0

HI Mob!

I am stumped. I learned on punch cards and a CDC 6600, so I've been at this for a bit, but I am over my head here and would greatly appreciate an assist. Running Vista Home Premium 32 bit (I know, I know. I have XP on my laptop!)

THANK YOU to the entire community for the advice on malware removal! (Even though it hasn't helped thus far, it was cool to play with the new software!!!)

My basic problem manifest itself first as a tendancy for Firefox to freeze-up and lock my system, necessitating a re-boot. Recently I have been unable to use the right-click function anywhere (except in task manager) without windows explorer crashing and calling the error code

"explorer.exe - Fatal Application Exit

The specified module could not be found. C:\Program Files\common files\Adobe\Adobe Version Cue CS4\client
4.0.0\VersionCue.dll"

Ran all of the elements requested by PhilliePhan, no joy.

Ran MS MSRT and it found nothing. Ran GMER and obtained report contained in GMER One.txt. When I proceded to step two my system froze (twice) shortly into the scan. The files I was able to see were in file "driver" (sorry, that's all I could see.) and were "TCP", Bthport.sys", Udp-avgtdix.sys", and Rawlp-avgtdvix.sys."

Ran MBA-M and it froze system upon finding one evil file. Ran it again after reboot, found one file, MBA-M removed it, re-booted, same dang problem!!

Scan logs for DDS were as follows:

DDS (Ver_10-03-17.01) - NTFSx86
Run by WildSide Associates at 20:49:42.56 on Sun 05/09/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1206 [GMT -4:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AERTSrv.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\Windows\system32\NLSSRV32.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\D-Link\D-Link USB VoIP Adapter\VServ.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\D-Link\D-Link USB VoIP Adapter\DLinkMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\D-Link\D-Link USB VoIP Adapter\DPH-50U Utility.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Windows\explorer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\WildSide Associates\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uStart Page = hxxp://google.com/
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
BHO: DeLorme Send To GPS: {fbaad182-3c7a-4bc4-a5e9-207b8e0f02fd} - c:\program files\delorme\sendtogps\PNPluginForIE.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [DLinkMonitor.exe] c:\program files\d-link\d-link usb voip adapter\DLinkMonitor.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\users\wildsi~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\quickl~1.lnk - c:\program files\alltel\quicklink mobile\QuickLink Mobile.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
TCP: {AA0325FB-E174-48B0-8BD5-3B902ADA75FA} = 66.174.95.44 66.174.92.14
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\wildsi~1\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\
FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/?ui=2&shva=1#inbox
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: c:\users\wildside associates\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\users\wildside associates\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}\platform\winnt_x86-msvc\components\winprocess.dll
FF - component: c:\users\wildside associates\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\users\wildside associates\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\extensions\support@lastpass.com\platform\winnt_x86-msvc\components\lpxpcom.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppnplugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\skyhook wireless\loki browser plugin\versions\3.1.0.05\nploki.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\wildside associates\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\wildside associates\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\wildside associates\appdata\roaming\mozilla\firefox\profiles\a6co307w.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
u s e r _ p r e f ( c a p a b i l i t y . p o l i c y . p o l i c y n a m e s , a l l o w c l i p b o a r d ) ;
u s e r _ p r e f ( c a p a b i l i t y . p o l i c y . a l l o w c l i p b o a r d . s i t e s , h t t p : / / w w w . wildsideassociates.com hxxp://www.theroundriver.com http://www.foodiegardens.com ) ;
u s e r _ p r e f ( c a p a b i l i t y . p o l i c y . a l l o w c l i p b o a r d . C l i p b o a r d . c u t c o p y , a l l A c c e s s ) ;
u s e r _ p r e f ( c a p a b i l i t y . p o l i c y . a l l o w c l i p b o a r d . C l i p b o a r d . p a s t e , a l l A c c e s s ) ;
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-25 64288]
R0 TLRecAgent;TLRecAgent;c:\windows\system32\drivers\TLRecAgent.sys [2010-3-15 37208]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-20 216200]
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;c:\windows\system32\drivers\avgmfx86.sys [2008-2-23 29512]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-20 242896]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-9-30 21504]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-12 308064]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2009-12-16 188736]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2009-12-16 65856]
R2 VService;VService;c:\program files\d-link\d-link usb voip adapter\VServ.exe [2007-1-2 105208]
R3 slusbvip;SL3800 USB Driver;c:\windows\system32\drivers\slusbvip.sys [2010-3-15 591832]
R3 SLVAD_simple;D-Link Virtual Audio Device;c:\windows\system32\drivers\slvad.sys [2010-3-15 85656]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-8-19 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-30 21504]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1285864]

============== File Associations ===============

.txt=

=============== Created Last 30 ================

2010-05-09 21:40:04 0 d-----w- c:\users\wildsi~1\appdata\roaming\Malwarebytes
2010-05-09 21:39:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-09 21:39:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-09 21:39:53 0 d-----w- c:\programdata\Malwarebytes
2010-05-09 21:39:53 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-09 13:14:29 2926592 ----a-w- c:\windows\home.exe
2010-05-08 20:01:10 0 d-----w- c:\program files\Windows Installer Clean Up
2010-05-08 20:00:40 0 d-----w- c:\program files\MSECACHE
2010-05-08 19:22:22 0 d-----w- c:\program files\McAfee Security Scan
2010-05-06 16:13:55 2725 ----a-w- c:\users\wildside associates\.recently-used.xbel
2010-05-05 20:48:00 67 ----a-w- c:\users\wildside associates\.gtk-bookmarks
2010-05-04 18:14:23 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
2010-05-04 18:14:23 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-05-04 18:14:10 0 d-----w- c:\programdata\Nitro PDF
2010-05-04 18:14:10 0 d-----w- c:\program files\common files\Nitro PDF
2010-05-04 18:12:24 0 d-----w- c:\users\wildsi~1\appdata\roaming\Downloaded Installations
2010-05-04 18:04:17 196608 ----a-w- c:\windows\system32\Utility.dll
2010-05-04 18:04:16 51604 ----a-w- c:\windows\system32\Adist5k.ppd
2010-05-04 18:04:16 212240 ----a-w- c:\windows\system32\Richtx32.ocx
2010-05-04 18:04:16 117507 ----a-w- c:\windows\system32\msinet.ocx
2010-05-04 18:04:06 204848 ----a-w- c:\windows\system32\gswin32c.exe
2010-05-04 18:04:04 0 d-----w- c:\windows\system32\gs
2010-05-04 17:55:39 8 ----a-w- c:\windows\system32\yrtsac106.cfg
2010-05-04 17:55:39 8 ----a-w- c:\windows\system32\kluda403b.dta
2010-05-04 17:55:38 0 d-----w- c:\program files\Text Cleanup
2010-05-01 19:02:10 0 d-----w- c:\program files\iPod
2010-05-01 18:58:15 0 d-----w- c:\program files\Bonjour
2010-04-21 21:41:11 240 ----a-w- c:\windows\DC_Manager.ini
2010-04-21 21:39:50 0 d-----w- c:\program files\DoubleCAD Setup
2010-04-14 12:47:20 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 12:47:20 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 12:47:20 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 12:47:12 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 12:47:12 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 12:47:12 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 12:47:03 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 12:47:02 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 12:46:59 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 12:46:36 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-04-14 12:46:35 220672 ----a-w- c:\windows\system32\l3codecp.acm
2010-04-14 12:42:32 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-14 12:42:08 172032 ----a-w- c:\windows\system32\wintrust.dll

==================== Find3M ====================

2010-05-10 00:46:37 2678 ----a-w- c:\windows\bthservsdp.dat
2010-05-01 18:59:26 51200 ----a-w- c:\windows\inf\infpub.dat
2010-05-01 18:59:25 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-04-28 15:11:39 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-21 12:01:56 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-08 17:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-02 22:29:14 143360 ----a-w- c:\windows\inf\infstor.dat
2010-03-15 23:05:27 4973920 ----a-w- c:\users\wildside associates\dph50u_QIG_110.zip
2010-03-15 22:19:38 85656 ----a-w- c:\windows\system32\drivers\slvad.sys
2010-03-15 22:19:38 591832 ----a-w- c:\windows\system32\drivers\slusbvip.sys
2010-03-15 22:19:38 37208 ----a-w- c:\windows\system32\drivers\TLRecAgent.sys
2010-03-15 22:19:38 248664 ----a-w- c:\windows\system32\slvipgx.dll
2010-03-15 22:19:38 150368 ----a-w- c:\windows\system32\slvipco.dll
2010-03-12 13:53:32 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-12 13:52:39 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06:41 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-19 23:47:50 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2009-11-17 13:37:54 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-10-01 05:01:31 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-02-13 07:54:29 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:50:42.46 ===============

and

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 2/12/2008 7:03:55 PM
System Uptime: 5/9/2010 8:47:18 PM (0 hours ago)

Motherboard: Dell Inc. | | 0RY007
Processor: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 2200/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 288 GiB total, 163.276 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 4.527 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 298 GiB total, 246.851 GiB free.
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft 6to4 Adapter
Device ID: ROOT\*6TO4MP\0002
Manufacturer: Microsoft
Name: Microsoft 6to4 Adapter #2
PNP Device ID: ROOT\*6TO4MP\0002
Service: tunnel

==== System Restore Points ===================


==== Installed Programs ======================

AAC Decoder
Ad-Aware
Ad-Aware Email Scanner for Outlook
Adobe Color - Photoshop Specific CS4
Adobe Color EU Recommended Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Color Video Profiles CS CS4
Adobe Drive CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Linguistics CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 9.3
Adobe WinSoft Linguistics Plugin
AdobeColorCommonSetCMYK
Akamai NetSession Interface
Amazon MP3 Downloader 1.0.10
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AutoUpdate
AVG Free 9.0
Bonjour
Browser Address Error Redirector
Cars 1.7
CD Audio Reader Filter (remove only)
Conexant D850 PCI V.92 Modem
D-Link USB VoIP Adapter
DC-Bass Source 1.1.1
Dell Support Center (Support Software)
DeLorme Earthmate GPS PN-20 Update
DeLorme Send To GPS 1.0
DeLorme Topo USA 6
DeLorme Topo USA 6.0 DVD Data
DeLorme Topo USA 6.0 PN Merge Modules
Digital Line Detect
DirectVobSub (remove only)
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
DoubleCAD XT
DoubleCAD XT Pro 2
DScaler 5 Mpeg Decoders
Facebook Plug-In
FileZilla Client 3.3.2
Foxit Reader
Foxit Toolbar
Free Download Manager 2.5
GIMP 2.6.7
GimPad 1.1
GimPhoto 1.4.3
Google Earth
Google Gears
Google Update Helper
GoToAssist 8.0.0.514
H.264 Decoder
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Inkscape 0.47
Intel(R) PRO Network Connections 12.1.11.0
iTunes
Java(TM) 6 Update 16
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6
Loki Browser Plugin
Malwarebytes' Anti-Malware
Media Player Codec Pack 3.2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.4
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Project 2007 Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Standard 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Sync Framework Runtime v1.0 (x86)
Microsoft Sync Framework Services v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
MKV Splitter
MobileMe Control Panel
Modem Diagnostic Tool
MONOGRAM AMR Splitter/Decoder (remove only)
Motorola Phone Tools
Mozilla Firefox (3.6.3)
MrSID Viewer
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Music, Photos & Videos Launcher
Netflix Movie Viewer
NetWaiting
Nitro PDF Professional
Octoshape add-in for Adobe Flash Player
OGA Notifier 2.0.0048.0
OpenSource DTS/AC3/DD+ Source Filter (remove only)
OpenSource Flash Video Splitter (remove only)
PDF Settings CS4
Photo Viewer S2.5
Picasa 3
PrimoPDF -- brought to you by Nitro PDF Software
Product Documentation Launcher
QuickLink Mobile
QuickTime
RealMedia (remove only)
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB980470)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
SHOUTcast Source (remove only)
Skype™ 4.2
Sonic Activation Module
Spelling Dictionaries Support For Adobe Reader 8
SyncToy 2.0 (x86)
TBS WMP Plug-in
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB981715)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Project 2007 Help (KB963668)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb981433)
User's Guides
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
Virtual Earth 3D (Beta)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WIDCOMM Bluetooth Software 6.0.1.4300
Windows Essentials Media Codec Pack 2.3d
Windows Installer Clean Up
Windows Live ID Sign-in Assistant
Windows Live OneCare safety scanner
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
Wise Disk Cleaner 5.3
Wise Registry Cleaner Free 5.31
Zoom Player (remove only)

==== End Of File ===========================

GMER One.log is

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-09 17:27:08
Windows 6.0.6002 Service Pack 2
Running: 1zjr07e2.exe; Driver: C:\Users\WILDSI~1\AppData\Local\Temp\fxlcyfob.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

---- EOF - GMER 1.0.15 ----


and the MBA-M is

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4084

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

5/9/2010 8:44:48 PM
mbam-log-2010-05-09 (20-44-48).txt

Scan type: Full scan (C:\|D:\|F:\|)
Objects scanned: 347830
Time elapsed: 1 hour(s), 29 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f02fabcb-92dd-475a-98af-14217bd50746} (Adware.Gamevance) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


This is a royal PITA, and I've been fighting it for 4 days to no avail. Spent all of today following advice on this most excellent site, and while instructive, has not moved me any closer to health for my system.

Additional information that you may find helpful, after all of the above AVG flagged "questionmkt(2).txt" and "Revsci" twice. Deleted both occurances, but I'm afraid they'll be back after re-boot.

I back-up to two, alternating external HDDs at K:, neither of these have been scanned or anything.

Any insights would be most appreciated. Thanks in advance, and I hope I can return the favor one day.

Best regards,

BrianC.

3
Contributors
22
Replies
23
Views
7 Years
Discussion Span
Last Post by happyrock
0

did you try booting into safe mode with networking....
for the firefox problem...
start Firefox in Safe Mode by clicking Start... selecting Run ...type in

"%PROGRAMFILES%\Mozilla Firefox\firefox.exe" -safe-mode
press enter...
put a tick in disable all add-ons and then click on continue in safe mode

0

Only issue I noticed was that I am unable to delete an add-on called "Browser Highlighter" v. 1.0.12514. Uninstall is unavailable in any configuration.

BrianC.

Edited by BrianC.: Clarification

0

Yes, and then returning to normal mode I disabled individual add-ons to see if that was the conflict. Apparently not.

Re-reading my initial post I need to correct the right-click statement. It does work in certain instances, but not all, and not at all in Windows menus, "Start" menu, and the programs pegged to the start menu will return same error message when left-clicked. I have to start everything from "Start > All Programs > ...." or the Desktop icons all work with left-click.

BrianC.

0

did running Firefox in safe mode cause your freeze-up and/or lock your system...run it for hours to check....if its stable running that way then backup your bookmarks file...uninstall firefox and delete the whole firefox folder...download a fresh copy and install it then import your bookmarks ... then only install 1 or 2 extensions and try running for a day or so before adding another extension or 2...that way you will know which extension is causing the grief...

now about the right click issue...

download the Event Viewer Tool by Vino Rosso VEW from here and save it to your Desktop:
Double-click VEW.exe
Under Select log to query... select
Application
System
Under select type to list select
Error
Warning

Then Click the radio button for Number of events
Type 5 in the 1 to 20 box
Then click the Run button.

Notepad will open with the output log....Please cut and paste the Output log in your next reply

Edited by happyrock: n/a

0

Happy,

Saved VEW to desktop, now can't remove it. Doesn't show up in add/remove, and as I have pointed out, right-clicking doesn't work. Do I now have MORE trouble than when I started?

BrianC.

0

VEW doesn't install...its a executable file...just right click on it and select delete

0

VEW doesn't install...its a executable file...just right click on it and select delete

Sigh....

0

open any folder...click on tools...folder options...select open on single click...ok...now go back to VEW on your desktop...put your cursor over it but don't click...it should change color...then press the delete key on your keyboard

0

1 click is already my default. Delete gives same error as right-click.

Appreciate your help, but how about giving someone else a shot?

0

Appreciate your help, but how about giving someone else a shot?

Hi Brian,

I think happyrock is approaching this issue in much the same way I or the other regulars here would do so - these are kind of hard to ferret out.

I do believe this is a known issue with Adobe and that bloody VersionCue.dll.
Have a look here and see if replacing the .dll helps ---> http://forums.adobe.com/thread/419427

Best Luck :)
PP

0

I am not unappreciative of the advice at all, and seriously meant to cast no aspersions upon anyone. I have tried the suggestions made prior to posting here, and in fairness, tried them again after reading them again. I'm not trying to be a jerk here. Really! I am very worried that this error will be soon eating into my professional productivity, and wish to cast a wide net, because the obvious has not been effective. Something is rotten in Win-mark!

I have tried this fix from the Adobe forums, but the result was only a different fatal error message. (Not certain of the wording, but nothing worked any better.) The primary difference may be that all of the posters at the adobe forum were installing CS4. I got rid of it.

I am sorry to have troubled you all.

Best regards.

Edited by BrianC.: n/a

0

I have tried this fix from the Adobe forums, but the result was only a different fatal error message. (Not certain of the wording, but nothing worked any better.) The primary difference may be that all of the posters at the adobe forum were installing CS4. I got rid of it. . . . .

I am sorry to have troubled you all.

No trouble at all :)

The thing is, when we move away from malware and into proprietary software such as Adobe, you'd probably have better luck with their tech support - Speaking only for myself, I don't know much about it other than a few select recurring issues....

CS4 shows as being installed in your logs, hence my point in that direction.
If a complete uninstall and then reinstall and/or update of Adobe doesn't clear up the problem, I really wouldn't know how to advise you further.
I am not sure how important VersionCue.dll is. If you are not using CS4, I don't know why that is being called?

Does C:\Program Files\common files\Adobe\Adobe Version Cue CS4\client 4.0.0\VersionCue.dll exist? Maybe there is an updated version?

I don't know - Though, I'm fairly certain your problem lies wholly with Adobe and not malware.

Cheers :)
PP

Edited by PhilliePhan: n/a

0

No trouble at all :)

The thing is, when we move away from malware and into proprietary software such as Adobe, you'd probably have better luck with their tech support - Speaking only for myself, I don't know much about it other than a few select recurring issues....

CS4 shows as being installed in your logs, hence my point in that direction.
If a complete uninstall and then reinstall and/or update of Adobe doesn't clear up the problem, I really wouldn't know how to advise you further.
I am not sure how important VersionCue.dll is. If you are not using CS4, I don't know why that is being called?

Does C:\Program Files\common files\Adobe\Adobe Version Cue CS4\client 4.0.0\VersionCue.dll exist? Maybe there is an updated version?

I don't know - Though, I'm fairly certain your problem lies wholly with Adobe and not malware.

Cheers :)
PP

I don't use CS4, just tried a trial of Dreamweaver and then uninstalled it through remove programs, which called up the Adobe removal tool. Not only doesn't VersionCue.dll exist, nothing exists below the \common files\Adobe level!

I'm going to download/install another trial of something CS4 and delete it to see if that works. I am so thankful for everyone's time, and to know that this isn't malware related!!

Given the state of this problem, and Apple and Microsoft's recent critique of Adobe, maybe this should be moved into the malware category?

Best regards,

BrianC.

0

one last try...
There is a button on some keyboards, next to right side ctrl key that pops up a right-click menu...

Use ShellExView to determine the Context-menu causing the problem...
the how to and download is here...

if that doesn't help you will need to run sfc /scannow

0

I don't use CS4, just tried a trial of Dreamweaver and then uninstalled it through remove programs, which called up the Adobe removal tool. Not only doesn't VersionCue.dll exist, nothing exists below the \common files\Adobe level!

Given the state of this problem, and Apple and Microsoft's recent critique of Adobe, maybe this should be moved into the malware category?

Perhaps malware is a bit harsh, but it is certainly a pain in the ass . . . .

The fact that it can bork a machine is distressing.

Worst case scenerio, I suppose we could hack the registry. That is if a complete uninstall / reinstall fails.

Cheers :)
PP

0

I'm in que with Adobe tech support, they promise to get back to me within 3 days. I hope this doesn't turn out to be a new "feature."s

Install of PS CS5 didn't include Adobe Drive so no Version Que. Didn't effect my issue yet. Took 2 hours to download (I live 40 minutes south of the Mackinac Bridge, skinny pipes up here.) so I'm looking for Adobe Drive before I do the delete.

Research shows this goes back YEARS, at least to the release of CS3.

I feel like they are punishing me for breaking up with them. Think they know my Ex?

Best regards,

Brian

0

I'm in que with Adobe tech support, they promise to get back to me within 3 days. . . .

Good - hope they can offer a viable solution.

If not, happyrock's post re: ShellExView would be a good next step before hacking the registry.

Keep us in the loop :)

PP

0

one last try...
There is a button on some keyboards, next to right side ctrl key that pops up a right-click menu...

Use ShellExView to determine the Context-menu causing the problem...
the how to and download is here...

if that doesn't help you will need to run sfc /scannow

ShellExView was the tool! Found and disable adobe drive item. Couldn't remove it, but my windows exporer works just fine now. Thanks Cap'n!

0

ShellExView was the tool! Found and disable adobe drive item. Couldn't remove it, but my windows exporer works just fine now. Thanks Cap'n!

Glad to hear you got this mess sorted out!

Cheers :)
PP

0

your welcome...and thanks for letting us know...

Edited by happyrock: n/a

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.