Visual C++ Runtime Library problems
-
Visual C++ Runtime Library problems
I have looked at previous similar posts and hope you can help me.
For a while I have been having a problem with the above. It has caused an 'abnormal program termination on C:Windows\system32\shvrtf.exe which I understand is PC Angel.
Now I am getting a message when I am using my genealogy software Family Tree Maker. The applicationhas requested the runtime to terminate in an unusual way.
I've looked at previous posts and other forums and this seems complex and I'm worried I might do more damage trying to fix it without help.
I've run AVG virus protection and spyware removal and Spybot Search and Destroy. I've also fiddled about a bit but now I am at my wits end and scared of losing data from my genealogy file (which is backed up)
This is the Hijack this log file
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:55:14, on 01/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\ehome\ehtray.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BHODemon 2\BHODemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.madasafish.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\sw g.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Protect] SHVRTF.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk/
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.laplink.com/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1173222094875
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/bbde...ivePreQual.cab
O20 - AppInit_DLLs: AntiLogger.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8245 bytes
This is the uninstall log
ACDSee 3.1 (SR-1)
ACDSee 32
Adobe Acrobat 4.0
Adobe Flash Player 9 ActiveX
Adobe Photoshop Elements 2.0
Adobe Reader 8.1.1
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.2
Andrees3
Apple Software Update
Ashampoo Magical UnInstall
Ashampoo Photo Commander 3
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Audacity 1.3.4
AVG 7.5
AVG Anti-Spyware 7.5
Battlefield 2(TM)
BHODemon 2.0.0.23
Canon PhotoRecord
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
Charting Companion for Family Tree Maker
Clifford (TM) Musical Memory Games
Clifford Learning Activities
Clipart.com Sampler 40,000
CNXT V92 Data Fax Voice
CyberTweak Version 1.3 Final
Dan Elwell's Broadband Speed Test
Driver Genius Professional Edition 2006 6.2.1525
DVD Region+CSS Free Lite 5.9.8.3
DVD To Audio Converter 1.00
Enable S3 for USB Device
Family Tree Maker 2006
FloorPlan 3D v8
Football Manager 2007
Genie Backup Manager V4.0
getPlus(R)_ocx
Golf Score Doctor
Google Earth
Google Updater
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB895953)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB898543)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB912024)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB927891)
Hotfix for Windows XP (KB935448)
IKEA HomePlanner Kitchen
iolo technologies' System Mechanic 6
IrfanView (remove only)
J2SE Runtime Environment 5.0 Update 7
Java(TM) SE Runtime Environment 6 Update 1
JPEG Lossless Rotator 5.0
Kubex Software 3D Home Designer
LivePix 1.1
MAGIX audio cleaning lab 2004 deLuxe
MAGIX Media Manager silver
Max Payne
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Age of Empires
Microsoft Age of Empires Expansion
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta 97 Encyclopedia World English Edition
Microsoft Encarta 97 World Atlas
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2000 Standard
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 2000
Microsoft Works 2000 Setup Launcher
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
Nero
Nikon FotoShare
Nikon Message Center
O&O DiskRecovery
Oblivion
PaperPort 6.5
Paragon Partition Manager 8.0 Personal
PCdefense
Picasa 2
PictureProject
Pinnacle Hollywood FX 4.6
PowerDVD
Presto! ImageFolio 4.2
Presto! VideoWorks 5.0
QuarkXPress 5.01
QuickTime
Readiris 7.0
RealPlayer
Realtek High Definition Audio Driver
Registry Mechanic 6.0
Roxio Easy Media Creator 7 Basic DVD Edition
Roxio EasyWrite Reader
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Serif WebPlus 6.0
SimCity 2000®
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Studio 8
TomTom HOME
TreeSize Professional 4.0
ULi Chipset Driver
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB925876)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update Rollup 2 for Windows XP Media Center Edition 2005
Visioneer 4400 Scanner
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893056
Windows XP Hotfix - KB894194
Windows XP Media Center Edition 2005 KB888316
Windows XP Media Center Edition 2005 KB890760
Windows XP Media Center Edition 2005 KB894553
Windows XP Media Center Edition 2005 KB895678
Windows XP Media Center Edition 2005 KB925766
ZoneAlarm
-
Welcome,
Sounds difficult alright.
Do you know what this is? O20 - AppInit_DLLs: AntiLogger.dll
Tools that could hinder fixing your PC:
I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes. So please disable TeaTimer by doing the following:- Run Spybot-S&D
- Go to the Mode menu, and make sure "Advanced Mode" is selected
- On the left hand side, choose Tools -> Resident
- Uncheck "Resident TeaTimer" and OK any prompts
You can reenable TeaTimer once your system is clean.
AVG Anti-Spyware (formerly ewido)
Launch AVG Anti-Spyware and in the main window click "Realtime protection" (in green indicating "Active") to change to inactive.
Also disable anti-virus after disconnected from the internet
If you have previously downloaded ComboFix,please delete that version now.
Now download ComboFix and save to your desktop:
Note:
It is IMPORTANT that it is saved directly to your desktop
Close any open browsers.
Disconnect from the Internet.
Please do not re-connect your machine back to the Internet until Combofix has completely finished.
Disable your antivirus program and any realtime malware scanners now
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.
Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Re-enable your anti-virus and re-connect back to the internet and post the combofix log.
*Note*
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.
-
Hi. Thanks for your help.
I am afraid I have no idea about
O20 - AppInit_DLLs: AntiLogger.dll
It must be rare not to find a single reference on google! I found it on Yahoo on a site www.runscanner.net and they say it is part of laplink pc defense. This curiously may be the source of a the message I get on startup which says that something is trying to hook the keyboard. When I prevent it I get a message that mentions PC defense. I have searched my pc for PC defense but find no reference to it.
I’ve disabled tea timer. I have read that it is a waste of resources anyway.
I couldn’t find the ‘realtime’ part of AVG Antispyware. Mine was a free version which didn’t seem to have it. So I have uninstalled the product It didn’t seem to add much to my security anyway. It just semed a bit more picky about tracking cookies than S&D.
I Uninstalled BHO demon.
I switched off virus protection, Spybot and Zone Alarm.
The followingis the combofix.txt
omboFix 08-02.03.1 - David_p 2008-02-03 14:49:50.2 - NTFSx86
Running from: C:\Documents and Settings\David_p\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.
2008-02-01 17:10 . 2008-02-03 11:26 <DIR> d-------- C:\Program Files\BHODemon 2
2008-01-29 10:38 . 2008-01-29 10:47 <DIR> d-------- C:\Program Files\designeasy
2008-01-25 12:18 . 2008-01-25 13:40 699 --a------ C:\WINDOWS\dvdtoaudioconverter.ini
2008-01-25 12:08 . 2008-01-25 12:08 <DIR> d-------- C:\Program Files\MyDVDTools
2008-01-25 11:44 . 2008-01-25 11:44 <DIR> d-------- C:\Program Files\Audacity 1.3 Beta
2008-01-25 11:44 . 2008-01-25 14:23 <DIR> d-------- C:\Documents and Settings\David_p\Application Data\Audacity
2008-01-22 20:13 . 2008-01-31 19:18 67 --a------ C:\WINDOWS\DVDRegionFreeLite.INI
2008-01-22 20:12 . 2008-01-22 20:12 <DIR> d-------- C:\Program Files\DVD Region+CSS Free Lite
2008-01-16 09:07 . 2008-01-16 09:07 244 --ah----- C:\sqmnoopt19.sqm
2008-01-16 09:07 . 2008-01-16 09:07 232 --ah----- C:\sqmdata19.sqm
2008-01-16 08:30 . 2008-01-16 08:30 244 --ah----- C:\sqmnoopt18.sqm
2008-01-16 08:30 . 2008-01-16 08:30 232 --ah----- C:\sqmdata18.sqm
2008-01-15 08:22 . 2008-01-15 08:22 244 --ah----- C:\sqmnoopt17.sqm
2008-01-15 08:22 . 2008-01-15 08:22 232 --ah----- C:\sqmdata17.sqm
2008-01-14 11:12 . 2008-01-14 11:12 244 --ah----- C:\sqmnoopt16.sqm
2008-01-14 11:12 . 2008-01-14 11:12 244 --ah----- C:\sqmnoopt15.sqm
2008-01-14 11:12 . 2008-01-14 11:12 232 --ah----- C:\sqmdata16.sqm
2008-01-14 11:12 . 2008-01-14 11:12 232 --ah----- C:\sqmdata15.sqm
2008-01-13 00:16 . 2008-01-13 00:16 244 --ah----- C:\sqmnoopt14.sqm
2008-01-13 00:16 . 2008-01-13 00:16 232 --ah----- C:\sqmdata14.sqm
2008-01-09 15:10 . 2008-01-09 15:11 <DIR> d-------- C:\Program Files\IKEA HomePlanner
2008-01-09 15:10 . 2008-01-09 15:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-07 12:03 . 2008-01-07 12:03 244 --ah----- C:\sqmnoopt13.sqm
2008-01-07 12:03 . 2008-01-07 12:03 232 --ah----- C:\sqmdata13.sqm
2008-01-06 11:59 . 2008-01-06 11:59 <DIR> d-------- C:\Program Files\Driver-Soft
2008-01-06 11:59 . 2004-06-14 14:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2008-01-04 17:14 . 2008-01-26 16:45 244 --ah----- C:\sqmnoopt12.sqm
2008-01-04 17:14 . 2008-01-26 16:45 232 --ah----- C:\sqmdata12.sqm
2008-01-04 15:49 . 2008-01-26 16:43 244 --ah----- C:\sqmnoopt11.sqm
2008-01-04 15:49 . 2008-01-26 16:43 232 --ah----- C:\sqmdata11.sqm
2008-01-03 12:22 . 2008-01-03 12:22 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2008-01-03 12:22 . 2008-01-03 12:23 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\AVG7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-03 14:53 15,525,920 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-03 10:46 182,132 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-03 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-01 19:27 --------- d-----w C:\Documents and Settings\David_p\Application Data\AVG7
2008-02-01 14:20 82,432 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2008-02-01 13:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-01 09:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-01 03:23 538,624 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2008-02-01 03:15 --------- d-----w C:\Program Files\Google
2008-01-26 02:30 373,760 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2008-01-26 02:30 1,480,704 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2008-01-25 23:37 --------- d-----w C:\Documents and Settings\David_p\Application Data\Roxio
2008-01-23 13:45 119,808 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2008-01-23 13:45 1,472,512 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2008-01-22 14:32 90,112 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2008-01-22 14:32 1,470,464 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2008-01-21 17:08 77,824 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-01-21 17:08 1,468,928 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-01-21 15:25 197,632 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-01-21 15:25 1,465,856 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-01-21 15:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-18 14:21 167,424 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-01-16 14:59 162,816 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-01-15 15:02 486,400 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-01-15 15:02 1,455,104 ----a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2008-01-09 15:23 467,968 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-01-09 15:23 1,449,472 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-01-03 14:19 1,438,208 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-01-02 23:01 52,224 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-01-01 01:47 66,560 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2007-12-31 17:10 140,288 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2007-12-31 17:10 1,434,624 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2007-12-31 11:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-31 10:45 --------- d-----w C:\Program Files\QuickTime
2007-12-31 10:41 --------- d-----w C:\Program Files\Apple Software Update
2007-12-31 10:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-30 20:30 265,728 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2007-12-30 20:30 1,434,112 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2007-12-22 20:46 83,968 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2007-12-22 20:46 1,423,872 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2007-12-21 12:02 134,656 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2007-12-21 12:02 1,422,848 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2007-12-20 17:54 --------- d-----w C:\Program Files\TomTom HOME 2
2007-12-20 17:54 --------- d-----w C:\Documents and Settings\David_p\Application Data\TomTom
2007-12-20 17:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2007-12-20 17:53 --------- d-----w C:\Documents and Settings\David_p\Application Data\InstallShield
2007-12-20 17:51 --------- d-----w C:\Program Files\TomTom DesktopSuite
2007-12-20 17:21 232,448 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-12-20 17:21 1,416,192 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-12-20 14:52 --------- d-----w C:\Program Files\MSBuild
2007-12-20 14:49 --------- d-----w C:\Program Files\Reference Assemblies
2007-12-20 14:47 --------- d-----w C:\Program Files\MSXML 6.0
2007-12-20 14:26 1,413,632 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-12-17 15:19 155,136 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-12-17 15:19 1,411,584 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-12-16 11:42 50,688 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2007-12-15 01:38 320,000 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2007-12-15 01:38 1,406,464 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2007-12-14 14:26 --------- d-----w C:\Documents and Settings\Sam\Application Data\AVG7
2007-12-14 14:25 --------- d-----w C:\Documents and Settings\Sam\Application Data\Grisoft
2007-12-10 14:45 124,416 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2007-12-07 21:05 542,208 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2007-12-06 08:37 --------- d-----w C:\Documents and Settings\Sudge\Application Data\Grisoft
2007-12-06 08:37 --------- d-----w C:\Documents and Settings\Sudge\Application Data\AVG7
2007-12-04 19:57 1,339,392 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2007-12-04 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-04 18:34 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2007-12-04 10:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-04 09:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-04 00:48 --------- d-----w C:\Documents and Settings\David_p\Application Data\Uniblue
2007-12-03 16:54 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-03 00:20 --------- d-----w C:\Program Files\iolo
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2006-03-22 18:18 328 ----a-w C:\Documents and Settings\David_p\Application Data\wklnhst.dat
1999-07-18 19:05 15,716 ----a-w C:\WINDOWS\inf\i386\Pmxscan.sys
2006-03-22 16:39 8,192 --sha-w C:\WINDOWS\o2cLicStore.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-14 17:51 14864384 C:\WINDOWS\RTHDCPL.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"Protect"="SHVRTF.EXE" [2005-02-04 10:58 1011712 C:\WINDOWS\system32\SHVRTF.EXE]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCh eck.exe" [2003-12-04 12:34 406016]
"ioloDelayModule"="C:\Program Files\iolo\System Mechanic 6\delay.exe" [2005-06-08 13:31 96256]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-03 12:25 579072]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43 45056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 16:54 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2006-03-21 01:08:53 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=AntiLogger.dll
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"Alcmtr"=ALCMTR.EXE
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"RoxioDragToDisc"="c:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
R0 hotcore2;hotcore2;C:\WINDOWS\system32\drivers\hotc ore2.sys [2006-10-02 09:39]
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-08-19 10:18]
R0 MrFilter;EasyWrite Driver;C:\WINDOWS\system32\drivers\MrFilter.sys [2005-03-01 22:40]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-10 12:00]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-10 12:00]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-10 12:00]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-10 12:00]
S3 SPYPRV;SPYPRV;C:\WINDOWS\system32\drivers\SPYPRV.S YS [2006-02-07 12:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{c1248ec9-86bf-11da-88cd-806d6172696f}]
\Shell\AutoRun\command - D:\PcAngel.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-28 01:00:05 C:\WINDOWS\Tasks\GBM_New Backup Job.job"
- C:\Program Files\Genie-Soft\Genie Backup Manager V4.0\GBManager.exe
"2006-09-01 21:46:14 C:\WINDOWS\Tasks\Laplink Antispyware.job"
- C:\Program Files\Laplink\PCdefense\LaplinkAsp.exe
"2007-07-04 18:37:40 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 14:54:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\detoured.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\detoured.dll
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\system32\detoured.dll
.
Completion time: 2008-02-03 14:55:10
ComboFix-quarantined-files.txt 2008-02-03 14:54:48
ComboFix2.txt 2008-02-03 11:00:57
.
2008-01-10 00:39:46 --- E O F ---
I hope this makes more sense to you than it does to me!
-
PC Angel/PC Defense
PC Angel
Let me know if you want to get rid of this program!
PC Defense is showing in add/remove program and can be uninstalled from there.
Let me know if you want it gone and we can fix some other stuff about that also
-
Neal
Eureka
Thanks for everything I think this has cured the problem. I couldn't wait and blew Laplink's PC Defense away and now I don't get the error messages.
If you have any other thoughts comments or suggestions I'd be glad to have them.
David
-

I figured that would do the trick.
If you are no longer having any more trouble here is some preventative measures for you.
Be sure to re-hide hidden files/folders if you were asked to unhide them
Here are some preventive measures you can take to keep your computer from getting infected again. also keep all these and Ad-awareSE and SpybotS&D updated.
http://www.d-a-l.com/help/showthread.php?t=32403
Flush your restore points in ME and XP, by turning System Restore off and then back on.
This will create a fresh restore point.
Explained Here:
Windows XP: http://vil.nai.com/vil/SystemHelpDoc...ysRestore.aspx
Explained Here
Microsoft ME:
http://service1.symantec.com/SUPPORT...rc=sec_doc_nam
Please download ATF Cleaner by Atribune to desktop.
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Double-click ATF-Cleaner.exe to run the program, to clean junk files off your PC.
If you would like to keep your cookies don't check that item
* Under Main "Select Files to Delete" choose: Select All.
* Click the Empty Selected button.
* If you use Firefox browser click Firefox at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
* If you use Opera browser click Opera at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
RegProtect
This small registry protection tool will save you hours of heartache by notifying you when some program good or bad is trying to access your registry.
You have the option of allowing(good) items or blocking(bad)items.
http://www.diamondcs.com.au/index.php?page=regprot
To reduce the re-infection potential for malware and protect yourself against spyware, here are a few helpful suggestions:
1. Keep Windows and Internet Explorer current with the latest critical security updates from Microsoft. This will patch many of the security holes through which attackers can gain access to your computer. You CANNOT complete this update using an alternate browser.
http://v5.windowsupdate.microsoft.co....aspx?ln=en-us
http://www.microsoft.com/windows/ie/default.asp
2. Run your antivirus software regularly, and to keep its definitions up-to-date. If you are thinking about switching, there are a some good free Antivirus programs that are decent, including AVG and Avast!.
AVG: http://free.grisoft.com/doc/1
Avast: http://www.avast.com/eng/avast_4_home.html
3. In addtion to using Ad-aware consider using another free malware scanning/removal program:
Windows Defender
http://www.microsoft.com/athome/secu...e/default.mspx
4. Consider using a free firewall if you are not already using one. Some good free ones are:
Kerio
Sunbelt
Comodo Personal Firewall:
Comodo
5. Consider using an alternate free browser for general web surfing but you must use IE for windows update.
Mozilla Firefox: www.mozilla.org/products/firefox/
6. Consider increasing your browser security by using these programs:
SpywareGuard will protect your homepage from being hijacked: http://www.javacoolsoftware.com/spywareguard.html
SpywareBlaster will increase browser protection by blocking Thousands of known malware sites by adding them to IE's restricted sites zone. Download it here:
http://www.javacoolsoftware.com/spywareblaster.html
If you use SpywareBlaster, you can also use a customblocklist to add even more entries into IE restricted sites zone. Go to this site for the current list and how to use instructions: http://customblockinglist.cjb.net/
IE-SPYAD is similar in that it adds thousands more known malware sites to IE's restricted zone. Download it here:
https://netfiles.uiuc.edu/ehowes/www/resource.htm
Block access to Untrustworthy Sites
You can prevent your computer from visiting a myriad of untrustworthy sites and ad-servers by installing a customised hosts file. One of the best available is the: MVPS Hosts File. Simply follow the instructions to install the file in the correct location. This will not only make surfing safer but will improve website load times and block popups from many of the large ad-servers.
*Remember just like your primary anti-virus software, it is important to keep all of these programs up-to-date and use them on a regular basis. It's Free