It has done this 1 time(s). scanning hidden files ... It throws an error every few minutes saying Internet Explorer has encountered a problem and needs to close. aswMBR version Copyright(c) 2011 AVAST Software Run date: 2011-07-13 20:58:34 ----------------------------- 20:58:34.875 OS Version: Windows 5.1.2600 Service Pack 3 20:58:34.875 Number of processors: 2 586 0xF0D 20:58:34.875 ComputerName: BRE-2008COMP UserName:

I'm deleting it! It was run on a newly installed computer I was setting up for my father. Malwarebytes' Anti-Malware Database version: 5518 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 14/01/2011 10:48:34 mbam-log-2011-01-14 (10-48-34).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 375341 Time elapsed: 2 hour(s), 1 Download and install HijackThis.

S3 gel90xne;gel90xne;\??\c:\docume~1\roisin\locals~1\temp\gel90xne.sys --> c:\docume~1\roisin\locals~1\temp\gel90xne.sys [?] 2011-01-04 19:46:37 53248 ----a-w- c:\windows\system32\drivers\sst6BA.sys 2011-01-04 19:46:37 0 ----a-w- c:\windows\system32\drivers\sst6BA.tmp 2011-01-04 19:46:00 -------- d-----w- c:\docume~1\alluse~1\applic~1\nJpCf06504 Do you know what these are? I'm not finding any other malware here. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged Copy the results and paste them in your next reply.

This is normal and ComboFix will restore your desktop before it is finished. I cleaned down a virus infected pc (Windows XP Media Centre Edition SP3 with IE8). It, like NX.exe, has the tricky dates (created 2004, modified 1994). Then I did a scan with updated MalwareBytes, and it found 2 "Trojan.FakeAlert", Category: Register Key, Item: HKEY_CURRENT_USER\SOFTWARE\IJKUK66HMN, and Item: HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP.

I have searched all anti virus sites and have scanned with my NOD32 and have picked up nothing. You also have used the wrong version of HiJackThis. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [25/08/2010 18:48 84072] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [29/09/2008 14:40 206096] R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [25/08/2010 18:47 271480] R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" For example, create a new folder and rename it "Saved File", then move it into that folder.

c:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully. c:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully. 0 PhilliePhan 171 6 Years Ago Any ideas on this one.....? Once the scan is complete, click the AnalyzeThis button.

c:\documents and settings\nuala\Desktop\system tool 2011.lnk (Rogue.SystemTool) -> Quarantined and deleted successfully. It seems to be left behind even after uninstalling all associated DK products and can simply be removed to complete the uninstallation." I was goofing off and checking out these old Win32.exe error report, fatal system error later This is a discussion on Win32.exe error report, fatal system error later within the Virus/Trojan/Spyware Help forums, part of the Tech Support Forum category. Folders Infected: c:\documents and settings\nuala\start menu\security central (Rogue.SecurityCentral) -> Quarantined and deleted successfully.

The error: "%233" Happened while starting this command: "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" -Embedding 07/01/2011 16:22:31, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order It's possible the long boot time is due to nvidia drivers. I hadn't mentioned it because there were more troubling problems and I thought it would go away once things were fixed, but it's still slow.

I know you have heard this error 1 milion times and i am very sorry about it. Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator) Click ScanUpon completion of the scan, click Save log and save it to your When I log in it loads several things before it even bothers to do the logging-in noise, and Pidgin seems to take abnormally long to auto-start. Note: Do not mouse-click combofix's window while it is running.

The system returned: (22) Invalid argument The remote host or network may be down. The scan then continued. scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) Thanks. 07-19-2011, 09:38 PM #33 Ried AdministratorManagement Team, Security Center & TSF Academy Expert Analyst, Moderator, Security Team Rangemaster, Moderator, TSF Academy Join Date: Jan 2005 Location:

Please re-enable javascript to access full functionality. c:\downloads\wobblybobbly-dm[1].exe (Adware.TryMedia) -> Quarantined and deleted successfully. I did a Google search and came here. After that i will...

Completion time: 2011-01-18 13:04:04 ComboFix-quarantined-files.txt 2011-01-18 13:03 Pre-Run: 64,979,394,560 bytes free Post-Run: 65,282,338,816 bytes free - - End Of File - - 90BDB5E363F0A6C85C683B99A8261B01 ________________ Hijack this log: Logfile of Trend Micro The system returned: (22) Invalid argument The remote host or network may be down.