Solved "Error loading dll files"

Discussion in 'Virus, Spyware and Malware Removal' started by dfly, Sep 4, 2010.


Thread Status:
Not open for further replies.
  1. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
    re: "Error loading dll files"

    no, i dont

  2. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    re: "Error loading dll files"

    Hello.
    Hmm, check this for me.

    Submit a file for analysis.
    1. Please visit this website: Jotti's Malware Scanner
    2. Press the "Browse" button and locate the following file in bold:

      C:\Program Files\Common Files\McAfee\FWDriver\mpfp.sys
    3. Press the "Submit File button to submit the file for analysis.
    4. Allow it to be scanned, it could take a few minutes depending on server load.
    5. Copy and paste the result back here.
  3. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
    re: "Error loading dll files"

    Filename: mpfp.sys Status: Scan finished. 0 out of 19 scanners reported malware.
    Scan taken on: Mon 6 Sep 2010 11:51:21 (CET) Permalink
  4. Google Advertisement

  5. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    re: "Error loading dll files"

    Hmm, you may be in luck here, the infected driver is just a Mcafee file, not biggy if it can't be repaired, we can completely delete it and replace it by re-installing Mcafee again. But lets try this anyway.


    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:
      KILLALL::
      
      File::
      c:\windows\system32\Drivers\Mpfp.sys
      
      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Xfelejobecebe"=-
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
      "Pzirofusoca"=-
      
      DDS::
      uInternet Settings,ProxyServer = http=127.0.0.1:5555
      uInternet Settings,ProxyOverride = <local>
      
      FCopy::
      C:\Program Files\Common Files\McAfee\FWDriver\mpfp.sys | C:\WINDOWS\system32\drivers\Mpfp.sys
      
    4. Save this as CFScript.txt, in the same location as ComboFix.exe

      [IMG]
    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.
  6. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
    re: "Error loading dll files"

    ComboFix 10-09-06.01 - Administrator 09/06/2010 10:21:15.14.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1976.1540 [GMT -7:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.text
    AV: Total Protection *On-access scanning disabled* (Outdated) {8C354827-2F54-4E28-90DC-AD391E77808C}
    FW: Total Protection *disabled* {259FBE35-46BE-45F3-8F2F-4DB67BBBC614}
    FILE ::
    "c:\windows\system32\Drivers\Mpfp.sys"
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\windows\system32\Drivers\Mpfp.sys
    c:\windows\system32\Drivers\Mpfp.sys . . . is infected!! . . . Failed to find a valid replacement.
    .
    --------------- FCopy ---------------
    c:\program files\Common Files\McAfee\FWDriver\mpfp.sys --> c:\windows\system32\drivers\Mpfp.sys
    .
    ((((((((((((((((((((((((( Files Created from 2010-08-06 to 2010-09-06 )))))))))))))))))))))))))))))))
    .
    2010-09-05 20:10 . 2010-09-05 20:10 3837097 ----a-r- C:\Combo-Fix.exe
    2010-09-03 07:25 . 2010-09-03 07:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
    2010-09-03 07:21 . 2010-09-03 07:21 -------- d-----w- c:\program files\SlySoft
    2010-09-03 06:53 . 2010-09-03 07:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\ImgBurn
    2010-09-03 06:45 . 2010-09-03 06:45 -------- d-----w- c:\program files\ImgBurn
    2010-09-01 13:00 . 2010-09-01 13:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
    2010-08-28 03:59 . 2010-08-28 04:03 -------- d-----w- c:\program files\Yahoo!
    2010-08-23 10:17 . 2010-08-23 10:17 2826192 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
    2010-08-18 01:43 . 2010-08-18 01:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL
    2010-08-18 01:43 . 2010-08-18 07:07 -------- d-----w- c:\program files\Common Files\AOL
    2010-08-18 01:43 . 2010-08-18 01:43 -------- d-----w- c:\program files\Common Files\Software Update Utility
    2010-08-17 06:09 . 2010-08-17 06:09 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-08-17 06:05 . 2010-08-17 06:09 -------- d-----w- C:\32788R22FWJFW(2)
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-06 17:31 . 2010-07-03 00:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
    2010-09-06 09:34 . 2010-07-16 17:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-09-05 02:55 . 2009-04-10 11:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\SiteAdvisor
    2010-09-01 07:08 . 2009-04-10 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\PDFC
    2010-08-31 22:46 . 2010-07-09 00:47 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2010-08-24 02:07 . 2010-02-18 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-08-20 00:40 . 2009-04-10 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2010-08-17 05:54 . 2010-07-11 22:44 120 ----a-w- c:\windows\Rlererihesogolo.dat
    2010-08-17 05:54 . 2010-07-11 22:44 0 ----a-w- c:\windows\Vciwe.bin
    2010-08-13 07:36 . 2010-07-03 00:44 -------- d-----w- c:\program files\uTorrent
    2010-08-06 06:28 . 2009-08-05 03:40 -------- d-----w- c:\program files\Windows Live
    2010-07-17 00:21 . 2009-09-06 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-07-13 21:59 . 2009-09-06 20:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-07-12 06:41 . 2010-07-07 07:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
    2010-07-10 03:35 . 2010-07-07 02:07 -------- d-----w- c:\program files\LimeWire
    2010-07-09 21:54 . 2010-07-09 21:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\CyberLink
    2010-07-09 21:53 . 2010-07-09 21:53 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
    2010-07-09 21:53 . 2009-04-10 10:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-07-09 21:53 . 2010-07-09 21:53 -------- d-----w- c:\program files\Cyberlink
    2010-07-09 21:52 . 2010-07-09 21:52 509488 ----a-w- c:\windows\system32\msvcp71.dll
    2010-07-09 21:52 . 2010-07-09 21:52 353840 ----a-w- c:\windows\system32\msvcr71.dll
    2010-07-09 21:52 . 2010-07-09 21:52 1066544 ----a-w- c:\windows\system32\mfc71.dll
    2010-07-07 07:52 . 2010-07-07 07:52 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
    2010-07-07 07:52 . 2010-07-07 07:52 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
    2010-07-07 07:52 . 2010-07-07 07:52 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
    2010-07-07 07:52 . 2010-07-07 07:53 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
    2010-07-07 07:52 . 2010-07-07 07:53 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
    2010-07-07 06:45 . 2009-10-09 01:52 2828 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    2010-07-07 06:45 . 2009-10-09 01:52 2828 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    .
    ((((((((((((((((((((((((((((( SnapShot_2010-07-17_18.36.40 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-09-06 17:31 . 2010-09-06 17:31 16384 c:\windows\temp\Perflib_Perfdata_de4.dat
    + 2010-04-17 05:12 . 2010-04-17 05:12 48464 c:\windows\system32\sirenacm.dll
    + 2010-08-06 06:28 . 2010-08-06 06:28 27136 c:\windows\Installer\109d7b6.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 83456 c:\windows\Installer\109d79b.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 58880 c:\windows\Installer\109d795.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 61272 c:\windows\Installer\{E6158D07-2637-4ECF-B576-37C489669174}\IconWlc.exe
    + 2010-08-06 06:28 . 2010-08-06 06:28 80395 c:\windows\Installer\{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}\MsblIco.Exe
    - 2009-11-10 11:14 . 2009-11-10 11:14 58945 c:\windows\Installer\{6412CECE-8172-4BE5-935B-6CECACD2CA87}\wlmail.exe
    + 2010-08-06 01:22 . 2010-08-06 01:22 58945 c:\windows\Installer\{6412CECE-8172-4BE5-935B-6CECACD2CA87}\wlmail.exe
    + 2010-08-23 10:17 . 2010-08-23 10:17 232912 c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe
    + 2010-08-23 10:17 . 2010-08-23 10:17 311760 c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.dll
    + 2008-10-01 22:01 . 2008-10-03 02:01 109216 c:\windows\system32\drivers\SafeBoot.sys
    - 2008-10-01 22:01 . 2008-10-01 22:01 109216 c:\windows\system32\drivers\SafeBoot.sys
    + 2010-08-06 01:22 . 2010-08-06 01:22 463872 c:\windows\Installer\3ef2a56.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 429056 c:\windows\Installer\109d7bd.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 140288 c:\windows\Installer\109d7af.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 149504 c:\windows\Installer\109d7a1.msi
    + 2010-08-06 06:28 . 2010-08-06 06:28 107008 c:\windows\Installer\109d78f.msi
    + 2010-08-17 06:08 . 2010-08-17 06:09 4238340 c:\windows\system32\Restore\rstrlog.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    2010-05-26 22:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
    [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
    [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-01-09 2393376]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-18 39408]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-08-13 327472]
    "Xfelejobecebe"="c:\windows\dukbcsas.dll" [BU]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CLJ"="0 (0x0)" [X]
    "MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
    "AccelerometerSysTrayApplet"="c:\windows\System32\accelerometerST.exe" [2009-01-23 82488]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-16 186904]
    "accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-11-28 298536]
    "PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2009-02-12 355896]
    "CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2009-01-28 24848]
    "PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-08-08 319000]
    "HP Mobile Broadband"="c:\swsetup\HPQWWAN\HPMobileBroadband.exe" [2009-01-09 455224]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
    "WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
    "MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2008-08-07 550208]
    "McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe" [2008-08-07 95552]
    "SiteAdvisor"="c:\program files\SiteAdvisor\6173\SiteAdv.exe" [2007-08-28 36640]
    "File Sanitizer"="c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-01-14 11223040]
    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
    "zCpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2008-12-11 81920]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 142872]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
    "HPCam_Menu"="c:\program files\Hewlett-Packard\HP Webcam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
    "WatchDog"="c:\program files\InterVideo\DVD8SESD\DVDCheck.exe" [2009-03-05 200848]
    "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-18 122368]
    "VX1000"="c:\windows\vVX1000.exe" [2009-06-27 757248]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
    "CLMLServer"="c:\program files\Cyberlink\Power2Go\CLMLSvc.exe" [2007-09-30 122880]
    "Power2GoExpress"="c:\program files\CyberLink\Power2Go\Power2GoExpress.exe" [2007-10-05 2680104]
    "Pzirofusoca"="c:\windows\oqukokoxevo.dll" [BU]
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
    2007-11-28 00:41 109568 ----a-w- c:\windows\system32\ackpbsc.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
    2007-11-28 00:40 286720 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
    2008-08-06 22:23 69632 ----a-w- c:\windows\system32\DeviceNP.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
    2009-01-28 04:15 186640 ----a-w- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\system32\APSHook.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mqsvc.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [10/1/2008 3:01 PM 109216]
    R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [10/1/2008 3:02 PM 51408]
    R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [10/1/2008 3:02 PM 12960]
    R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [3/28/2008 3:14 AM 24064]
    R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [10/1/2008 3:02 PM 12528]
    R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [11/27/2007 5:42 PM 185896]
    R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Bioscrypt [8/4/2004 1:00 AM 14336]
    R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Bioscrypt [8/4/2004 1:00 AM 14336]
    R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [10/3/2008 1:33 PM 1185016]
    R2 EngineServer;EngineServer;c:\progra~1\McAfee\MANAGE~1\VScan\ENGINE~1.EXE [4/10/2009 4:03 AM 13632]
    R2 HpFkCryptService:Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [10/1/2008 3:01 PM 256544]
    R2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files\Hewlett-Packard\File Sanitizer\HPFSService.exe [4/10/2009 4:06 AM 77824]
    R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [4/10/2009 4:03 AM 202048]
    R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [4/10/2009 3:48 AM 777240]
    R2 regi;regi;c:\windows\system32\drivers\regi.sys [4/17/2007 8:09 PM 11032]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [4/10/2009 4:07 AM 222512]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [7/27/2009 12:29 PM 109568]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/3/2010 2:14 PM 136176]
    S3 DAMDrv:DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [8/6/2008 2:43 PM 32256]
    S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [8/6/2008 3:24 PM 349432]
    S3 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2/11/2009 11:01 PM 45056]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Bioscrypt REG_MULTI_SZ ASBroker ASChannel
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2009-01-09 23:28 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-03 21:14]
    2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-03 21:14]
    2010-09-05 c:\windows\Tasks\Norton Security Scan for Administrator.job
    - c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-07-07 08:27]
    2010-09-06 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2010-05-26 22:23]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = https://www.scotiaitrade.com/pages/home/main.shtml
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=all&pf=cmnb
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3a9oy6u0.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.cknw.com/other/audiovault.html
    FF - component: c:\program files\SiteAdvisor\6173\FF\components\FFHook.dll
    FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    **************************************************************************
    scanning hidden processes ...
    scanning hidden autostart entries ...
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    zCpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    CLJ = 63
    scanning hidden files ...
    scan completed successfully
    hidden files:
    **************************************************************************
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
    "ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    [HKEY_USERS\S-1-5-21-2394006169-2039493040-1202352694-500\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (Administrator)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,58,65,fc,bc,09,b3,bf,4b,9f,38,dd,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,58,65,fc,bc,09,b3,bf,4b,9f,38,dd,\
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    - - - - - - - > 'winlogon.exe'(912)
    c:\windows\system32\ackpbsc.dll
    c:\windows\system32\aclog.dll
    c:\windows\system32\accrypto.dll
    c:\windows\system32\ACLIBEAY.dll
    c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    c:\program files\Hewlett-Packard\IAM\bin\itmsg.dll
    c:\program files\ActivIdentity\ActivClient\acunlock.dll
    c:\windows\system32\aipingui.dll
    c:\windows\system32\acevtsub.dll
    c:\windows\system32\asphat32.dll
    c:\windows\system32\acerrmes.dll
    c:\windows\system32\aspcom.dll
    c:\windows\system32\aicext.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\acerrmrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\asphatrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\aipinguirc.dll
    c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\acunlockrc.dll
    c:\windows\system32\DeviceNP.dll
    c:\windows\system32\SSREGLIB.dll
    c:\windows\system32\HPPTLog.dll
    c:\program files\Hewlett-Packard\IAM\Bin\TrayIcon.dll
    c:\program files\Hewlett-Packard\IAM\bin\brand.dll
    c:\program files\Hewlett-Packard\IAM\Bin\AsChnl.dll
    c:\program files\Hewlett-Packard\IAM\Bin\HPPlugIn.dll
    c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHostServices.dll
    c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTStrings.dll
    - - - - - - - > 'explorer.exe'(5964)
    c:\windows\system32\WININET.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\SCardSvr.exe
    c:\program files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\ActivIdentity\ActivClient\acevents.exe
    c:\windows\system32\msdtc.exe
    c:\program files\LSI SoftModem\agrsmsvc.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\McAfee\HackerWatch\HWAPI.exe
    c:\program files\McAfee\MPF\MPFSrv.exe
    c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
    c:\program files\SiteAdvisor\6173\SAService.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    c:\windows\system32\mqsvc.exe
    c:\windows\system32\mqtgsvc.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
    .
    **************************************************************************
    .
    Completion time: 2010-09-06 10:35:18 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-09-06 17:35
    ComboFix2.txt 2010-09-05 20:37
    ComboFix3.txt 2010-08-19 01:24
    ComboFix4.txt 2010-08-17 06:48
    ComboFix5.txt 2010-09-06 17:06
    Pre-Run: 205,354,610,688 bytes free
    Post-Run: 205,407,010,816 bytes free
    - - End Of File - - 5063E4A2C825DE8E00D586DD7E6F6C7E
  7. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    re: "Error loading dll files"

    Hello.
    Please get rid of Ask Toolbar before we move on.

    Go to Start > Control Panel > Add/Remove Programs and remove the following programs.
    • Ask Toolbar
    • uTorrent

    Next,

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:
      KILLALL::
      
      File::
      c:\windows\Rlererihesogolo.dat
      c:\windows\Vciwe.bin
      
      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Xfelejobecebe"=-
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Pzirofusoca"=-
      
    4. Save this as CFScript.txt, in the same location as ComboFix.exe

      [IMG]
    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.
  8. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
    re: "Error loading dll files"

    ComboFix 10-09-06.03 - Administrator 09/06/2010 14:08:03.15.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1976.1280 [GMT -7:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
    AV: Total Protection *On-access scanning disabled* (Outdated) {8C354827-2F54-4E28-90DC-AD391E77808C}
    FW: Total Protection *disabled* {259FBE35-46BE-45F3-8F2F-4DB67BBBC614}
    FILE ::
    "c:\windows\Rlererihesogolo.dat"
    "c:\windows\Vciwe.bin"
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\windows\Rlererihesogolo.dat
    c:\windows\Vciwe.bin
    .
    ((((((((((((((((((((((((( Files Created from 2010-08-06 to 2010-09-06 )))))))))))))))))))))))))))))))
    .
    2010-09-05 20:10 . 2010-09-05 20:10 3837097 ----a-r- C:\Combo-Fix.exe
    2010-09-03 07:25 . 2010-09-03 07:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
    2010-09-03 07:21 . 2010-09-03 07:21 -------- d-----w- c:\program files\SlySoft
    2010-09-03 06:53 . 2010-09-03 07:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\ImgBurn
    2010-09-03 06:45 . 2010-09-03 06:45 -------- d-----w- c:\program files\ImgBurn
    2010-09-01 13:00 . 2010-09-01 13:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2010-08-28 03:59 . 2010-08-28 03:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
    2010-08-28 03:59 . 2010-08-28 04:03 -------- d-----w- c:\program files\Yahoo!
    2010-08-23 10:17 . 2010-08-23 10:17 2826192 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
    2010-08-18 01:43 . 2010-08-18 01:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL
    2010-08-18 01:43 . 2010-08-18 07:07 -------- d-----w- c:\program files\Common Files\AOL
    2010-08-18 01:43 . 2010-08-18 01:43 -------- d-----w- c:\program files\Common Files\Software Update Utility
    2010-08-17 06:09 . 2010-08-17 06:09 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-08-17 06:05 . 2010-08-17 06:09 -------- d-----w- C:\32788R22FWJFW(2)
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-06 21:01 . 2010-07-03 00:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
    2010-09-06 09:34 . 2010-07-16 17:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-09-05 02:55 . 2009-04-10 11:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\SiteAdvisor
    2010-09-01 07:08 . 2009-04-10 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\PDFC
    2010-08-31 22:46 . 2010-07-09 00:47 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2010-08-24 02:07 . 2010-02-18 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-08-20 00:40 . 2009-04-10 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2010-08-06 06:28 . 2009-08-05 03:40 -------- d-----w- c:\program files\Windows Live
    2010-07-17 00:21 . 2009-09-06 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-07-13 21:59 . 2009-09-06 20:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-07-12 06:41 . 2010-07-07 07:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
    2010-07-10 03:35 . 2010-07-07 02:07 -------- d-----w- c:\program files\LimeWire
    2010-07-09 21:54 . 2010-07-09 21:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\CyberLink
    2010-07-09 21:53 . 2010-07-09 21:53 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
    2010-07-09 21:53 . 2009-04-10 10:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-07-09 21:53 . 2010-07-09 21:53 -------- d-----w- c:\program files\Cyberlink
    2010-07-09 21:52 . 2010-07-09 21:52 509488 ----a-w- c:\windows\system32\msvcp71.dll
    2010-07-09 21:52 . 2010-07-09 21:52 353840 ----a-w- c:\windows\system32\msvcr71.dll
    2010-07-09 21:52 . 2010-07-09 21:52 1066544 ----a-w- c:\windows\system32\mfc71.dll
    2010-07-07 07:52 . 2010-07-07 07:52 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
    2010-07-07 07:52 . 2010-07-07 07:52 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
    2010-07-07 07:52 . 2010-07-07 07:52 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
    2010-07-07 07:52 . 2010-07-07 07:53 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
    2010-07-07 07:52 . 2010-07-07 07:53 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
    2010-07-07 06:45 . 2009-10-09 01:52 2828 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    2010-07-07 06:45 . 2009-10-09 01:52 2828 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-01-09 2393376]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-18 39408]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CLJ"="0 (0x0)" [X]
    "MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
    "AccelerometerSysTrayApplet"="c:\windows\System32\accelerometerST.exe" [2009-01-23 82488]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-16 186904]
    "accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-11-28 298536]
    "PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2009-02-12 355896]
    "CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2009-01-28 24848]
    "PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-08-08 319000]
    "HP Mobile Broadband"="c:\swsetup\HPQWWAN\HPMobileBroadband.exe" [2009-01-09 455224]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
    "WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
    "MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2008-08-07 550208]
    "McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe" [2008-08-07 95552]
    "SiteAdvisor"="c:\program files\SiteAdvisor\6173\SiteAdv.exe" [2007-08-28 36640]
    "File Sanitizer"="c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-01-14 11223040]
    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
    "zCpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2008-12-11 81920]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 142872]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
    "HPCam_Menu"="c:\program files\Hewlett-Packard\HP Webcam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
    "WatchDog"="c:\program files\InterVideo\DVD8SESD\DVDCheck.exe" [2009-03-05 200848]
    "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-18 122368]
    "VX1000"="c:\windows\vVX1000.exe" [2009-06-27 757248]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
    "CLMLServer"="c:\program files\Cyberlink\Power2Go\CLMLSvc.exe" [2007-09-30 122880]
    "Power2GoExpress"="c:\program files\CyberLink\Power2Go\Power2GoExpress.exe" [2007-10-05 2680104]
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
    2007-11-28 00:41 109568 ----a-w- c:\windows\system32\ackpbsc.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
    2007-11-28 00:40 286720 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
    2008-08-06 22:23 69632 ----a-w- c:\windows\system32\DeviceNP.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
    2009-01-28 04:15 186640 ----a-w- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\system32\APSHook.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mqsvc.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [10/1/2008 3:01 PM 109216]
    R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [10/1/2008 3:02 PM 51408]
    R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [10/1/2008 3:02 PM 12960]
    R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [3/28/2008 3:14 AM 24064]
    R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [10/1/2008 3:02 PM 12528]
    R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [11/27/2007 5:42 PM 185896]
    R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Bioscrypt [8/4/2004 1:00 AM 14336]
    R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Bioscrypt [8/4/2004 1:00 AM 14336]
    R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [10/3/2008 1:33 PM 1185016]
    R2 EngineServer;EngineServer;c:\progra~1\McAfee\MANAGE~1\VScan\ENGINE~1.EXE [4/10/2009 4:03 AM 13632]
    R2 HpFkCryptService:Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [10/1/2008 3:01 PM 256544]
    R2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files\Hewlett-Packard\File Sanitizer\HPFSService.exe [4/10/2009 4:06 AM 77824]
    R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [4/10/2009 4:03 AM 202048]
    R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [4/10/2009 3:48 AM 777240]
    R2 regi;regi;c:\windows\system32\drivers\regi.sys [4/17/2007 8:09 PM 11032]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [4/10/2009 4:07 AM 222512]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [7/27/2009 12:29 PM 109568]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/3/2010 2:14 PM 136176]
    S3 DAMDrv:DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [8/6/2008 2:43 PM 32256]
    S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [8/6/2008 3:24 PM 349432]
    S3 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2/11/2009 11:01 PM 45056]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Bioscrypt REG_MULTI_SZ ASBroker ASChannel
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2009-01-09 23:28 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-03 21:14]
    2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-03 21:14]
    2010-09-05 c:\windows\Tasks\Norton Security Scan for Administrator.job
    - c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-07-07 08:27]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = https://www.scotiaitrade.com/pages/home/main.shtml
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=all&pf=cmnb
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3a9oy6u0.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.cknw.com/other/audiovault.html
    FF - component: c:\program files\SiteAdvisor\6173\FF\components\FFHook.dll
    FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    - - - - ORPHANS REMOVED - - - -
    BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2010-09-06 14:13
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    zCpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    CLJ = 63
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
    "ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    [HKEY_USERS\S-1-5-21-2394006169-2039493040-1202352694-500\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (Administrator)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,58,65,fc,bc,09,b3,bf,4b,9f,38,dd,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,58,65,fc,bc,09,b3,bf,4b,9f,38,dd,\
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    - - - - - - - > 'winlogon.exe'(912)
    c:\windows\system32\ackpbsc.dll
    c:\windows\system32\aclog.dll
    c:\windows\system32\accrypto.dll
    c:\windows\system32\ACLIBEAY.dll
    c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    c:\program files\Hewlett-Packard\IAM\bin\itmsg.dll
    c:\program files\ActivIdentity\ActivClient\acunlock.dll
    c:\windows\system32\aipingui.dll
    c:\windows\system32\acevtsub.dll
    c:\windows\system32\asphat32.dll
    c:\windows\system32\acerrmes.dll
    c:\windows\system32\aspcom.dll
    c:\windows\system32\aicext.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\acerrmrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\asphatrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\aipinguirc.dll
    c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
    c:\program files\ActivIdentity\ActivClient\Resources\Localized\acunlockrc.dll
    c:\windows\system32\DeviceNP.dll
    c:\windows\system32\SSREGLIB.dll
    c:\windows\system32\HPPTLog.dll
    c:\program files\Hewlett-Packard\IAM\Bin\TrayIcon.dll
    c:\program files\Hewlett-Packard\IAM\bin\brand.dll
    c:\program files\Hewlett-Packard\IAM\Bin\AsChnl.dll
    c:\program files\Hewlett-Packard\IAM\Bin\HPPlugIn.dll
    c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHostServices.dll
    c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTStrings.dll
    - - - - - - - > 'explorer.exe'(5092)
    c:\windows\system32\WININET.dll
    c:\windows\system32\APSHook.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\SCardSvr.exe
    c:\program files\Hewlett-Packard\IAM\Bin\AsGHost.exe
    c:\program files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\ActivIdentity\ActivClient\acevents.exe
    c:\windows\system32\msdtc.exe
    c:\program files\LSI SoftModem\agrsmsvc.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\McAfee\HackerWatch\HWAPI.exe
    c:\program files\McAfee\MPF\MPFSrv.exe
    c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
    c:\program files\SiteAdvisor\6173\SAService.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    c:\windows\system32\mqsvc.exe
    c:\windows\system32\mqtgsvc.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
    .
    **************************************************************************
    .
    Completion time: 2010-09-06 14:17:18 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-09-06 21:17
    ComboFix2.txt 2010-09-06 17:35
    ComboFix3.txt 2010-09-05 20:37
    ComboFix4.txt 2010-08-19 01:24
    ComboFix5.txt 2010-09-06 21:07
    Pre-Run: 205,363,302,400 bytes free
    Post-Run: 205,348,708,352 bytes free
    - - End Of File - - D69544FCB6F4E0CD9CF18554E8F97C69
  9. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    re: "Error loading dll files"

    Hello.
    We win, killed the TDL infection and fixed that error on startup.

    Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

    ComboFix /uninstall

    This will also reset your restore points.

    Run ESET Online Scan
    Please do an online scan with ESET Online Scanner. Please use Internet Explorer as it uses ActiveX.
    • Check (tick) this box: YES, I accept the Terms of Use.
    • Click on the Start button next to it.
    • When prompted to run ActiveX. click Yes.
    • You will be asked to install an ActiveX. Click Install.
    • Once installed, the scanner will be initialized.
    • After the scanner is initialized, click Start.
    • Check (tick) Remove found threats box.
    • Check (tick) Scan unwanted applications.
    • Click on Scan.
    • It will start scanning. Please be patient.
    • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.
  10. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
  11. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    re: "Error loading dll files"

    Yes will do, but one more thing I want you to read through here.

    We need to make a new restore point.

    To turn off System Restore, follow these steps:
    1. Click Start, right-click My Computer, and then click Properties.
    2. Click the System Restore tab.
    3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
    4. Click Yes when you receive the prompt to the turn off System Restore.

    Now we need to make a new restore point.
    To turn on System Restore, follow these steps:
    1. Click Start, right-click My Computer, and then click Properties.
    2. Click the System Restore tab.
    3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.

    Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. :p

    1) Please navigate to Microsoft Windows Update and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

    Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

    2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

    Ad-Aware SE
    A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

    Spybot-Search & Destroy
    A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

    Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

    3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
    Firefox web browser | Faster, more secure, & customizable
    I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
    https://addons.mozilla.org/en-US/firefox/addon/722
    https://addons.mozilla.org/en-US/firefox/addon/1865
    https://addons.mozilla.org/en-US/firefox/addon/433

    4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

    To help you keep your software updated, please considering using this free software program that will check for program updates.
    Update Checker

    5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
    Outpost
    A tutorial on understanding and using firewalls may be found here.

    Please also read Tony Klein's excellent article: How I got Infected in the First Place

    Hopefully this should take care of your problems! Good luck. :D
  12. dfly Gold Member

    Gold
    Message Count:
    240
    Likes Received:
    2
    My System
    Loading...
    re: "Error loading dll files"

    Done.. Thanks once again!

"Error loading dll files"

Thread Status:
Not open for further replies.