8 and Windows 10 dual boot with two SSD's

    Darthgumby



      Beginner
    • Thanked: 6
      • Experience: Beginner
      • OS: Unknown
      Re: program files 86 problems
      « Reply #3 on: March 26, 2012, 01:12:36 PM »
      The 64-bit version of Windows 7 can run both 32-bit programs [which it stores in C:\Program Files (x86)],  and 64-bit programs [which it stores in C:\Program Files].


      Taken from Microsoft Answers:
      http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_programs/program-files-x-86-folder/6cb49a61-2c68-4562-9912-036378a2e8fe

      I would not be worried if you are running a 64-bit OS if files are saving to a Program Files x86 folder, as this is normal.
      There's a time when a man needs to fight, and a time when he needs to accept that his destiny is lost, that the ship has sailed, and that only a fool will continue. The truth is, I've always been a fool.

      Tubbz

        Topic Starter


        Greenhorn

        • Experience: Beginner
        • OS: Unknown
        Re: program files 86 problems
        « Reply #4 on: March 26, 2012, 03:01:50 PM »
         :)

        Hello and thanks, Sorry if this question seems a bit mundane but I cant seem to be able to turn off avira, I can only turn off real protection enable and web protection enable it is the free version.

        Is there a way?

        Tubbz

          Topic Starter


          Greenhorn

          • Experience: Beginner
          • OS: Unknown
          Re: program files 86 problems
          « Reply #5 on: March 26, 2012, 03:27:20 PM »
          I have followed the instructions and these are my logs.

          SUPERAntiSpyware Scan Log
          http://www.superantispyware.com

          Generated 03/26/2012 at 08:32 PM

          Application Version : 5.0.1146

          Core Rules Database Version : 8381
          Trace Rules Database Version: 6193

          Scan type       : Complete Scan
          Total Scan Time : 00:25:56

          Operating System Information
          Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
          UAC On - Limited User

          Memory items scanned      : 565
          Memory threats detected   : 0
          Registry items scanned    : 64523
          Registry threats detected : 0
          File items scanned        : 39798
          File threats detected     : 0

          Tubbz

            Topic Starter


            Greenhorn

            • Experience: Beginner
            • OS: Unknown
            Re: program files 86 problems
            « Reply #6 on: March 26, 2012, 03:28:16 PM »
            Malwarebytes Anti-Malware (Trial) 1.60.1.1000
            www.malwarebytes.org

            Database version: v2012.03.26.06

            Windows 7 Service Pack 1 x64 NTFS
            Internet Explorer 9.0.8112.16421
            Cameron :: CAMERONS-PC [administrator]

            Protection: Enabled

            26/03/2012 21:07:46
            mbam-log-2012-03-26 (21-07-46).txt

            Scan type: Quick scan
            Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
            Scan options disabled: P2P
            Objects scanned: 189949
            Time elapsed: 2 minute(s), 36 second(s)

            Memory Processes Detected: 0
            (No malicious items detected)

            Memory Modules Detected: 0
            (No malicious items detected)

            Registry Keys Detected: 0
            (No malicious items detected)

            Registry Values Detected: 0
            (No malicious items detected)

            Registry Data Items Detected: 0
            (No malicious items detected)

            Folders Detected: 0
            (No malicious items detected)

            Files Detected: 0
            (No malicious items detected)

            (end)

            Tubbz

              Topic Starter


              Greenhorn

              • Experience: Beginner
              • OS: Unknown
              Re: program files 86 problems
              « Reply #7 on: March 26, 2012, 03:29:10 PM »
              .
              DDS (Ver_2011-08-26.01) - NTFSAMD64
              Internet Explorer: 9.0.8112.16421
              Run by Cameron at 22:19:53 on 2012-03-26
              Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.3767.2209 [GMT 1:00]
              .
              AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
              SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
              SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
              FW: Online Armor Firewall *Disabled* {32E71E58-6AAE-2557-2ABD-EA739069CE41}
              .
              ============== Running Processes ===============
              .
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe -k DcomLaunch
              C:\Windows\system32\svchost.exe -k RPCSS
              C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
              C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
              C:\Windows\system32\svchost.exe -k netsvcs
              C:\Windows\system32\svchost.exe -k LocalService
              C:\Windows\system32\svchost.exe -k NetworkService
              C:\Program Files (x86)\Online Armor\OAcat.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\System32\spoolsv.exe
              C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
              C:\Windows\system32\taskhost.exe
              C:\Windows\System32\igfxtray.exe
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
              C:\Program Files\Elantech\ETDCtrl.exe
              C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
              C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
              C:\Program Files (x86)\Launch Manager\LManager.exe
              C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
              C:\Program Files (x86)\Ask.com\Updater\Updater.exe
              C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
              C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
              c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
              C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
              C:\Program Files (x86)\Launch Manager\dsiwmis.exe
              C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
              C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
              C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
              C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
              C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
              C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
              C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
              C:\Windows\system32\igfxext.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files (x86)\Launch Manager\LMworker.exe
              C:\Windows\system32\wbem\unsecapp.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
              C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
              C:\Windows\system32\conhost.exe
              C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\Program Files\Elantech\ETDCtrlHelper.exe
              C:\Windows\System32\svchost.exe -k LocalServicePeerNet
              C:\Windows\system32\DllHost.exe
              C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
              C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
              C:\Program Files (x86)\Nero\Update\NASvc.exe
              C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
              C:\Windows\System32\svchost.exe -k secsvcs
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
              C:\Windows\system32\taskhost.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10x_ActiveX.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Windows\system32\DllHost.exe
              C:\Windows\system32\DllHost.exe
              C:\Windows\SysWOW64\cmd.exe
              C:\Windows\system32\conhost.exe
              C:\Windows\SysWOW64\cscript.exe
              .
              ============== Pseudo HJT Report ===============
              .
              uStart Page = hxxp://www.google.co.uk/
              uDefault_Page_URL = hxxp://packardbell.msn.com
              mDefault_Page_URL = hxxp://packardbell.msn.com
              mStart Page = hxxp://packardbell.msn.com
              mWinlogon: Userinit=userinit.exe
              BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
              BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
              BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
              BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
              TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
              TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
              TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
              mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
              mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
              mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
              mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
              mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
              mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
              mRun: [<NO NAME>]
              mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
              mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
              mPolicies-explorer: NoActiveDesktop = 1 (0x1)
              mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
              mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
              mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
              mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
              IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
              IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
              LSP: C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll
              DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
              DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
              DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
              TCP: DhcpNameServer = 192.168.0.1
              TCP: Interfaces\{2D8F8784-3D6D-4008-8BEB-C2B3E7033B83} : DhcpNameServer = 192.168.0.1
              Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
              BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              BHO-X64:     AcroIEHelperStub - No File
              BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
              BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
              BHO-X64: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
              BHO-X64:     Ask Toolbar BHO - No File
              BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
              TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
              TB-X64: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
              TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
              mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
              mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
              mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
              mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
              mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
              mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
              mRun-x64: [(Default)]
              mRun-x64: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
              mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
              IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
              .
              ============= SERVICES / DRIVERS ===============
              .
              R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
              R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
              R1 OADevice;OADriver;C:\Windows\SysWOW64\drivers\OADriver.sys [2012-3-26 59176]
              R1 OAmon;OAmon;C:\Windows\SysWOW64\drivers\OAmon.sys [2012-3-26 38064]
              R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
              R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
              R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
              R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
              R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
              R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-3-26 86224]
              R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-3-26 110032]
              R2 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe [2012-3-26 463824]
              R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
              R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-5-12 249648]
              R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-10-28 321104]
              R2 ePowerSvc;Acer ePower Service;C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2012-3-26 867712]
              R2 GREGService;GREGService;C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [2011-5-30 36456]
              R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-28 13336]
              R2 Live Updater Service;Live Updater Service;C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2011-10-28 244624]
              R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-3-26 652360]
              R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
              R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2010-6-28 255744]
              R2 OAcat;Online Armor Helper Service;C:\Program Files (x86)\Online Armor\oacat.exe [2012-3-26 208472]
              R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-10-28 2320920]
              R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
              R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\drivers\HECIx64.sys --> C:\Windows\system32\drivers\HECIx64.sys [?]
              R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
              R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
              R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
              R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
              R3 OAnet;OnlineArmor Service;C:\Windows\system32\DRIVERS\oanet.sys --> C:\Windows\system32\DRIVERS\oanet.sys [?]
              S1 oahlpXX;Online Armor helper driver;C:\Windows\SysWOW64\drivers\oahlp64.sys [2012-3-26 59176]
              S2 SvcOnlineArmor;Online Armor;C:\Program Files (x86)\Online Armor\oasrv.exe [2012-3-26 4369208]
              S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-6-7 191752]
              S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
              S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
              S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
              S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
              S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
              .
              =============== Created Last 30 ================
              .
              2012-03-26 21:06:40   --------   d-----w-   C:\Windows\NAPP_Dism_Log
              2012-03-26 17:24:42   --------   d-----w-   C:\Users\Cameron\AppData\Roaming\Avira
              2012-03-26 17:18:24   --------   d-----w-   C:\Users\Cameron\AppData\Local\AskToolbar
              2012-03-26 17:18:16   --------   d-----w-   C:\Program Files (x86)\Ask.com
              2012-03-26 17:17:51   97312   ----a-w-   C:\Windows\System32\drivers\avgntflt.sys
              2012-03-26 17:17:51   27760   ----a-w-   C:\Windows\System32\drivers\avkmgr.sys
              2012-03-26 17:17:50   --------   d-----w-   C:\ProgramData\Avira
              2012-03-26 17:17:50   --------   d-----w-   C:\Program Files (x86)\Avira
              2012-03-26 16:49:00   --------   d-----w-   C:\Program Files\CCleaner
              2012-03-26 16:40:11   472808   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
              2012-03-26 16:27:37   --------   d-----w-   C:\Users\Cameron\AppData\Roaming\SUPERAntiSpyware.com
              2012-03-26 16:27:01   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
              2012-03-26 16:27:01   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
              2012-03-26 16:22:31   --------   d-----w-   C:\Users\Cameron\AppData\Roaming\OnlineArmor
              2012-03-26 16:22:31   --------   d-----w-   C:\ProgramData\OnlineArmor
              2012-03-26 16:19:17   59176   ----a-w-   C:\Windows\SysWow64\drivers\oahlp64.sys
              2012-03-26 16:19:17   59176   ----a-w-   C:\Windows\SysWow64\drivers\OADriver.sys
              2012-03-26 16:19:17   38064   ----a-w-   C:\Windows\SysWow64\drivers\OAmon.sys
              2012-03-26 16:19:17   32920   ----a-w-   C:\Windows\System32\drivers\OAnet.sys
              2012-03-26 16:19:13   --------   d-----w-   C:\Program Files (x86)\Online Armor
              2012-03-26 15:36:05   --------   d-----w-   C:\Users\Cameron\AppData\Roaming\Malwarebytes
              2012-03-26 15:36:00   --------   d-----w-   C:\ProgramData\Malwarebytes
              2012-03-26 15:35:59   23152   ----a-w-   C:\Windows\System32\drivers\mbam.sys
              2012-03-26 15:35:59   --------   d-----w-   C:\Program Files (x86)\Malwarebytes' Anti-Malware
              2012-03-26 13:23:08   --------   d-----w-   C:\Program Files (x86)\Common Files\Symantec Shared
              2012-03-26 13:14:55   --------   d-----w-   C:\Users\Cameron\AppData\Local\Mozilla
              2012-03-26 12:56:37   --------   d-----w-   C:\Users\Cameron\AppData\Roaming\Screensaver
              2012-03-26 12:56:35   --------   d-----w-   C:\Users\Cameron\AppData\Local\Adobe
              2012-03-26 12:56:10   --------   d-----w-   C:\Users\Cameron\AppData\Local\VirtualStore
              2012-03-26 12:55:54   826880   ----a-w-   C:\Windows\SysWow64\rdpcore.dll
              2012-03-26 12:55:54   1031680   ----a-w-   C:\Windows\System32\rdpcore.dll
              2012-03-26 12:55:53   23552   ----a-w-   C:\Windows\System32\drivers\tdtcp.sys
              2012-03-26 12:55:53   210944   ----a-w-   C:\Windows\System32\drivers\rdpwd.sys
              2012-03-26 12:55:52   9216   ----a-w-   C:\Windows\System32\rdrmemptylst.exe
              2012-03-26 12:55:52   77312   ----a-w-   C:\Windows\System32\rdpwsx.dll
              2012-03-26 12:55:52   149504   ----a-w-   C:\Windows\System32\rdpcorekmts.dll
              2012-03-26 12:33:29   --------   d-----w-   C:\Program Files (x86)\Video Web Camera
              2012-03-26 12:31:59   650240   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\Office14\Access.en-us\AccessMUISet.msi
              2012-03-26 12:31:59   1813504   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\Office14\Access.en-us\Access.en-us\AccessMUI.msi
              2012-03-26 12:31:59   1100664   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\Office14\setup.exe
              2012-03-26 12:31:58   1631120   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\SetupConsumerC2ROLW.exe
              2012-03-26 12:31:58   1631120   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\SetupConsumerC2R.exe
              2012-03-26 12:31:57   5336456   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\Office.exe
              2012-03-26 12:31:57   18336   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\launchofficeintl.dll
              2012-03-26 12:31:51   33000960   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\click2run64.msi
              2012-03-26 12:31:50   26051072   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OStarter\en-us\click2run.msi
              2012-03-26 12:31:50   2376704   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OOBE\oobe.msi
              2012-03-26 12:31:50   101888   ----a-w-   C:\ProgramData\Microsoft\OEMOffice14\OOBE\oobe-x-none.msp
              2012-03-26 12:27:18   55856   ------w-   C:\Windows\System32\drivers\PxHlpa64.sys
              2012-03-26 12:27:18   10224   ------w-   C:\Windows\System32\drivers\cdralw2k.sys
              2012-03-26 12:27:18   10224   ------w-   C:\Windows\System32\drivers\cdr4_xp.sys
              2012-03-26 12:25:58   --------   d-----w-   C:\Program Files (x86)\Common Files\Sonic Shared
              2012-03-26 12:25:58   --------   d-----w-   C:\Program Files (x86)\Common Files\PX Storage Engine
              2012-03-26 12:25:20   --------   d-----w-   C:\ProgramData\CLSK
              2012-03-26 12:25:14   --------   d-----w-   C:\Program Files (x86)\Social Networks
              2012-03-26 12:25:10   --------   d-----w-   C:\ProgramData\install_clap
              2012-03-26 12:24:32   --------   d-----w-   C:\Program Files (x86)\Microsoft
              2012-03-26 12:19:58   757760   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
              2012-03-26 12:19:58   69715   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
              2012-03-26 12:19:58   65024   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
              2012-03-26 12:19:58   5632   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
              2012-03-26 12:19:58   32768   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
              2012-03-26 12:19:58   274432   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
              2012-03-26 12:19:58   204800   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
              2012-03-26 12:19:57   331908   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
              2012-03-26 12:19:57   200836   ----a-w-   C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
              2012-03-26 12:17:11   --------   d-----w-   C:\Program Files (x86)\Launch Manager
              2012-03-26 12:14:00   --------   d--ha-w-   C:\book
              2012-03-26 12:11:02   --------   d-----w-   C:\Program Files\Common Files\Intel
              2012-03-26 12:11:02   --------   d-----w-   C:\Program Files (x86)\Common Files\Intel
              .
              ==================== Find3M  ====================
              .
              .
              ============= FINISH: 22:20:17.51 ===============

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: program files 86 problems
              « Reply #8 on: March 27, 2012, 10:33:40 AM »
              I strongly recommend that you remove Ask from your computer because it;

              •Promotes its toolbars on sites targeted to kids.

              •Promotes its toolbars through ads that appear to be part of other companies' sites.

              •Promotes its toolbars through other companies' spyware.

              •Installs without any disclosure whatsoever and without any consent whatsoever.

              •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

              •Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.

              See Here for more info.

              If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

              AskBarDis or anything related to Ask

              Then please find and delete this folder in bold (if present):
              C:\Program Files\AskBarDis. or anything related to Ask.
              *****************************************************
              Download Combofix from any of the links below, and save it to your desktop

              Link 1
              Link 2
              Link 3

              To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
              • Close any open windows and double click ComboFix.exe to run it.

                You will see the following image:


              Click I Agree to start the program.

              ComboFix will then extract the necessary files and you will see this:



              As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

              It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

              If you did not have it installed, you will see the prompt below. Choose YES.



              Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

              **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

              Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



              Click on Yes, to continue scanning for malware.

              When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

              Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

              Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
              « Last Edit: March 28, 2012, 12:02:26 PM by SuperDave »
              Windows 8 and Windows 10 dual boot with two SSD's

              Tubbz

                Topic Starter


                Greenhorn

                • Experience: Beginner
                • OS: Unknown
                Re: program files 86 problems
                « Reply #9 on: March 28, 2012, 01:32:16 AM »
                I cant open the link i was sent. It wont let me turn off internet protection. I've tried ending processes and when its finished it tells me to restart then when I boot its on again should i uninstall avira then run combofix?
                I also have uninstalled the bar but cant find anything related to askbar.dis.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: program files 86 problems
                « Reply #10 on: March 28, 2012, 12:05:55 PM »
                I fixed that link. Here's how to disable Avira:

                Avira Anti-Vir

                Please navigate to the system tray on the bottom right hand corner and look for an open white umbrella on red background.
                right click it-> untick the option AntiVir Guard enable.
                You should now see a closed, white umbrella on a red background.
                You successfully disabled the AntiVir Guard.
                Windows 8 and Windows 10 dual boot with two SSD's