Recent Posts

Pages: 1 2 [3] 4 5 ... 10
Thanks Bill and Bret for the new fixed update. New version running on all my computers now with no problems.   :thanks:
Meet & Greet! / Welcome Michaelsalis
« Last post by GR@PH;<'S on Today at 04:51:07 PM »
:welcome: hope you enjoy your stay. 

 GR@PH;<'S   :Hammys pint:
Meet & Greet! / Re: Welcome onDvine
« Last post by ProTruckDriver on Today at 04:44:58 PM »
Hi onDvine, :welcome2: Enjoy your stay.  :wink:
Here is the DDS:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.5.1
Run by Linda Ellis at 13:39:05 on 2014-07-23
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3317.1903 [GMT -4:00]
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ================
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Linda Ellis\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Ruiware\WinPatrol\WinPatrol.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
============== Pseudo HJT Report ===============
uStart Page = hxxp://
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.9012.1008\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WinPatrol] c:\program files\ruiware\winpatrol\winpatrol.exe -expressboot
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon
mRun: [WinPatrol [FREE Edition]] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [WinPatrol PLUS] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
StartupFolder: c:\docume~1\lindae~1\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\linda ellis\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\lindae~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://
TCP: NameServer =
TCP: Interfaces\{00F049BB-98E3-4B07-83B1-92E17AD448C5} : DHCPNameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\documents and settings\linda ellis\application data\mozilla\firefox\profiles\9712rryy.default\
FF - prefs.js: browser.startup.homepage - hxxp://
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_14_0_0_145.dll
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2013-1-10 134248]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2013-1-10 118768]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2013-9-12 1337752]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-3-24 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-3-24 860472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-5-27 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-3-25 110296]
S0 cerc6;cerc6;

=============== Created Last 30 ================
2014-07-23 15:40:27   --------   d-----w-   c:\documents and settings\linda ellis\application data\WinPatrol
2014-07-23 15:40:17   --------   d-----w-   c:\program files\Ruiware
==================== Find3M  ====================
2014-07-23 17:29:43   110296   ----a-w-   c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-09 01:14:44   71344   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 01:14:44   699056   ----a-w-   c:\windows\system32\FlashPlayerApp.exe
2014-06-06 10:47:08   4558848   ----a-w-   c:\windows\system32\GPhotos.scr
2014-05-12 11:26:02   53208   ----a-w-   c:\windows\system32\drivers\mbamchameleon.sys
2014-05-12 11:25:54   23256   ----a-w-   c:\windows\system32\drivers\mbam.sys
2014-05-12 10:58:33   107736   ----a-w-   c:\windows\system32\drivers\48230029.sys
============= FINISH: 13:39:27.73 ===============

I got this message at the top of the Attach.txt:

DDS (Ver_2012-11-20.01)


So, please advise if I have to attach this one in full.  Thank you. 
LandzDown Lounge / Re: Word Association
« Last post by onDvine on Today at 03:34:07 PM »
Hi, Linda.

To explain the %username% for future reference, that is the username of your account.  Thus, looking back at your log, it would be in C:\DOCUMENTS AND SETTINGS\LINDA ELLIS\APPLICATION DATA\.  I believe the removal tool would have taken care of it anyway so nothing to be concerned with now.

As to the comparison between the screen copies, the before uninstall has the Display secret startup locations box checked and the new image does not have that checked.  Also, the programs that were disabled (e.g. Easyshare) are not listed due to having run the WinPatrol Removal Program.

That said, you do now have the Ruiware folder shown but there are still two entries showing for WinPatrol PLUS with "file does not exist".  I don't know if I can track down what is going on but if you would like to dig deeper, different logs may help.  If you wish to proceed, please do the following:

Download DDS.scr by sUBs from here and save it to your desktop.
  • Disable any script blocker and then double-click dds.scr to run.
  • Shortly after two logs will appear, DDS.txt & Attach.txt
  • The logs will automatically be saved to your desktop.
  • Copy the contents of both logs & post in your next reply
Hi again.  Well, I went through all of the steps.  In your # 6 though now where could I find a %User%.  So, I had to keep going without it.  I am looking now at the Start Up programs, and there are a lot less than before.  I had done a screen print (two screen prints) of what I had before.  I am missing Kodak Easyshare and Malwarebytes at first glance through it.  When I went into the add/remove step and removed the only Winpatrol I had which appeared to be the old version, there was a question about keeping the settings, and I clicked on yes.  So, not only did settings change, but I lost some of the programs now in the start up list that were there.  Please let me know what to do. 

Thanks very much for your swift reply and solution to my question.


WinPatrol version 32 creates a new directory, Ruiware, to hold the WinPatrol v32 files.

Installing version 32.0 also left both the BillP directory (fully populated with files for version 31), as well as a Control Panel Removal entry for version 31.   Meaning you'd have both versions 31 and 32 "co-existing" on your disk system.   In this case, you could then run the Control Panel uninstaller for version 31 to properly remove it.   However, doing so might also remove some of the WinPatrol entries from your START menu... but if so, it's a simple enough matter to then reinstall v32 again.   [Note:  I am writing from experience on Win7 and WinXP... there might be some differences on Win8.x]

In contrast, while installing Version 32.5 also leaves the BillP directory (with files from version 31), it eliminates the Control Panel removal entry for it.   In this case, the BillP directory can/should be manually deleted.

But this explains why FileHippo and Secunia were still finding files, in the BillP directory, for the older version.   Just uninstall version 31 (if the uninstaller is still available, as it should be after 32.0) or else, delete the BillP directory (if you installed 32.5).

A little messy to explain, but I hope I've done an adequate job.

P.S.  For reference to anyone else, it would much cleaner/simpler to UNinstall v31 first, before installing v32.   This avoids all the "double folder" issues.
I have become a little confused with this matter.

I have a Windows Surface Pro 2 running 8.1 downloaded the latest version of WinPatrol a couple of days ago on this and a couple of other laptops I own a. Windows 7 Ultimate b. Vista Ultimate. I have not checked those yet to see if the same situation exists.

I am a first time user of this forum linking from the WinPatrol website. On reading this post I noticed that there was WinPatrol versions 31 and 32 listed in the Windows list of programs. I downloaded and re-installed WinPatrol v32 again rebooted and the v31 no longer showed in the program list.

However, I use Filhippo update check and Secunia PSI to check for new versions of programs. Both these programs show that I still have the files of the old version from BillPStudios on the on the Surface with PSI still showing the folder and all the files of this version.

I am now at a loss as to what to do, can anybody please help me in this matter.

Many thanks.

Pages: 1 2 [3] 4 5 ... 10