Windows XP Home may have infections?

Started by Ghost, September 17, 2015, 12:43:42 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Corrine

Hi, Ghost.  It appears that McAfee is "stuck" in the Windows Security Center.  ComboFix can remove the reference since McAfee is no longer installed.  If you still get a caution, please let me know.

Custom CFScript

Note: The following instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.



  • Please open Notepad (Click Start -> Run -> type notepad in the Open field -> OK).  Copy/Paste all of the text present inside the code box below:


SecCenter::


  • Save this as CFScript.txt and place it on your desktop.
  • Close any open browsers.
  • Close/disable all antivirus and anti-malware programs so they do not interfere with the running of ComboFix.





  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Ghost

Hi Corrine.
I dont seem to be getting the mcafee error now;-).
ComboFix 15-09-07.01 - coolcee 09/19/2015  15:53:25.2.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.510.235 [GMT -4:00]
Running from: c:\documents and settings\coolcee\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\coolcee\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
(((((((((((((((((((((((((   Files Created from 2015-08-19 to 2015-09-19  )))))))))))))))))))))))))))))))
.
.
2015-09-19 16:29 . 2015-09-19 16:29   --------   d-----w-   c:\documents and settings\coolcee\Application Data\AVAST Software
2015-09-19 16:20 . 2015-09-19 16:20   208664   ----a-w-   c:\windows\system32\drivers\aswVmm.sys
2015-09-19 16:20 . 2015-09-19 16:20   434184   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2015-09-19 16:20 . 2015-09-19 16:20   49776   ----a-w-   c:\windows\system32\drivers\aswRvrt.sys
2015-09-19 16:20 . 2015-09-19 16:20   76000   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2015-09-19 16:20 . 2015-09-19 16:20   24016   ----a-w-   c:\windows\system32\drivers\aswHwid.sys
2015-09-19 16:20 . 2015-09-19 16:20   55200   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2015-09-19 16:20 . 2015-09-19 16:18   789296   ----a-w-   c:\windows\system32\drivers\aswSnx.sys
2015-09-19 16:20 . 2015-09-19 16:18   313472   ----a-w-   c:\windows\system32\aswBoot.exe
2015-09-19 16:18 . 2015-09-19 16:18   43112   ----a-w-   c:\windows\avastSS.scr
2015-09-19 16:11 . 2015-09-19 16:27   --------   d-----w-   c:\program files\Avast
2015-09-19 15:51 . 2015-09-19 15:51   --------   d-----w-   c:\documents and settings\All Users\Application Data\AVAST Software
2015-09-19 00:59 . 2008-04-14 02:57   79872   ------w-   c:\windows\system32\dllcache\msxml6r.dll
2015-09-19 00:59 . 2009-07-31 15:05   1372672   ------w-   c:\windows\system32\msxml6.dll
2015-09-19 00:59 . 2009-07-31 15:05   1372672   ------w-   c:\windows\system32\dllcache\msxml6.dll
2015-09-19 00:59 . 2008-04-14 02:57   79872   ------w-   c:\windows\system32\msxml6r.dll
2015-09-19 00:48 . 2008-04-14 09:41   4255   ------w-   c:\windows\system32\drivers\adv01nt5.dll
2015-09-19 00:47 . 2008-04-14 09:42   11325   ------w-   c:\windows\system32\drivers\vchnt5.dll
2015-09-19 00:47 . 2008-04-14 04:26   12800   ------w-   c:\windows\system32\drivers\usb8023x.sys
2015-09-19 00:47 . 2008-04-14 04:06   44672   ------w-   c:\windows\system32\drivers\uagp35.sys
2015-09-19 00:47 . 2008-04-14 04:06   5888   ------w-   c:\windows\system32\drivers\smbali.sys
2015-09-19 00:47 . 2008-04-14 03:53   13240   ------w-   c:\windows\system32\drivers\slwdmsup.sys
2015-09-19 00:47 . 2008-04-14 04:13   14208   ------w-   c:\windows\system32\drivers\wacompen.sys
2015-09-19 00:47 . 2008-04-14 02:04   25471   ------w-   c:\windows\system32\drivers\watv10nt.sys
2015-09-19 00:47 . 2008-04-14 02:04   22271   ------w-   c:\windows\system32\drivers\watv06nt.sys
2015-09-19 00:47 . 2008-04-14 02:04   11935   ------w-   c:\windows\system32\drivers\wadv11nt.sys
2015-09-19 00:47 . 2008-04-14 02:04   11871   ------w-   c:\windows\system32\drivers\wadv09nt.sys
2015-09-19 00:47 . 2008-04-14 02:04   11807   ------w-   c:\windows\system32\drivers\wadv07nt.sys
2015-09-19 00:47 . 2008-04-14 02:04   11295   ------w-   c:\windows\system32\drivers\wadv08nt.sys
2015-09-19 00:39 . 2015-09-19 00:39   --------   d-----w-   c:\windows\EHome
2015-09-19 00:28 . 2015-09-19 02:17   --------   d-----w-   C:\219139e4c70a557a317b
2015-09-18 15:15 . 2015-09-18 15:15   --------   d-----w-   c:\documents and settings\All Users\Application Data\Licenses
2015-09-18 15:15 . 2012-05-02 16:17   1070152   ----a-w-   c:\windows\system32\MSCOMCTL.OCX
2015-09-18 15:15 . 2009-03-24 16:52   129872   ----a-w-   c:\windows\system32\MSSTDFMT.DLL
2015-09-18 15:15 . 2015-09-18 15:24   --------   d-----w-   c:\program files\SpywareBlaster
2015-09-18 15:14 . 2015-09-18 15:39   --------   d-----w-   c:\program files\SpywareGuard
2015-09-18 13:05 . 2015-09-18 13:06   --------   d-----w-   c:\program files\SP3
2015-09-18 01:10 . 2015-09-18 01:10   --------   d-sh--w-   c:\documents and settings\NetworkService\PrivacIE
2015-09-18 01:10 . 2015-09-18 01:10   --------   d-sh--w-   c:\documents and settings\NetworkService\UserData
2015-09-18 01:10 . 2015-09-18 01:10   --------   d-sh--w-   c:\documents and settings\NetworkService\IECompatCache
2015-09-18 01:04 . 2004-08-10 21:05   14240   ----a-w-   c:\windows\system32\drivers\wg6n.sys
2015-09-18 01:04 . 2004-08-10 21:05   14240   ----a-w-   c:\windows\system32\drivers\wg5n.sys
2015-09-18 01:04 . 2004-08-10 21:05   14240   ----a-w-   c:\windows\system32\drivers\wg4n.sys
2015-09-18 01:04 . 2004-08-10 21:05   14240   ----a-w-   c:\windows\system32\drivers\wg3n.sys
2015-09-18 01:04 . 2004-08-10 20:53   21075   ----a-w-   c:\windows\system32\drivers\wpsdrvnt.sys
2015-09-18 01:04 . 2004-08-10 20:51   59984   ----a-w-   c:\windows\system32\drivers\Teefer.sys
2015-09-18 01:04 . 2004-08-10 21:05   83096   ----a-w-   c:\windows\system32\SSSensor.dll
2015-09-18 01:04 . 2015-09-18 01:04   --------   d-----w-   c:\program files\Sygate
2015-09-18 01:03 . 2015-09-18 01:03   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2015-09-18 00:49 . 2015-09-18 00:49   --------   d-----w-   c:\documents and settings\coolcee\Application Data\SumatraPDF
2015-09-18 00:49 . 2015-09-18 00:49   --------   d-----w-   c:\program files\SumatraPDF
2015-09-17 02:31 . 2015-09-17 03:12   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2015-09-17 00:34 . 2015-09-17 02:21   --------   d-----w-   C:\FRST
2015-09-16 20:53 . 2015-09-17 02:31   170200   ----a-w-   c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-09-16 20:52 . 2015-09-17 02:25   121560   ----a-w-   c:\windows\system32\drivers\mbamchameleon.sys
2015-09-16 20:52 . 2015-09-16 20:56   --------   d-----w-   c:\program files\Malwarebytes Anti-Malware
2015-09-16 20:52 . 2015-09-16 20:52   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2015-09-16 20:52 . 2015-06-18 12:41   23256   ----a-w-   c:\windows\system32\drivers\mbam.sys
2015-09-16 20:47 . 2015-09-16 20:47   --------   d-----w-   c:\program files\7-Zip
2015-09-16 20:47 . 2015-09-16 20:49   --------   d-----w-   c:\program files\Power Defrag
2015-09-16 20:34 . 2015-09-16 20:34   --------   d-----w-   c:\program files\Mozilla Maintenance Service
2015-09-16 20:27 . 2015-09-16 20:27   --------   d-----w-   c:\documents and settings\coolcee\Local Settings\Application Data\Mozilla
2015-09-16 18:32 . 2015-09-16 18:33   --------   d-----w-   c:\program files\CCleaner
2015-09-16 18:28 . 2015-09-16 18:28   --------   d-----w-   c:\program files\VS Revo Group
2015-09-15 22:25 . 2004-08-04 04:56   21504   ------w-   c:\windows\system32\hidserv.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-09-19 16:18   696120   ----a-w-   c:\program files\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-08-13 2532576]
"AvastUI.exe"="c:\program files\Avast\AvastUI.exe" [2015-09-19 6134544]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
2005-08-31 17:06   106496   ----a-w-   c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 11:00   15360   ------w-   c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-02-23 22:19   53248   ------w-   c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-04-06 01:19   77824   ----a-w-   c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-04-06 01:22   94208   ----a-w-   c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 02:12   221184   ----a-w-   c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 16:44   249856   ----a-w-   c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 16:44   81920   ----a-w-   c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 09:42   1695232   ----a-w-   c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2005-04-06 01:23   114688   ----a-w-   c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-15 01:42   1404928   ----a-w-   c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [9/19/2015 12:20 PM 49776]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [9/19/2015 12:20 PM 208664]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9/19/2015 12:20 PM 789296]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9/19/2015 12:20 PM 434184]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [9/19/2015 12:20 PM 24016]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [9/19/2015 12:20 PM 76000]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/16/2015 4:52 PM 23256]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [9/16/2015 4:52 PM 1133880]
S4 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [9/16/2015 4:52 PM 1871160]
.
Contents of the 'Scheduled Tasks' folder
.
2015-09-19 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Avast\AvastEmUpdate.exe [2015-09-19 16:18]
.
2015-09-19 c:\windows\Tasks\User_Feed_Synchronization-{7BB9EFBE-0EB2-4B05-A0C7-DE9E7907DF5E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\documents and settings\coolcee\Application Data\Mozilla\Firefox\Profiles\wult6a61.default-1442591269296\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/?gws_rd=ssl
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-09-19 16:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2376)
c:\windows\system32\SSSensor.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2015-09-19  16:08:27
ComboFix-quarantined-files.txt  2015-09-19 20:08
ComboFix2.txt  2015-09-19 17:15
.
Pre-Run: 64,138,178,560 bytes free
Post-Run: 64,129,200,128 bytes free
.
- - End Of File - - 7C4DC1F96BAAC284601961C040E68391
91722E6BC3A2B40FF00222DCA4A3DB3E

Corrine

Maybe not but the Security Center is still wrong and I haven't seen any signs of McAfee in Programs or in registry entries from the logs.

AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

This works for all versions of Windows (see How do I restore security settings to a known working state?).

  • Click Start > Run > type cmd >  Press Enter >
  • Type or copy/paste the following and press Enter again:
    secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
  • Wait for the "Task Is Completed" message and then restart the computer.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Ghost

Hi Corrine,
Followed instructions for cmd command and get this in the cmd window:

'secedit' is not recognized as an internal or external command, operable program or batch file



Corrine

Security Check showed:  "Windows Security Center service is not running!"  In addition, CF is still showing McAfee.  Just one last thing before cleaning up the tools we used: 

Type services.msc in the Run box.  Then check that wscsvc is Started and set to Automatic.

Again, my encouragement to convince the person to use Linux until a new computer is purchased, most especially if there will be anything related to finances.

Please download Delfix from here.

Ensure the following boxes are checked:
  • Remove disinfection tools
  • Create registry backup
  • Purge system restore

  • Click Run
The program will run for a few moments and then notepad will open with a log.   Please paste the log in your next reply.



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Ghost

Hi Corrine,
QuoteThen check that wscsvc is Started and set to Automatic.
It is started and set to automatic;-).
# DelFix v1.011 - Logfile created 19/09/2015 at 21:07:16
# Updated 18/08/2015 by Xplode
# Username : coolcee - BIGCEE
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\Combofix
Deleted : C:\FRST
Deleted : C:\ComboFix.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\Addition.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\ComboFix.exe
Deleted : C:\Documents and Settings\coolcee\Desktop\ComboFix.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\ComboFix2.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\Fixlog.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\FRST.exe
Deleted : C:\Documents and Settings\coolcee\Desktop\FRST.txt
Deleted : C:\Documents and Settings\coolcee\Desktop\SecurityCheck.exe
Deleted : C:\Documents and Settings\coolcee\Desktop\TFC.exe
Deleted : C:\WINDOWS\grep.exe
Deleted : C:\WINDOWS\PEV.exe
Deleted : C:\WINDOWS\NIRCMD.exe
Deleted : C:\WINDOWS\MBR.exe
Deleted : C:\WINDOWS\SED.exe
Deleted : C:\WINDOWS\SWREG.exe
Deleted : C:\WINDOWS\SWSC.exe
Deleted : C:\WINDOWS\SWXCACLS.exe
Deleted : C:\WINDOWS\Zip.exe
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #677 [Installed Windows XP KB955069. | 09/19/2015 01:19:14]
Deleted : RP #678 [Installed Windows XP KB973687. | 09/19/2015 01:20:25]
Deleted : RP #679 [Installed Windows XP KB955759. | 09/19/2015 01:21:37]
Deleted : RP #680 [Installed Windows XP KB956572. | 09/19/2015 01:22:56]
Deleted : RP #681 [Installed Windows XP KB956802. | 09/19/2015 01:24:20]
Deleted : RP #682 [Installed Windows XP KB956803. | 09/19/2015 01:25:29]
Deleted : RP #683 [Installed Windows XP KB956844. | 09/19/2015 01:26:38]
Deleted : RP #684 [Installed Windows XP KB958644. | 09/19/2015 01:27:48]
Deleted : RP #685 [Installed Windows XP KB959426. | 09/19/2015 01:28:58]
Deleted : RP #686 [Installed Windows XP KB960225. | 09/19/2015 01:30:12]
Deleted : RP #687 [Installed Windows XP KB960803. | 09/19/2015 01:31:21]
Deleted : RP #688 [Installed Windows XP KB960859. | 09/19/2015 01:32:33]
Deleted : RP #689 [Installed Windows XP KB961501. | 09/19/2015 01:33:44]
Deleted : RP #690 [Installed Windows XP KB967715. | 09/19/2015 01:35:02]
Deleted : RP #691 [Installed Windows XP KB968389. | 09/19/2015 01:36:21]
Deleted : RP #692 [Installed Windows XP KB969059. | 09/19/2015 01:37:35]
Deleted : RP #693 [Installed Windows XP KB970238. | 09/19/2015 01:38:45]
Deleted : RP #694 [Installed Windows XP KB970430. | 09/19/2015 01:39:56]
Deleted : RP #695 [Installed Windows XP KB971468. | 09/19/2015 01:41:06]
Deleted : RP #696 [Installed Windows XP KB971657. | 09/19/2015 01:42:16]
Deleted : RP #697 [Installed Windows XP KB971737. | 09/19/2015 01:43:26]
Deleted : RP #698 [Installed Windows XP KB972270. | 09/19/2015 01:44:45]
Deleted : RP #699 [Installed Windows XP KB973507. | 09/19/2015 01:45:55]
Deleted : RP #700 [Installed Windows XP KB973687. | 09/19/2015 01:47:05]
Deleted : RP #701 [Installed Windows XP KB973815. | 09/19/2015 01:48:15]
Deleted : RP #702 [Installed Windows XP KB973869. | 09/19/2015 01:49:26]
Deleted : RP #703 [Installed Windows XP KB974112. | 09/19/2015 01:50:37]
Deleted : RP #704 [Installed Windows XP KB974318. | 09/19/2015 01:51:46]
Deleted : RP #705 [Installed Windows XP KB974392. | 09/19/2015 01:52:57]
Deleted : RP #706 [Installed Windows XP KB974571. | 09/19/2015 01:54:05]
Deleted : RP #707 [Installed Windows XP KB975025. | 09/19/2015 01:55:13]
Deleted : RP #708 [Installed Windows XP KB975467. | 09/19/2015 01:56:20]
Deleted : RP #709 [Installed Windows XP KB975560. | 09/19/2015 01:57:31]
Deleted : RP #710 [Installed Windows XP KB975561. | 09/19/2015 01:58:46]
Deleted : RP #711 [Installed Windows XP KB975562. | 09/19/2015 02:00:00]
Deleted : RP #712 [Installed Windows XP KB975713. | 09/19/2015 02:01:12]
Deleted : RP #713 [Installed Windows XP KB977914. | 09/19/2015 02:02:27]
Deleted : RP #714 [Installed Windows XP KB978037. | 09/19/2015 02:03:38]
Deleted : RP #715 [Installed Windows XP KB978338. | 09/19/2015 02:04:47]
Deleted : RP #716 [Installed Windows XP KB978542. | 09/19/2015 02:05:59]
Deleted : RP #717 [Installed Windows XP KB978601. | 09/19/2015 02:07:10]
Deleted : RP #718 [Installed Windows XP KB978706. | 09/19/2015 02:08:21]
Deleted : RP #719 [Installed Windows XP KB979309. | 09/19/2015 02:09:31]
Deleted : RP #720 [Installed Windows XP KB979482. | 09/19/2015 02:10:41]
Deleted : RP #721 [Installed Windows XP KB979559. | 09/19/2015 02:11:51]
Deleted : RP #722 [Installed Windows XP KB979683. | 09/19/2015 02:13:10]
Deleted : RP #723 [Installed Windows XP KB980218. | 09/19/2015 02:14:31]
Deleted : RP #724 [Installed Windows XP KB980232. | 09/19/2015 02:15:46]
Deleted : RP #725 [Revo Uninstaller's restore point - avast! Free Antivirus | 09/19/2015 14:27:23]
Deleted : RP #726 [avast! Free Antivirus Setup | 09/19/2015 14:28:59]
Deleted : RP #727 [avast! antivirus system restore point | 09/19/2015 16:12:53]
Deleted : RP #728 [Revo Uninstaller's restore point - Avast Free Antivirus | 09/20/2015 00:18:26]
Deleted : RP #729 [avast! antivirus system restore point | 09/20/2015 00:19:31]
Deleted : RP #730 [Revo Uninstaller's restore point - Avast Free Antivirus | 09/20/2015 00:22:10]
Deleted : RP #731 [avast! antivirus system restore point | 09/20/2015 00:33:18]

New restore point created !

########## - EOF - ##########

Thank you,
Ghost

Corrine

Let me know if the person takes you up on the offer to use Linux.  :)


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Ghost

Hi Corrine,
I will do that and thanks again for your help;-)
Ghost