Unsolved

This post is more than 5 years old

62 Posts

3800

April 1st, 2011 13:00

Unable to Update Security Software

I can not seem to get Secunia PSI to open on my desktop. I did, earlier today, have to quarantine the WORM/Kolabc.ixm in my Antivir. I then deleted it from the quarantine file. But, that was this morning. I have been trying for over 1 week to reinstall Secunia. Don't know if the two issues are related. I have uninstalled all of Secunia I could find for the time being. Hope I'm not over- thinking this!

Thanks in advance for your time and help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:07:41 PM, on 4/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139782755687
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup163.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

--
End of file - 7860 bytes

2 Intern

 • 

1.5K Posts

April 10th, 2011 15:00

Your Welcome,

Depending how how your browsers are set, they automatically save all downloads to the downloads folder. Then files you see located there are just installers that you previously downloaded. They can be deleted by just right clicking them and selecting delete. They will not interfere with the Secunia install as they are not active on the system.

If you have been using IE to download Secunia, this time use Firefox. Before download Secunia, please click the Tools tab on the browser toolbar and then select Options. Click the General tab and then put a check next to "Always Ask me where to save files", then when you download the Secunia Installer, please save it to the desktop and run it from there.

Let me if clearing the temp and cache using CCleaner and downloading Secunia using a different browser has made any difference.

Thanks.

62 Posts

April 10th, 2011 20:00

K27,

          Sorry to report no success. Same results, a white empty screen appears for a second and then is gone without Secunia opening up.

           What to do?

Thanks

2 Intern

 • 

1.5K Posts

April 11th, 2011 03:00

Hi,

Please post me a fresh set of DDS logs.

Thanks.

2 Intern

 • 

1.5K Posts

April 11th, 2011 07:00

Hi,

Please confirm that there is no Secuina Taskbar Icon and if there is, does it work. Also, if there is, please Right Click the Taskbar icon and select "Open". If that fails please go to "Start > All Programs > Secunia and try opening the program from there.

The only reason I ask is that according to the logs, Secuina is installed and running on the System:

===========Running Processes=====================

C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Secunia\PSI\sua.exe

============== Pseudo HJT Report ===============


StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe


============= SERVICES / DRIVERS ===============

R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848]

R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-1-10 399416]

R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]

=============== Created Last 30 ================

2011-04-11 01:52:57   --------            d-----w-          c:\program files\Secunia

2011-04-07 13:00:48   --------            d-----w-          c:\docume~1\bill\locals~1\applic~1\Secunia PSI


 ==== Installed Programs ======================

Secunia PSI (2.0.0.3001)

 

 

If it is still not working or showing as installed on the system then it is a very strange problem indeed.

62 Posts

April 11th, 2011 07:00

K27,

Here are the fresh set of DDS logs:

Normal 0 false false false MicrosoftInternetExplorer4

.

DDS (Ver_11-03-05.01) - NTFSx86 

Run by Bill at  8:57:09.60 on Mon 04/11/2011

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24

Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1014.491 [GMT -4:00]

.

AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\stsystra.exe

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\Secunia\PSI\psi_tray.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\cisvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\Program Files\Secunia\PSI\PSIA.exe

svchost.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Canon\CAL\CALMAIN.exe

C:\WINDOWS\system32\dlcccoms.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Secunia\PSI\sua.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Documents and Settings\Bill\Desktop\dds.com

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/ig/dell?hl=en

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s

mSearchAssistant = hxxp://www.google.com/ie

BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll

BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\googleafe\GoogleAE.dll

BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

mRun: [SigmatelSysTrayApp] stsystra.exe

mRun: [dla] c:\windows\system32\dla\tfswctrl.exe

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe"  /autorun

mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup

mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16

mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe"

mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139782755687

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab

DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - hxxp://download.abacast.com/download/files/abasetup163.cab

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\docume~1\bill\applic~1\mozilla\firefox\profiles\bmxgz0yd.default\

FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties

FF - prefs.js: network.proxy.type - 0

FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll

FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll

FF - component: c:\documents and settings\bill\application data\mozilla\firefox\profiles\bmxgz0yd.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCoreGecko19.dll

FF - component: c:\documents and settings\bill\application data\mozilla\firefox\profiles\bmxgz0yd.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll

FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll

FF - plugin: c:\documents and settings\bill\application data\move networks\plugins\npqmp071505000010.dll

FF - plugin: c:\documents and settings\bill\application data\move networks\plugins\npqmp071505000011.dll

FF - plugin: c:\program files\google\google updater\2.4.1851.5542\npCIDetect14.dll

FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll

FF - plugin: c:\program files\nos\bin\np_gp.dll

.

============= SERVICES / DRIVERS ===============

.

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-10-17 11608]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-10-17 135336]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-10-17 269480]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-4-29 61960]

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848]

R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-1-10 399416]

R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]

S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-7 135664]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2005-12-29 30192]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2005-8-16 14336]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

.

=============== Created Last 30 ================

.

2011-04-11 01:52:57   --------            d-----w-          c:\program files\Secunia

2011-04-07 13:00:48   --------            d-----w-          c:\docume~1\bill\locals~1\applic~1\Secunia PSI

2011-04-03 17:50:43   38224  ----a-w-           c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-03 17:50:38   20952  ----a-w-           c:\windows\system32\drivers\mbam.sys

2011-04-03 17:50:38   --------            d-----w-          c:\program files\Malwarebytes' Anti-Malware

2011-04-03 17:12:22   --------            d-----w-          c:\program files\CCleaner

2011-04-01 19:06:44   388096            ----a-r-            c:\docume~1\bill\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe

2011-03-29 03:20:14   142296            ----a-w-           c:\program files\mozilla firefox\components\browsercomps.dll

2011-03-29 03:20:13   781272            ----a-w-           c:\program files\mozilla firefox\mozsqlite3.dll

2011-03-29 03:20:13   728024            ----a-w-           c:\program files\mozilla firefox\libGLESv2.dll

2011-03-29 03:20:13   1975768          ----a-w-           c:\program files\mozilla firefox\D3DCompiler_42.dll

2011-03-29 03:20:13   1893336          ----a-w-           c:\program files\mozilla firefox\d3dx9_42.dll

2011-03-29 03:20:13   1874904          ----a-w-           c:\program files\mozilla firefox\mozjs.dll

2011-03-29 03:20:13   15832  ----a-w-           c:\program files\mozilla firefox\mozalloc.dll

2011-03-29 03:20:13   142296            ----a-w-           c:\program files\mozilla firefox\libEGL.dll

.

==================== Find3M  ====================

.

2011-02-19 13:31:59   73728  ----a-w-           c:\windows\system32\javacpl.cpl

2011-02-19 13:31:59   472808            ----a-w-           c:\windows\system32\deployJava1.dll

2011-02-18 21:36:58   4184352          ----a-w-           c:\windows\system32\usbaaplrc.dll

2011-02-04 22:48:32   456192            ----a-w-           c:\windows\system32\encdec.dll

2011-02-04 22:48:30   291840            ----a-w-           c:\windows\system32\sbe.dll

2011-02-02 07:58:35   2067456          ----a-w-           c:\windows\system32\mstscax.dll

2011-01-28 21:34:38   348160            ----a-w-           c:\windows\system32\msvcr71.dll

2011-01-27 11:57:06   677888            ----a-w-           c:\windows\system32\mstsc.exe

2011-01-21 14:44:37   439296            ----a-w-           c:\windows\system32\shimgvw.dll

.

============= FINISH:  8:57:54.75 ===============

 

Normal 0 false false false MicrosoftInternetExplorer4

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_11-03-05.01)

.

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume2

Install Date: 1/3/2006 10:47:55 PM

System Uptime: 4/11/2011 8:51:16 AM (0 hours ago)

.

Motherboard: Dell Inc.           |  | 0WG261

Processor:               Intel(R) Pentium(R) 4 CPU 3.40GHz | Microprocessor | 3391/800mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 70 GiB total, 28.908 GiB free.

D: is CDROM ()

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP186: 1/9/2011 3:09:16 PM - System Checkpoint

RP187: 1/10/2011 5:22:30 PM - System Checkpoint

RP188: 1/11/2011 6:32:51 PM - System Checkpoint

RP189: 1/12/2011 10:45:15 AM - Software Distribution Service 3.0

RP190: 1/12/2011 11:02:34 AM - Software Distribution Service 3.0

RP191: 1/13/2011 12:10:46 PM - System Checkpoint

RP192: 1/14/2011 4:12:33 PM - System Checkpoint

RP193: 1/15/2011 8:57:30 PM - System Checkpoint

RP194: 1/17/2011 10:58:04 AM - System Checkpoint

RP195: 1/18/2011 12:23:08 PM - System Checkpoint

RP196: 1/19/2011 3:04:02 PM - System Checkpoint

RP197: 1/20/2011 3:06:22 PM - System Checkpoint

RP198: 1/21/2011 7:46:36 PM - System Checkpoint

RP199: 1/22/2011 8:29:56 PM - System Checkpoint

RP200: 1/23/2011 9:16:28 PM - System Checkpoint

RP201: 1/24/2011 9:46:11 PM - System Checkpoint

RP202: 1/26/2011 12:48:40 PM - System Checkpoint

RP203: 1/27/2011 1:12:16 PM - Removed HiJackThis

RP204: 1/28/2011 1:36:47 PM - System Checkpoint

RP205: 1/29/2011 5:59:32 PM - System Checkpoint

RP206: 1/31/2011 9:29:34 AM - System Checkpoint

RP207: 2/1/2011 10:18:27 AM - System Checkpoint

RP208: 2/2/2011 10:52:35 AM - System Checkpoint

RP209: 2/3/2011 2:10:04 PM - System Checkpoint

RP210: 2/4/2011 2:45:54 PM - System Checkpoint

RP211: 2/5/2011 2:46:12 PM - System Checkpoint

RP212: 2/6/2011 3:37:22 PM - System Checkpoint

RP213: 2/7/2011 4:15:32 PM - System Checkpoint

RP214: 2/8/2011 5:00:18 PM - System Checkpoint

RP215: 2/9/2011 12:14:00 AM - Software Distribution Service 3.0

RP216: 2/10/2011 12:34:28 PM - System Checkpoint

RP217: 2/11/2011 1:21:55 PM - System Checkpoint

RP218: 2/12/2011 9:54:42 AM - Removed Adobe Reader 9.4.2.

RP219: 2/12/2011 9:58:11 AM - Installed Adobe Reader X (10.0.1).

RP220: 2/13/2011 12:49:03 PM - System Checkpoint

RP221: 2/14/2011 1:35:40 PM - System Checkpoint

RP222: 2/15/2011 8:00:52 AM - Software Distribution Service 3.0

RP223: 2/16/2011 10:54:21 AM - System Checkpoint

RP224: 2/17/2011 11:20:46 AM - System Checkpoint

RP225: 2/18/2011 11:50:03 AM - System Checkpoint

RP226: 2/19/2011 8:31:01 AM - Removed Java(TM) 6 Update 22

RP227: 2/19/2011 8:31:42 AM - Installed Java(TM) 6 Update 24

RP228: 2/20/2011 6:32:53 PM - System Checkpoint

RP229: 2/21/2011 10:47:52 PM - System Checkpoint

RP230: 2/23/2011 12:18:09 PM - Software Distribution Service 3.0

RP231: 2/24/2011 5:08:29 PM - System Checkpoint

RP232: 2/25/2011 5:51:28 PM - System Checkpoint

RP233: 2/26/2011 6:21:44 PM - System Checkpoint

RP234: 2/27/2011 8:49:41 PM - System Checkpoint

RP235: 3/1/2011 3:25:23 PM - System Checkpoint

RP236: 3/2/2011 3:41:43 PM - System Checkpoint

RP237: 3/3/2011 4:19:37 PM - System Checkpoint

RP238: 3/4/2011 4:52:26 PM - System Checkpoint

RP239: 3/6/2011 9:42:22 PM - Installed iTunes

RP240: 3/8/2011 6:34:01 PM - System Checkpoint

RP241: 3/8/2011 10:19:50 PM - Software Distribution Service 3.0

RP242: 3/10/2011 8:23:50 AM - System Checkpoint

RP243: 3/11/2011 5:15:20 PM - System Checkpoint

RP244: 3/12/2011 7:47:04 PM - System Checkpoint

RP245: 3/13/2011 9:06:18 PM - System Checkpoint

RP246: 3/15/2011 12:21:22 PM - System Checkpoint

RP247: 3/16/2011 12:24:17 PM - System Checkpoint

RP248: 3/17/2011 2:50:22 PM - System Checkpoint

RP249: 3/18/2011 4:32:57 PM - System Checkpoint

RP250: 3/19/2011 4:49:33 PM - System Checkpoint

RP251: 3/20/2011 5:36:45 PM - System Checkpoint

RP252: 3/21/2011 6:18:08 PM - System Checkpoint

RP253: 3/22/2011 6:24:46 PM - System Checkpoint

RP254: 3/23/2011 6:29:18 PM - System Checkpoint

RP255: 3/24/2011 11:05:35 AM - Software Distribution Service 3.0

RP256: 3/25/2011 4:15:21 PM - System Checkpoint

RP257: 3/28/2011 1:29:41 PM - System Checkpoint

RP258: 3/29/2011 3:11:47 PM - System Checkpoint

RP259: 3/30/2011 3:57:41 PM - System Checkpoint

RP260: 3/30/2011 10:36:03 PM - Installed HiJackThis

RP261: 4/1/2011 4:58:38 PM - System Checkpoint

RP262: 4/2/2011 5:01:33 PM - System Checkpoint

RP263: 4/3/2011 5:07:29 PM - System Checkpoint

RP264: 4/4/2011 5:21:53 PM - System Checkpoint

RP265: 4/5/2011 6:08:37 PM - System Checkpoint

RP266: 4/6/2011 7:09:53 PM - System Checkpoint

RP267: 4/7/2011 8:15:31 PM - System Checkpoint

RP268: 4/8/2011 7:46:12 PM - Removed Adobe Reader X (10.0.1).

.

==== Installed Programs ======================

.

123 Free Solitaire

924PLC32

ABBYY FineReader 6.0 Sprint

Acrobat.com

Adobe Photoshop 7.0

AOLIcon

Apple Application Support

Apple Mobile Device Support

Apple Software Update

Avira AntiVir Personal - Free Antivirus

Blaze Audio RipEditBurn 2

Blaze Audio Wave Breaker

Bonjour

BufferChm

CameraDrivers

Canon Camera Access Library

Canon Camera Support Core Library

CANON iMAGE GATEWAY Task for ZoomBrowser EX

Canon Internet Library for ZoomBrowser EX

Canon MOV Decoder

Canon MovieEdit Task for ZoomBrowser EX

Canon PhotoRecord

Canon RAW Image Task for ZoomBrowser EX

Canon Utilities CameraWindow

Canon Utilities CameraWindow DC

Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX

Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX

Canon Utilities Digital Photo Professional 3.5

Canon Utilities EOS Utility

Canon Utilities MyCamera

Canon Utilities MyCamera DC

Canon Utilities PhotoStitch

Canon Utilities RemoteCapture DC

Canon Utilities RemoteCapture Task for ZoomBrowser EX

Canon Utilities ZoomBrowser EX

Canon ZoomBrowser EX Memory Card Utility

CCleaner

Compatibility Pack for the 2007 Office system

Create and Print Greeting Cards 1.0

CreativeProjects

CreativeProjectsTemplates

CueTour

Dell Digital Jukebox Driver

Dell Driver Download Manager

Dell Driver Download Manager - 1

Dell Driver Reset Tool

Dell Game Console

Dell Photo AIO Printer 924

Dell Support 3.1

Dell System Restore

DellConnect

Destinations

Digital Content Portal

Director

DVD Flick 1.3.0.7

EducateU

Google AFE

Google Desktop

Google Toolbar for Internet Explorer

Google Update Helper

Google Updater

HiJackThis

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Hotfix for Windows Internet Explorer 7 (KB947864)

Hotfix for Windows XP (KB954550-v5)

HP Image Zone 4.5

HP Photosmart Cameras 4.5

HP Product Assistant

HP Software Update

HPSystemDiagnostics

ImgBurn

InstantShare

Intel(R) 537EP V9x DF PCI Modem

Intel(R) Graphics Media Accelerator Driver

Intel(R) PRO Network Connections Drivers

Intel(R) PROSet for Wired Connections

iPod for Windows 2005-09-23

iTunes

Jasc Paint Shop Pro Studio GDI+ Patch

Jasc Paint Shop Pro Studio, Dell Editon

Jasc Paint Shop Pro Studio.01 , Dell Edition Patch

Java Auto Updater

Java(TM) 6 Update 24

Learn2 Player (Uninstall Only)

Malwarebytes' Anti-Malware

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2416447)

Microsoft .NET Framework 1.1 Security Update (KB979906)

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft Greetings 2001

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Office 2003 Web Components

Microsoft Office Basic Edition 2003

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office XP Web Components

Microsoft Picture It! Photo Premium 9

Microsoft Plus! Digital Media Edition Installer

Microsoft Plus! Photo Story 2 LE

Microsoft Silverlight

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Works

Microsoft Works 2004 Setup Launcher

Modem Event Monitor

Modem Helper

Modem On Hold

Move Media Player

MovieEdit Task

Mozilla Firefox 4.0 (x86 en-US)

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Musicmatch for Windows Media Player

Musicmatch® Jukebox

OE-Mail Recovery 1.7

Otto

PanoStandAlone

PhotoGallery

PowerDVD 5.3

QFolder

QuickTime

RAW Image Task 1.2

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.1

Repair Tool for Outlook Express v.1.7.0

Secunia PSI (2.0.0.3001)

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)

Security Update for Windows Internet Explorer 7 (KB928090)

Security Update for Windows Internet Explorer 7 (KB929969)

Security Update for Windows Internet Explorer 7 (KB931768)

Security Update for Windows Internet Explorer 7 (KB933566)

Security Update for Windows Internet Explorer 7 (KB937143)

Security Update for Windows Internet Explorer 7 (KB938127)

Security Update for Windows Internet Explorer 7 (KB939653)

Security Update for Windows Internet Explorer 7 (KB942615)

Security Update for Windows Internet Explorer 7 (KB944533)

Security Update for Windows Internet Explorer 7 (KB950759)

Security Update for Windows Internet Explorer 7 (KB953838)

Security Update for Windows Internet Explorer 7 (KB956390)

Security Update for Windows Internet Explorer 7 (KB958215)

Security Update for Windows Internet Explorer 7 (KB960714)

Security Update for Windows Internet Explorer 7 (KB961260)

Security Update for Windows Internet Explorer 7 (KB963027)

Security Update for Windows Internet Explorer 8 (KB2183461)

Security Update for Windows Internet Explorer 8 (KB2360131)

Security Update for Windows Internet Explorer 8 (KB2416400)

Security Update for Windows Internet Explorer 8 (KB2482017)

Security Update for Windows Internet Explorer 8 (KB971961)

Security Update for Windows Internet Explorer 8 (KB981332)

Security Update for Windows Internet Explorer 8 (KB982381)

Security Update for Windows Media Player 6.4 (KB925398)

Security Update for Windows XP (KB923689)

ShareIns

Shockwave

SkinsHP1

Sonic Audio module

Sonic Copy Module

Sonic Data Module

Sonic DLA

Sonic Encoders

Sonic Express Labeler

Sonic MyDVD

Sonic RecordNow!

Sonic Update Manager

SpywareBlaster 4.4

TrayApp

Unload

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Windows Internet Explorer 8 (KB976662)

Update for Windows Internet Explorer 8 (KB982632)

Visual C++ 2008 x86 Runtime - (v9.0.30729)

Visual C++ 2008 x86 Runtime - v9.0.30729.01

Voyetra Record Producer

Watchtower Library 2010 - English

WebCyberCoach 3.2 Dell

WebFldrs XP

WebReg

WildTangent Web Driver

Windows Genuine Advantage Notifications (KB905474)

Windows Genuine Advantage v1.3.0254.0

Windows Genuine Advantage Validation Tool (KB892130)

Windows Internet Explorer 7

Windows Internet Explorer 8

Windows Management Framework Core

Windows Media Format 11 runtime

Windows Media Player 10

Windows Media Player 11

Windows XP Service Pack 3

.

==== Event Viewer Messages From Past Week ========

.

4/8/2011 8:58:33 AM, error: DCOM [10005]  - DCOM got error "%1058" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

4/8/2011 2:57:53 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Lbd

.

==== End Of File ===========================

 

Thanks..............:emotion-11:

62 Posts

April 11th, 2011 08:00

K27,

          A very strange problem indeed! Yes, everything shows that Secunia is installed on my desktop, but when attempting to open it by any means, a page that is completely white will flash open for about a second. The only thing on this page, in the upper left hand corner, is 'Secunia PSI'. The page the disappears and I'm back to whatever I had open or my desktop if nothing was open when I tried to open Secunia.

          I noticed the following in my DDS scans and was wondering if there is any need for concern over these things:

Normal 0 false false false MicrosoftInternetExplorer4

BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File

Normal 0 false false false MicrosoftInternetExplorer4

SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File

Also:

Normal 0 false false false MicrosoftInternetExplorer4

4/8/2011 8:58:33 AM, error: DCOM [10005]  - DCOM got error "%1058" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

4/8/2011 2:57:53 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Lbd

Of course, anything I ask is just guesswork. Would a System Restore be in order?

Thanks :emotion-44:

 

 

62 Posts

April 11th, 2011 11:00

K27,

          Sorry to answer my own post, (see above) but in that response, I did not put "Normal 0 false false false MicrosoftInternetExplorer4" in the dialogue.

I don't know how that came to be in it three times. It was not there when I sent it.!!!!!

Thanks :emotion-40:

2 Intern

 • 

1.5K Posts

April 12th, 2011 06:00

Hi,

The "Normal 0 false" seems to be something happening with the forum software as some of my other thread have the same lines in them. It always seems to be when something has been copied and pasted to the reply.

The left overs are from Adobe Reader and SuperAntiSpyware, nether of them would stop the program opening.

The errors at the bottom of the log are very common and are nothing to worry about.

I would like you to please post a new topic at the Secunia Forum stating the exact problem and posting them a link to this thread so they can see what we have done. Thye should be able to get this sorted a lot quicker that I could.

I will leave this thread open for a few days until you reply telling me that the problem is solved or still the same. Then we will remove the tools we used.

Thanks.

62 Posts

April 12th, 2011 11:00

K27,

           Yes, I did copy and used 'control v' to add parts to my response when the '...false false false...' words were added.

           I never remember having "SuperAntiSpyware" installed on my desktop.

           I want you to know how much I appreciate your time and efforts to help me. It's a very kind service for novices such as me. I'm hoping I followed all your instructions and did not do anything, or miss any steps to cause this outcome.

           1) Could you please tell me the name of the forum topic you wish me to post to. (I know this forum is the Malware Removal Forum.)

           2) And could you please tell me how to 'post a link to this thread.'

           3) I just received a notice that  Windows Updates are ready for downloading. Should I go ahead with that or wait till all is well?

Again, many thanks for all you did for me especially all the 'extra' questions I had. I will post the outcome or an update as soon as possible. :emotion-21: :emotion-2:

62 Posts

April 13th, 2011 19:00

K27,

Sorry once more for answering my own post but I wanted to share this with you:

MISSION ACCOMPLISHED ! :emotion-22:          Normal 0 false false false MicrosoftInternetExplorer4

Look at Trezac's 2nd post here: http://secunia.com/community/forum/thread/show/8073/install_error_opening_sua_exe

"The PSI process was still running from the previous time I opened it. I ended the process in Task Manager, and then the install ran ok.

Incidentally, I'm running XP and did have to "Turn off advanced text services" so the PSI window would stay visible." :emotion-15:

I did this and Voila!! A Victory (for now) for us die-hards!

Once again, Thank You for all your time, services, energy and advice. :emotion-21:



2 Intern

 • 

1.5K Posts

April 15th, 2011 00:00

Hi,

Sorry for not replying sooner, its been manic for me of late. Good work on getting it dealt with, and thank you for letting me know.

Now we clean up and remove the tools.

 

Your logs now appear to be clean and your system is running to a satisfactory standard. We have some housekeeping to do which I will post the instructions for now. This will be follow by some general advice for how to maintain the system and how to minimize the chances of this happening in the future.

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall
Note the space between Combofix and /

 

 

Please uninstall the other programs we used as without proper guidance they can seriously harm the workings of Windows and your PC

  • HiJackThis via Add/Remove Programs in control Panel
  • You may also delete any logs that you have saved from the above tools

 

You can also then delete the non invasive DDS program and the two logs it created on your desktop by right click each file and then click delete.

.


  • Adobe Acrobat/Reader can be reinstalled from HERE (NOTE: On the Download page, please make sure to uncheck the box next to the "McAfee Scan" item as it is not needed)
    Once you have the latest version of Adobe Reader installed, please uninstall all outdated version that remain in the add/Remove programs list on your system in control panel.

  •  

    Now some advice on how to surf safe in the future.

    ALWAYS keep all programs on your PC up to date and this especially means your Anti-Virus/Anti-Spyware/Firewall/Java and Adobe programs.
    They can all be found via the "All Programs" feature in the start menu and if opened will 100% have a update feature somewhere.
    NEVER use more than ONE Anti-Virus program,
    NEVER use more than ONE resident Full time Anti-Spyware program,
    NEVER use more than ONE Software Firewall,(and never use the Windows built in Firewall as it will not keep you protected)

    As more than one of each of these will conflict with each other and leave you just as vunrable as not having them.
    You can get some VERY GOOD FREE ones from HERE

    Its always a good idea to back these up with SpywareBlaster as this will run in the background and not conflict with any of your other Security.

    Also give WinPatrol a try as it is a very good program that will inform you of any changes being made to your system in the same way that User Account Control does but better, (DO NOT switch off UAC if you install WinPatrol, it is still very much needed)

    Research and consider using a HARDWARE Firewall as this will provide a very good extra layer of protection.

    Scan with each piece of your security Daily and at the very least two daily.
    Always keep a few on-demand scanners on your machine and use them every other day, such as,

     

     

    If you use IE then consider using a more secure browser such as FireFox or Opera

    Install all the latest Windows updates from HERE
    or by clicking start>all programs>Windows update, and keep going back and doing these untill you have all the avalible updates untill none are showing.
    Its a good idea to set Windows Update to automatic so as not to miss any Important updates.

    Always you a site advisor such as WOT to confirm the sites you are using are really the sites they say they are.
    There is a version of WOT avalible for both IE and FIreFox.

    Downloading and installing Secunia PSI will keep the system fully updated.
    It runs quietly in the background and will give a balloon pop-up from the task bar each time a program needs updating. Just click the Secunia task bar icon and the program will open. You will then see a list of the program(s) that needs updating, click the blue circle under the "Solution" heading, and you will be taken directly to the download for the exploited program.

    And please read these links for adivce on Computer Security:
    Infection Prevention
    Do's and Don't's of Security Programs
    Anti-Virus Programs Explained

    If you have any other questions then please fill free to post back,
    I will mark this thread as solved tomorrow,

    Safe Surfing,
    K27.

62 Posts

April 15th, 2011 20:00

K27,

          All is well. I now have Super Anti Spyware, Avira Antivir, Malwarebytes, CCleaner, Spyware Blaster, Win Patrol and Outpost Firewall.

          Will these all run in harmony with each other? So far so good. I just don't know how to update Win Patrol and Outpost Firewall.

          Win Patrol will take me a while to understand just what it's doing and I can't seem to find a way to update it.

          Outpost Firewall has an update button but it's only good for upgrading to their Pro product.

          Do these indeed need updating? Did I miss something?

          If you can share the secret to updating these two downloads with me, I think I'm good to go!

          In case I miss it before you close this thread, Thank you again and again for your time, effort, patience and the fact that you care to help others!

          :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2: :emotion-1: :emotion-2:

2 Intern

 • 

1.5K Posts

April 17th, 2011 07:00

Hi,

You are more than welcome.

Did you install just the Outpost Firewall or the Free Outpost security suite as the free Security suite comes bundled with an AV and that will not bode well with Avira.

 

As for updating Winpatrol, You need to start the program, click the "Plus" tab and then in the bottom left corner is a button marked "Check for new Winpatrol Version", click that button and it will take you to the Winpatrol site where you will see the version you have installed and the current version. If the current version number is higher than yours, then just download and run the new installer. That will upgrade your version to the latest version. You can find tutorials and info for using WinPatrol HERE

 

Let me know about Outpost and I will let you know if you need to remove it (free security suite). If you just have the Firewall, which I am not sure they do anymore, I will try and find a download and get the instructions for you.

Thanks.

62 Posts

April 17th, 2011 08:00

K27,

I have just the Outpost Firewall v.192.168.0.100

It even has an add on the front page encouraging me to change it to Outpost Security Suite Free 7.1. Thanks to you, I know not to do that!

I found the location to update Winpatrol too, thanks to your eagle eye. And thanks as well for the tutorials.

What more can I say. You saved my computer from becoming another casualty. I am up and running so well that I have made a Restore Point named K27....:emotion-2:

Maybe we'll name our next cat - K27 !

Sincerely, thank you from the bottom of my motherboard and thanks to your whole team of selfless helpers who really do make a difference.

It's inevitable that I'll be back some day, but it's an experience that I really don't mind because I'm leaning something very useful.

I'll land this plane now with one last THANK YOU K27 !!!         :emotion-21:            :emotion-2:

2 Intern

 • 

1.5K Posts

April 17th, 2011 09:00

You are most Welcome :emotion-21:

I am in the middle of a major work project and can not take the risk of installing outpost and it crashing my system or rebooting it without my say so.

Give me a day or so and I will let you know how to update the firewall.

 

0 events found

No Events found!

Top