EXCEL用Foxit Reader PDF Printer转PDF 为什么pdf转word出现乱码GDI windows错误

WIN7系统中EXCEL转PDF的软件?求高手指点。_百度知道
WIN7系统中EXCEL转PDF的软件?求高手指点。
的是WIN7家庭版。我装了07版的OFFICE. WORD可以直接点另存转成PDF,但是EXCEL的就不行
我有更好的答案
百度搜索“教你一招pdf转换成word或txt★作图”
很简单,去安装一个 PDF creator,然后打印,选择打印机是 PDF CREATOR,跟平时打印差不多,打印输出的就是PDF文件
系统不行,我以前也是,我用PDF和CAD时也不行,后来换了系统,就行了
这是说你打印机的问题和PDF有什么关系
你可以试试这个
foxitReader-seutp PDF
其他3条回答
为您推荐:
其他类似问题
win7系统的相关知识
换一换
回答问题,赢新手礼包
个人、企业类
违法有害信息,请在下方选择后提交
色情、暴力
我们会通过消息、邮箱等方式尽快将举报结果通知您。Excel表格转成PDF后,PDF页面空白是怎么回事_百度知道
Excel表格转成PDF后,PDF页面空白是怎么回事
我有更好的答案
转换为PDF的时候,在选择保存位置和名字的时候,有个“选项”,你点开就可以选择把哪几页转换
采纳率:17%
<img class="ikqb_img" src="http;3、文件有可能是加密文件.baidu;4、字体不兼容。以上原因都是可能导致PDF空白页面的原因。其实进行文件之间的转换可以在网页上进行转换excel文件转换成pdf后,页面空白原因可能有:1.hiphotos.baidu.com/zhidao/wh%3D600%2C800/sign=f6f57abd104c510fae91ea1cbb051fcb4bf140ed2e738bd4e633
如果还是这样就不一定是字体兼容性的问题了。
31、在转换之前,认真在excel中检查打印区域是否设置好,再预览,转换后就会出现页面空白,没问题了最后再打印。将你需要打印的内容选中,然后点【文件】【打印区域】【设置打印区域】。
2、也可能是字体不兼容,打开pdf 格式的文件没有正常显示,可以考虑再下载个绿色版的foxit pdf reader尝试打开检查一下,打印区域没有设置好
本回答被提问者采纳
1条折叠回答
为您推荐:
其他类似问题
您可能关注的内容
excel表格的相关知识
&#xe675;换一换
回答问题,赢新手礼包&#xe6b9;
个人、企业类
违法有害信息,请在下方选择后提交
色情、暴力
我们会通过消息、邮箱等方式尽快将举报结果通知您。Javascript Disabled Detected
You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.
Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
or read our
to learn how to use this site.
Latest News:&&&
Featured Deal:
Password Changing On Its Own
Started by
ihopeidonthavearkit
This topic is locked
40 replies to this topic
ihopeidonthavearkit
Recently when waking my desktop from sleep I cannot log into my main profile. I find that my password has been changed. I usually go into the other accounts on the desktop and change my profile's password into something that I know. I am not sure if my PC is infected with a virus. Here is my DDS log.
DDS (Ver_.01) - NTFS_x86&#160;
Internet Explorer: 8.0. &#160;BrowserJavaVersion: 10.25.2
Run by Chris at 21:00:54 on
Microsoft Windows XP Professional &#160;5.1.2.1.2.1684 [GMT -7:00]
AV: AVG AntiVirus 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF432-AEDE-D861FCBCFCDF}
============== Running Processes ================
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
e:\Program Files\GNU\GnuPG\dirmngr.exe
C:\Program Files\Java\jre7\bin\jqs.exe
E:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
E:\Program Files\NMapWin\bin\nmapserv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
H:\Zune\ZuneBusEnum.exe
H:\Zune\ZuneNss.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
H:\Zune\ZuneLauncher.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Mindjet\MindManager 10\MMReminderService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Documents and Settings\Chris\Application Data\Spotify\Data\SpotifyWebHelper.exe
C:\Documents and Settings\Chris\Application Data\Traffic Travis v4\TrafficTravisV4.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Chris\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files\Evernote\Evernote\Evernote.exe
C:\Program Files\Evernote\Evernote\EvernoteTray.exe
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
e:\Program Files\GNU\GnuPG\bin\dbus-daemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris\Application Data\Juniper Networks\Setup Client\JuniperSetupClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG2013\Tuneup\TUMICR~1.EXE
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: &Yahoo! Toolbar Helper: {F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {62-4905-BF09-} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: {5C255C8A-E604-49b4-9D64-CECB} - &orphaned&
BHO: CmjBrowserHelperObject Object: {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll
BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {C02-4ABF-8ECC-C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java&#153; Plug-In 2 SSV Helper: {DBC85b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -&#160;
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
EB: {a0-441b-a342-7c2a440a9478} - &orphaned&
EB: HP Smart Web Printing: {555D4D79-4BD2--CFC} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Aim6] &no file&
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_5_502_135_ActiveX.exe -update activex
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [DXDllRegExe] c:\windows\system32\dxdllreg.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [zBrowser Launcher] e:\program files\logitech\itouch\iTouch.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [Zune Launcher] "h:\zune\ZuneLauncher.exe"
mRun: [KeePass 2 PreLoad] "e:\program files\keepass password safe 2\KeePass.exe" --preload
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Synergy] C:/Program Files/Synergy/synergy.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MMReminderService] c:\program files\mindjet\mindmanager 10\MMReminderService.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\chris\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\hipchat.lnk - c:\program files\hipchat\HipChat.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\rainme~1.lnk - c:\program files\rainmeter\Rainmeter.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Send Image To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/201
IE: Send Link To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/203
IE: Send Page To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/204
IE: Send Text To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/202
IE: {2F7-4F82-B600-ED77F354B7FF} - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {DDE-48c4-B1AA84522} - {DDE-48c4-B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {e2e2dd38-d088--f2ba} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5Fd2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - e:\program files\plotsoft\pdfill\DownloadPDF.exe
DPF: {166B1BCA-3F9C-11CF-40000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?3
DPF: {6E3D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?5
DPF: {D27CDB6E-AE6D-11CF-96B8-} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FC8-44C2-AC6E-DF} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
DPF: {FD0BA91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=724
TCP: Interfaces\{0254AFCD-D2E2-4BAA-89D6-1FD52FF2DB0A} : NameServer = 208.67.222.222,208.67.220.220
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-0F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: cetihpz - {CF184AD3-CDCB--8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D} - c:\windows\system32\WPDShServiceObj.dll
STS: FencesShlExt Class - {CF-49cd-AB77-18F378FEA264} - c:\program files\fences\FencesMenu.dll
SEH: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\program files\windows defender\MpShHook.dll
mASetup: {90EF4A5E-85DB--1AB93C2A8EEB} - c:\program files\mindjet\mindmanager 10\sys\MmInternetExplorerActiveSetup.vbs
================= FIREFOX ===================
FF - ProfilePath - c:\documents and settings\chris\application data\mozilla\firefox\profiles\bo0n0r1j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\bo0n0r1j.default\extensions\\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\chris\local settings\application data\google\update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files\photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: !HIDDEN!
22:10; {20a8ed-80e3-b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R0 AAVG Logging Dc:\windows\system32\drivers\avglogx.sys [ 246072]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Sc:\windows\system32\drivers\avgmfx86.sys [ 96568]
R0 Avgrkx86;AVG Anti-Rootkit Dc:\windows\system32\drivers\avgrkx86.sys [ 39224]
R0 MpFMicrosoft Malware Protection Dc:\windows\system32\drivers\MpFilter.sys [ 211560]
R1 AVGIDSDAVGIDSDc:\windows\system32\drivers\avgidsdriverx.sys [ 208184]
R1 AVGIDSSAVGIDSSc:\windows\system32\drivers\avgidsshimx.sys [ 22328]
R1 Avgldx86;AVG AVI Loader Dc:\windows\system32\drivers\avgldx86.sys [ 171320]
R1 AAVG TDI Dc:\windows\system32\drivers\avgtdix.sys [ 182072]
R1 MpKsl9c270MpKsl9c270c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cfcdc5-a5ad-8d412d320c8a}\MpKsl9c270fbf.sys [ 29904]
R1 NEOFLTR_710_19525;Juniper Networks TDI Filter Driver (NEOFLTR_710_19525);c:\windows\system32\drivers\NEOFLTR_710_19525.SYS [ 85064]
R2 AVGIDSAAVGIDSAc:\program files\avg\avg2013\avgidsagent.exe [ 4939312]
R2AVG WatchDc:\program files\avg\avg2013\avgwdsvc.exe [ 283136]
R2 DirMDirMe:\program files\gnu\gnupg\dirmngr.exe [ 242176]
R2 KodakDigitalDisplaySKodakDigitalDisplaySe:\program files\kodak\digital display\orbkodaklauncher\DllStartupService.exe [ 98304]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [ 10384]
R2 LMIGuardianSLMIGuardianSc:\program files\logmein\x86\LMIGuardianSvc.exe [ 374704]
R2 LMIILogMeIn Kernel Information Pc:\program files\logmein\x86\rainfo.sys [ 12856]
R2 LMIRfsDLogMeIn Remote File System Dc:\windows\system32\drivers\LMIRfsDriver.sys [ 47640]
R2 Skype C2C SSkype C2C Sc:\documents and settings\all users\application data\skype\toolbars\skype c2c service\c2c_service.exe [ 3291008]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [ 60216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [ 130384]
S2 OpenSSHSOpenssh SSHD;e:\program files\icw\bin\cygrunsrv.exe [ 68096]
S2 SkypeUSkype Uc:\program files\skype\updater\Updater.exe [ 161536]
S2 WinDWindows Dc:\program files\windows defender\MsMpEng.exe [ 13592]
S3 cpuz135;cpuz135;c:\program files\pc wizard 2012\pcwiz_x32.sys [ 24328]
S3c:\windows\system32\epmntdrv.sys [ 13192]
S3 EuGdiDEuGdiDc:\windows\system32\EuGdiDrv.sys [ 8456]
S3 LEqdULogitech SetPoint Unifying KMDF USB Fc:\windows\system32\drivers\LEqdUsb.sys [ 40720]
S3 LHidELogitech SetPoint Unifying KMDF HID Fc:\windows\system32\drivers\LHidEqd.sys [ 10384]
S3 McComponentHostSMcAfee Security Scan Component Host S"c:\program files\mcafee security scan\2.1.121\mcchsvc.exe" --& c:\program files\mcafee security scan\2.1.121\McCHSvc.exe [?]
S3 NPF;NetGroup Packet Filter Dc:\windows\system32\drivers\npf.sys [ 32528]
S3 TNET WLAN;c:\windows\system32\drivers\TNET1130.sys [ 438912]
S3 WefiEngSWeFi Engine Sc:\program files\wefi\WefiEngSvc.exe [ 140632]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [ 754856]
S4 Apache2.2;Apache2.2;e:\program files\apache software foundation\apache2.2\bin\httpd.exe [ 24645]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
=============== File Associations ===============
FileExt: .js: jsfile="e:\program files\adobe\adobe dreamweaver cs3\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="e:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe", "%1"
ShellExec: Foxit Reader.exe: print="e:\program files\foxit software\foxit reader\Foxit Reader.exe"/p "%1"&#160;
ShellExec: Foxit Reader.exe: printto="e:\program files\foxit software\foxit reader\Foxit Reader.exe"/t "%1" "%2" "%3" "%4"&#160;
ShellExec: FOXITR~1.EXE: print="e:\progra~1\foxits~1\foxitr~1\FOXITR~1.EXE"/p "%1"&#160;
ShellExec: FOXITR~1.EXE: printto="e:\progra~1\foxits~1\foxitr~1\FOXITR~1.EXE"/t "%1" "%2" "%3" "%4"&#160;
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office10\FRONTPG.EXE
=============== Created Last 30 ================
21:43:30 -------- d-----w- c:\documents and settings\chris\application data\AVG2013
21:42:36 -------- d-----w- c:\documents and settings\chris\application data\TuneUp Software
21:42:17 -------- d--h--w- C:\$AVG
21:42:17 -------- d-----w- c:\documents and settings\all users\application data\AVG2013
21:41:29 -------- d-----w- c:\program files\AVG
21:40:14 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
21:40:14 -------- d-----w- c:\documents and settings\chris\local settings\application data\MFAData
21:40:14 -------- d-----w- c:\documents and settings\chris\local settings\application data\Avg2013
21:40:14 -------- d-----w- c:\documents and settings\all users\application data\MFAData
21:11:50 60872 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cfcdc5-a5ad-8d412d320c8a}\offreg.dll
21:11:50 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cfcdc5-a5ad-8d412d320c8a}\MpKsl9c270fbf.sys
21:04:14 7166848 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cfcdc5-a5ad-8d412d320c8a}\mpengine.dll
21:02:23 -------- d-----w- c:\program files\Microsoft Security Client
14:24:16 7166848 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{a95d45-a83a-9b80eee548e9}\mpengine.dll
05:22:30 -------- d-----w- c:\windows\Performance
05:22:26 -------- d-----w- c:\documents and settings\chris\local settings\application data\Microsoft Corporation
05:12:37 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
10:10:56 -------- d-----w- c:\windows\system32\MRT
00:26:35 -------- d-----w- c:\program files\MSECache
00:21:09 85064 ----a-w- c:\windows\system32\drivers\NEOFLTR_710_19525.SYS
00:21:09 -------- d-----w- c:\program files\Juniper Networks
18:11:04 4774272 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
==================== Find3M &#160;====================
21:18:38 1543680 ------w- c:\windows\system32\wmvdecod.dll
02:47:17 920064 ----a-w- c:\windows\system32\wininet.dll
02:47:13 43520 ------w- c:\windows\system32\licmgr10.dll
02:47:12 1469440 ------w- c:\windows\system32\inetcpl.cpl
15:52:59 385024 ------w- c:\windows\system32\html.iec
08:51:00 246072 ----a-w- c:\windows\system32\drivers\avglogx.sys
08:50:56 60216 ----a-w- c:\windows\system32\drivers\avgidshx.sys
08:50:56 208184 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
08:50:50 171320 ----a-w- c:\windows\system32\drivers\avgldx86.sys
19:19:53 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
19:19:52 867240 ----a-w- c:\windows\system32\npdeployJava1.dll
19:19:52 789416 ----a-w- c:\windows\system32\deployJava1.dll
19:19:52 144896 ----a-w- c:\windows\system32\javacpl.cpl
10:37:53 406016 ----a-w- c:\windows\system32\usp10.dll
08:32:40 39224 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
03:03:25 2149888 ------w- c:\windows\system32\ntoskrnl.exe
02:08:30 2028544 ------w- c:\windows\system32\ntkrnlpa.exe
04:50:08 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys
06:40:23 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
06:40:23 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
07:23:02 562688 ------w- c:\windows\system32\qedit.dll
01:40:45 1876736 ------w- c:\windows\system32\win32k.sys
20:12:16 2279464 ----a-w- c:\program files\PcSetup.exe
============= FINISH: 21:06:23.78 ===============
Back to top
BC AdBot (Login to Remove)
Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK &&&
&&& CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.Please do this even if you have previously posted logs for us.If you were unable to produce the logs originally please try once more.If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.If you are unsure about any of these characteristics just post what you can and we will guide you.Please tell us if you have your original Windows CD/DVD available. Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.
Thank you for your patience, and again sorry for the delay.
***************************************************
We need to see some information about what is happening in your machine. Please perform the following scan again: Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.Double click on the DDS icon, allow it to run. A small box will open, with an explanation about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that pop up for posting the results. Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control can be found .As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!
Back to top
ihopeidonthavearkit
Recently when waking my desktop from sleep I cannot log into my main profile. I find that my password has been changed. I usually go into the other accounts on the desktop and change my profile's password into something that I know. I am not sure if my PC is infected with a virus. Here is my DDS log.
Here is a new DDS scan.
DDS (Ver_.01) - NTFS_x86
Internet Explorer: 8.0.&#160; BrowserJavaVersion: 10.25.2
Run by Chris at 2:19:30 on
Microsoft Windows XP Professional&#160; 5.1.2.1.2.1896 [GMT -7:00]
AV: AVG AntiVirus 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF432-AEDE-D861FCBCFCDF}
============== Running Processes ================
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
e:\Program Files\GNU\GnuPG\dirmngr.exe
C:\Program Files\Java\jre7\bin\jqs.exe
E:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
E:\Program Files\NMapWin\bin\nmapserv.exe
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Windows Media Player\WMPNetwk.exe
H:\Zune\ZuneBusEnum.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
E:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
H:\Zune\ZuneLauncher.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Mindjet\MindManager 10\MMReminderService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Chris\Application Data\Spotify\Data\SpotifyWebHelper.exe
C:\Documents and Settings\Chris\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Evernote\Evernote\Evernote.exe
C:\Program Files\Evernote\Evernote\EvernoteTray.exe
H:\Zune\ZuneNss.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris\Application Data\Juniper Networks\Setup Client\JuniperSetupClient.exe
C:\PROGRA~1\AVG\AVG2013\Tuneup\TUMICR~1.EXE
C:\WINDOWS\system32\wuauclt.exe
E:\Program Files\KeePass Password Safe 2\KeePass.exe
E:\Program Files\Mozilla Firefox6\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: &Yahoo! Toolbar Helper: {F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {62-4905-BF09-} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: CmjBrowserHelperObject Object: {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll
BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {C02-4ABF-8ECC-C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java&#153; Plug-In 2 SSV Helper: {DBC85b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {D4A-4066-A1AD-} - c:\program files\ask.com\GenericAskToolbar.dll
EB: {a0-441b-a342-7c2a440a9478} - &orphaned&
EB: HP Smart Web Printing: {555D4D79-4BD2--CFC} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\chris\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Spotify Web Helper] "c:\documents and settings\chris\application data\spotify\data\SpotifyWebHelper.exe"
uRun: [TrafficTravisv4] c:\documents and settings\chris\application data\traffic travis v4\TrafficTravisV4.exe
uRun: [Spotify] "c:\documents and settings\chris\application data\spotify\Spotify.exe" /uri spotify:autostart
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [zBrowser Launcher] e:\program files\logitech\itouch\iTouch.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [Zune Launcher] "h:\zune\ZuneLauncher.exe"
mRun: [KeePass 2 PreLoad] "e:\program files\keepass password safe 2\KeePass.exe" --preload
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MMReminderService] c:\program files\mindjet\mindmanager 10\MMReminderService.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\chris\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\rainme~1.lnk - c:\program files\rainmeter\Rainmeter.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Send Image To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/201
IE: Send Link To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/203
IE: Send Page To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/204
IE: Send Text To MindManager - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll/202
IE: {2F7-4F82-B600-ED77F354B7FF} - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - c:\program files\mindjet\mindmanager 10\Mm8InternetExplorer.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {DDE-48c4-B1AA84522} - {DDE-48c4-B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {e2e2dd38-d088--f2ba} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5Fd2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - e:\program files\plotsoft\pdfill\DownloadPDF.exe
DPF: {166B1BCA-3F9C-11CF-40000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?3
DPF: {6E3D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?5
DPF: {D27CDB6E-AE6D-11CF-96B8-} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FC8-44C2-AC6E-DF} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
DPF: {FD0BA91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=724
TCP: Interfaces\{0254AFCD-D2E2-4BAA-89D6-1FD52FF2DB0A} : NameServer = 208.67.222.222,208.67.220.220
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-0F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: cetihpz - {CF184AD3-CDCB--8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D} - c:\windows\system32\WPDShServiceObj.dll
STS: FencesShlExt Class - {CF-49cd-AB77-18F378FEA264} - c:\program files\fences\FencesMenu.dll
SEH: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\program files\windows defender\MpShHook.dll
mASetup: {90EF4A5E-85DB--1AB93C2A8EEB} - c:\program files\mindjet\mindmanager 10\sys\MmInternetExplorerActiveSetup.vbs
================= FIREFOX ===================
FF - ProfilePath - c:\documents and settings\chris\application data\mozilla\firefox\profiles\bo0n0r1j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\bo0n0r1j.default\extensions\\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\chris\local settings\application data\google\update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files\photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: !HIDDEN!
22:10; {20a8ed-80e3-b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [ 60216]
R0 AAVG Logging Dc:\windows\system32\drivers\avglogx.sys [ 246072]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Sc:\windows\system32\drivers\avgmfx86.sys [ 96568]
R0 Avgrkx86;AVG Anti-Rootkit Dc:\windows\system32\drivers\avgrkx86.sys [ 39224]
R0 MpFMicrosoft Malware Protection Dc:\windows\system32\drivers\MpFilter.sys [ 211560]
R1 AVGIDSDAVGIDSDc:\windows\system32\drivers\avgidsdriverx.sys [ 208184]
R1 AVGIDSSAVGIDSSc:\windows\system32\drivers\avgidsshimx.sys [ 22328]
R1 Avgldx86;AVG AVI Loader Dc:\windows\system32\drivers\avgldx86.sys [ 171320]
R1 AAVG TDI Dc:\windows\system32\drivers\avgtdix.sys [ 182072]
R1 NEOFLTR_650_15255;Juniper Networks TDI Filter Driver (NEOFLTR_650_15255);c:\windows\system32\drivers\NEOFLTR_650_15255.SYS [ 85360]
R2 AVGIDSAAVGIDSAc:\program files\avg\avg2013\avgidsagent.exe [ 4939312]
R2AVG WatchDc:\program files\avg\avg2013\avgwdsvc.exe [ 283136]
R2 DirMDirMe:\program files\gnu\gnupg\dirmngr.exe [ 242176]
R2 KodakDigitalDisplaySKodakDigitalDisplaySe:\program files\kodak\digital display\orbkodaklauncher\DllStartupService.exe [ 98304]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [ 10384]
R2 LMIGuardianSLMIGuardianSc:\program files\logmein\x86\LMIGuardianSvc.exe [ 374704]
R2 LMIILogMeIn Kernel Information Pc:\program files\logmein\x86\rainfo.sys [ 12856]
R2 LMIRfsDLogMeIn Remote File System Dc:\windows\system32\drivers\LMIRfsDriver.sys [ 47640]
R2 Skype C2C SSkype C2C Sc:\documents and settings\all users\application data\skype\toolbars\skype c2c service\c2c_service.exe [ 3291008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [ 130384]
S2 OpenSSHSOpenssh SSHD;e:\program files\icw\bin\cygrunsrv.exe [ 68096]
S2 SkypeUSkype Uc:\program files\skype\updater\Updater.exe [ 161536]
S2 WinDWindows Dc:\program files\windows defender\MsMpEng.exe [ 13592]
S3 cpuz135;cpuz135;c:\program files\pc wizard 2012\pcwiz_x32.sys [ 24328]
S3c:\windows\system32\epmntdrv.sys [ 13192]
S3 EuGdiDEuGdiDc:\windows\system32\EuGdiDrv.sys [ 8456]
S3 LEqdULogitech SetPoint Unifying KMDF USB Fc:\windows\system32\drivers\LEqdUsb.sys [ 40720]
S3 LHidELogitech SetPoint Unifying KMDF HID Fc:\windows\system32\drivers\LHidEqd.sys [ 10384]
S3 NPF;NetGroup Packet Filter Dc:\windows\system32\drivers\npf.sys [ 32528]
S3 TNET WLAN;c:\windows\system32\drivers\TNET1130.sys [ 438912]
S3 WefiEngSWeFi Engine Sc:\program files\wefi\WefiEngSvc.exe [ 140632]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [ 754856]
S4 Apache2.2;Apache2.2;e:\program files\apache software foundation\apache2.2\bin\httpd.exe [ 24645]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
SUnknown McComponentHostSMcComponentHostS [x]
=============== File Associations ===============
FileExt: .js: jsfile="e:\program files\adobe\adobe dreamweaver cs3\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="e:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe", "%1"
ShellExec: Foxit Reader.exe: print="e:\program files\foxit software\foxit reader\Foxit Reader.exe"/p "%1"
ShellExec: Foxit Reader.exe: printto="e:\program files\foxit software\foxit reader\Foxit Reader.exe"/t "%1" "%2" "%3" "%4"
ShellExec: FOXITR~1.EXE: print="e:\progra~1\foxits~1\foxitr~1\FOXITR~1.EXE"/p "%1"
ShellExec: FOXITR~1.EXE: printto="e:\progra~1\foxits~1\foxitr~1\FOXITR~1.EXE"/t "%1" "%2" "%3" "%4"
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office10\FRONTPG.EXE
=============== Created Last 30 ================
09:09:10&#160;&#160; &#160;6;&#160; &#160;----a-w-&#160;&#160; &#160;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8657d98b-aa47-48f9-958c-}\offreg.dll
16:48:19&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8657d98b-aa47-48f9-958c-}\mpengine.dll
16:48:06&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
16:43:13&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\local settings\application data\Ofi Labs
16:00:59&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;C:\Tables
14:14:15&#160;&#160; &#160;8;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\NEOFLTR_650_15255.SYS
21:43:30&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\application data\AVG2013
21:42:36&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\application data\TuneUp Software
21:42:17&#160;&#160; &#160;--------&#160;&#160; &#160;d--h--w-&#160;&#160; &#160;C:\$AVG
21:42:17&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\all users\application data\AVG2013
21:41:29&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\program files\AVG
21:40:14&#160;&#160; &#160;--------&#160;&#160; &#160;d--h--w-&#160;&#160; &#160;c:\documents and settings\all users\application data\Common Files
21:40:14&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\local settings\application data\MFAData
21:40:14&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\local settings\application data\Avg2013
21:40:14&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\all users\application data\MFAData
21:02:23&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\program files\Microsoft Security Client
14:24:16&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{a95d45-a83a-9b80eee548e9}\mpengine.dll
05:22:30&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\windows\Performance
05:22:26&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\documents and settings\chris\local settings\application data\Microsoft Corporation
05:12:37&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\program files\Microsoft Windows 7 Upgrade Advisor
10:10:56&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\windows\system32\MRT
00:26:35&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\program files\MSECache
00:21:09&#160;&#160; &#160;--------&#160;&#160; &#160;d-----w-&#160;&#160; &#160;c:\program files\Juniper Networks
18:11:04&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
==================== Find3M&#160; ====================
21:18:38&#160;&#160; &#160;0;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\wmvdecod.dll
02:47:17&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\wininet.dll
02:47:13&#160;&#160; &#160;4;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\licmgr10.dll
02:47:12&#160;&#160; &#160;0;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\inetcpl.cpl
15:52:59&#160;&#160; &#160;0;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\html.iec
08:51:00&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\avglogx.sys
08:50:56&#160;&#160; &#160;6;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\avgidshx.sys
08:50:56&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\avgidsdriverx.sys
08:50:50&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\avgldx86.sys
19:19:53&#160;&#160; &#160;9;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\WindowsAccessBridge.dll
19:19:52&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\npdeployJava1.dll
19:19:52&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\deployJava1.dll
19:19:52&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\javacpl.cpl
10:37:53&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\usp10.dll
08:32:40&#160;&#160; &#160;3;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\avgrkx86.sys
03:03:25&#160;&#160; &#160;0;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\ntoskrnl.exe
02:08:30&#160;&#160; &#160;0;&#160; &#160;------w-&#160;&#160; &#160;c:\windows\system32\ntkrnlpa.exe
04:50:08&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\windows\system32\drivers\MpFilter.sys
20:12:16&#160;&#160; &#160;0;&#160; &#160;----a-w-&#160;&#160; &#160;c:\program files\PcSetup.exe
============= FINISH:&#160; 2:19:57.64 ===============
Back to top
Oh My&#33;
Greetings ihopeidonthavearkit and
to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.If you would allow me to call you by your first name I would prefer to do that. ===================================================Ground Rules:First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.When you post your reply, use the
button instead.In the upper right hand corner of the topic you will see the
button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.I would like to remind you to make no further changes to your computer unless I direct you to do so.Now let's get started ===================================================Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.Thank you for your patience thus far. Please consider and run these programs for me.===================================================Multiple Antivirus Programs-------------------I do not recommend that you have more than one anti virus product installed
on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.Therefore please remove all but one of the below listed Antivirus programs currently on your computer, even if only one is running. You can do this via Add/Remove Programs, or Programs and Features in the Control Panel.AVG AntiVirus 2013Microsoft Security Essentials===================================================AdwCleaner by Xplode - Delete Adware-------------------Please download
by Xplode onto your desktop.Close all open programs and internet browserDouble click on AdwCleaner.exe, select OK, then RunClick on DeleteConfirm each time with OKYour computer will be rebooted automatically. A text file will open after the restartCopy and paste the contents in your replyYou can find the logfile at C:\AdwCleaner[S1].txt===================================================Junkware Removal Tool by thisisu-------------------Please download
and save it to your desktop.Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on
to see a list of programs that should be disabled. The list is not all inclusive.)Right-mouse click JRT.exe and select Run as administrator (Windows XP double click the icon)Please allow the program time to runOnce completed a Notepad document will open on your desktopCopy and paste the contents in your reply===================================================Farbar Recovery Scan Tool (FRST)--------------------Download Farbar Recover Scan Tool for either
systems and save it to your desktopIf you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one shouldDouble click the iconClick Yes to the disclaimerClick Scan and allow the program to runClick OK on the Scan complete screen, then OK on the Addition.txt pop up screen2 Notepad documents should now be open on your desktop.Please copy and paste the contents of both in your reply===================================================Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. AdwCleaner logJunkware logFRST resultsAddition log
Edited by Oh My, 15 September 2013 - 09:15 AM.
Added instructions
Gary&#160;If I do not reply within 24 hours please send me a ."Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."
Back to top
ihopeidonthavearkit
You can go ahead and call me Chris
Here are my results.
# AdwCleaner v3.004 - Report created 17/09/2013 at 23:45:02
# Updated 15/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Chris - MOMDESK
# Running from : C:\Documents and Settings\Chris\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Viewpoint
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Documents and Settings\Chris\Local Settings\Application Data\apn
Folder Deleted : C:\Documents and Settings\Chris\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Documents and Settings\Chris\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\Chris Trillana\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\bo0n0r1j.default\StumbleUpon
Folder Deleted : C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\bo0n0r1j.default\Extensions\
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E41-4FD3-5E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4A-4066-A1AD-}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-F88}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6CE-486D-B62A-D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A--E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4A-4066-A1AD-}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03F998B2-0E00-11D3-A498-E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEE5C-4ED4-8F7B-F1F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4A-4066-A1AD-}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AEE5C-4ED4-8F7B-F1F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4A-4066-A1AD-}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4A-4066-A1AD-}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4A-4066-A1AD-}]
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Viewpoint
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-FE}
Product Deleted : Ask Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.
-\\ Mozilla Firefox v23.0.1 (en-US)
[ File : C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\bo0n0r1j.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [5854 octets] - [17/09/:26]
AdwCleaner[S0].txt - [5901 octets] - [17/09/:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5961 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.1 (09.15.2013:1)
OS: Microsoft Windows XP x86
Ran by Chris on Wed 09/18/2013 at&#160; 0:02:23.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 09/18/2013 at&#160; 0:10:01.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03
Ran by Chris (administrator) on MOMDESK on 18-09-:25
Running from C:\Documents and Settings\Chris\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
() C:\WINDOWS\system32\Ati2evxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() e:\Program Files\GNU\GnuPG\dirmngr.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Orb Networks, Inc.) E:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
() E:\Program Files\NMapWin\bin\nmapserv.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) H:\Zune\ZuneBusEnum.exe
(Microsoft Corporation) H:\Zune\ZuneNss.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
(Logitech Inc.) E:\Program Files\Logitech\iTouch\iTouch.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
(Microsoft Corporation) H:\Zune\ZuneLauncher.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Mindjet) C:\Program Files\Mindjet\MindManager 10\MMReminderService.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\WMPNSCFG.exe
(Spotify Ltd) C:\Documents and Settings\Chris\Application Data\Spotify\Data\SpotifyWebHelper.exe
(Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
(Mozilla Corporation) E:\Program Files\Mozilla Firefox6\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SigmatelSysTrayApp] - C:\Windows\stsystra.exe [5-03-22] (SigmaTel, Inc.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [6-11-03] (Microsoft Corporation)
HKLM\...\Run: [HP Component Manager] - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [4-05-12] (Hewlett-Packard Company)
HKLM\...\Run: [LogMeIn GUI] - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [-01-11] (LogMeIn, Inc.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [-11-02] (Apple Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [-04-27] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [-06-17] (Logitech, Inc.)
HKLM\...\Run: [zBrowser Launcher] - e:\Program Files\Logitech\iTouch\iTouch.exe [4-03-18] (Logitech Inc.)
HKLM\...\Run: [ATIPTA] - C:\Program Files\ATI Technologies\ATI Control Panel\atiptax}

我要回帖

更多关于 word转pdf出现空白页 的文章

更多推荐

版权声明:文章内容来源于网络,版权归原作者所有,如有侵权请点击这里与我们联系,我们将及时删除。

点击添加站长微信