Home > Outlook Express > Outlook Express EL2k_XP.sys Exe Missing

Outlook Express EL2k_XP.sys Exe Missing

Install Autoruns. Malwarebytes' Anti-Malware 1.34 Database version: 1826 Windows 5.1.2600 Service Pack 3 8/03/2009 9:04:30 PM mbam-log-2009-03-08 (21-04-30).txt Scan type: Full Scan (C:\|) Objects scanned: 128810 Time elapsed: 43 minute(s), 38 second(s) Memory It has done this 1 time(s). 8/03/2009 10:26:00 AM, error: Srv [2019] - The server was unable to allocate from the system nonpaged pool because the pool was empty. 8/03/2009 1:36:44 TDI RDR Driver(Verified) ALWIL Softwarec:\windows\system32\drivers\aswrdr.sys+ aswTdiavast! http://osuweb.net/outlook-express/need-help-in-outlook-express.php

Thanks Phill DDS (Ver_09-02-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 13/07/2008 4:23:33 PM System Uptime: 3/09/2009 4:28:23 PM (-4272 hours ago) Motherboard: ASUSTeK Computer Inc. | | P4P800 Despite my question if you think i'm smart ^_^ . c:\windows\system32\svchost.exe . . . So we assumed he were talking about the programme "Autoruns".

If this service is disabled spyware protection will be disabled.(Verified) PC Toolsc:\anti-rootkit\spyware doctor\pctssvc.exe+ seclogonEnables starting processes under alternate credentials. Contents of the 'Scheduled Tasks' folder 2009-03-07 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 15:31] 2009-03-07 c:\windows\Tasks\Spybot - Search & Destroy Updater First : Autorun asking me to install Security Task Manager have been execute by Spyware Doctor as a malicious, so i install Glarysoft Security process Explorer & work fine . Thank you very much Help me if you think i'm handsome ^_^ .

poor, i apologize for makeModerator Karlchenmisunderstanding, sorry . Get Sysinternals Autoruns. So this sounds as if youeither downloaded a manipulated copy somewhere or some malware already on your disk before Autoruns manipulated the executable file or the demand to install Security Task NEVER A OR CHANGE ANY KEY*] "??"=hex:66,94,cc,f3,0c,5e,a5,d8,bb,b4,9e,29,d1,b5,ab,55,2d,74,af,58,3b,88,42, b4,53,fc,7d,45,62,06,5a,f7,9e,9c,95,9c,0c,a9,11,d0,18,f7,08,70,f7,72,9e,37,\ "??"=hex:2f,b6,6f,45,ee,e2,ec,0a,29,d5,69,d3,55,fd,2c,18 [HKEY_USERS\S-1-5-21-1004336348-1364589140-839522115-1003\Software\SecuROM\License information*] "datasecu"=hex:df,f4,07,a6,e3,cd,8f,92,4c,6a,a5,88,20,37,0f,89,a9,65,27,89,be, f6,db,f1,ee,1f,cb,8b,56,50,c9,06,2e,3b,a3,48,c6,28,b1,d3,fc,29,75,6f,d7,50,\ "rkeysecu"=hex:49,ad,0a,06,c6,9f,3b,a1,ac,01,13,5b,fa,e9,24,10 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,32,5e,54,ef,19, 9e,0f,ac,2e,e8,e1,00,eb,16,2b,de,53,e4,18,3d,00,7d,2c,ed,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,2d,f0,e6,35,45, f6,a3,1a,46,47,15,b0,92,4b,c7,ef,33,93,86,0a,4c,1a,ab,ee,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,0f,c3,a7,df,e9, 35,c5,6b,7a,45,05,fd,91,e8,6f,31,03,c8,a6,4f,fe,da,07,69,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment"

First : Autorun asking me to install Security Task Manage ...Where did you get your copy of Autoruns from? The Windows File Protection window pops up. c:\windows\explorer.exe . . . mfesmfk: system32\drivers\mfesmfk.sys (manual start)MidiSyn: system32\drivers\MidiSyn.sys (manual start)NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)MPFP: System32\Drivers\Mpfp.sys (system)McAfee Personal Firewall Service: "C:\Program Files\McAfee\MPF\MPFSrv.exe" (autostart)WebDav Client

Thanks again. antivirus services for this computer. I would appreciate help Thank you Ed Sevice pack SP2 Sorry Remove Advertisements Sponsored Links TechSupportForum.com Advertisement 10-17-2010, 11:27 PM #2 spunk.funk TSF Team, Emeritus Join If anyone could please take a look at it I would appreciate it.

scan completed successfully hidden processes: 7 hidden files: 38 --------------------\\ Searching for other infections No other infections found ! [F:2538][D:27]-> C:\DOCUME~1\phill\LOCALS~1\Temp [F:35][D:0]-> C:\DOCUME~1\phill\Cookies [F:1088][D:4]-> C:\DOCUME~1\phill\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - Mon https://support.microsoft.com/en-my/help/235300/olexp-outlook-express-5-starts-very-slowly Sign Up All Content All Content Advanced Search Browse Forums Guidelines Staff Online Users Members More Activity All Activity My Activity Streams Unread Content Content I Started Search More Malwarebytes.com Malwarebytes I had alreaddy exited from AVG. Third : Can anyone introduce a " super " repair application to meI tend to assume you need a super anti-malware programme much more than a super repair application.

If this service is stopped, this list will not be updated or maintained. navigate to this website Press F5 next in order to refresh the list. Windows, I hope I understand you right now: You used Google and looked for information about Windows automatic startup locations. (I.e. is infected!!

Thanks for any assistance. If this service is stopped, these connections will be unavailable. What do I do? http://osuweb.net/outlook-express/outlook-express.php Here are the two logs.

Turning this service off makes your machine vulnerable to such attacks.(Verified) PC Toolsc:\anti-rootkit\threatfire\tfservice.exe+ TrkWksMaintains links between NTFS files within a computer or across computers in a network domain.(Verified) Microsoft Windows Publisherc:\windows\system32\trkwks.dll+ You suspect that one or more of these programmes may have screwed up or infected your system with malware. Shell Extension(Verified) ALWIL Softwarec:\program files\alwil software\avast4\ashshell.dll+ Avi Properties HandlerMedia File Property Extractor Shell Extension(Verified) Microsoft Windows Publisherc:\windows\system32\shmedia.dll+ BandProxyShell Browser UI Library(Verified) Microsoft Windows Component Publisherc:\windows\system32\browseui.dll+ BriefcaseWindows Briefcase(Verified) Microsoft Windows Publisherc:\windows\system32\syncui.dll+ CDF

TRY IT...... 10-18-2010, 10:22 AM #4 AlbertMC2 Windows Tech Team Join Date: Jul 2010 Location: SA Posts: 1,930 OS: DOS 3.3 Hi El2k_xp.sys is a 3com network card

So depending on your 3com network card model you can go to 3com's site and manually download the latest driver. OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-09 17:32:06 EP_X0FF Members Profile Send Private Message Find Members Posts Add to Buddy List Senior Member Joined: 08 March 2006 Location: Russian Federation Status: Offline Points: 4758 Post Options Post Reply QuoteEP_X0FF Post Reply Page 12> Author Message Topic Search Topic OptionsPost ReplyCreate New Topic Printable Version Translate Topic Windows Members Profile Send Private Message Find Members Posts Add to Buddy List Newbie

If this service is disabled, any services that explicitly depend on it will fail to start.(Verified) Microsoft Windows Publisherc:\windows\system32\w32time.dll+ WebClientEnables Windows-based programs to create, access, and modify Internet-based files. Q: is CDROM (CDFS) R: is CDROM (UDF) S: is Removable T: is CDROM () U: is FIXED (NTFS) - 466 GiB total, 328.235 GiB free. ==== Disabled Device Manager Items It has done this 1 time(s). 8/03/2009 5:11:16 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started. 8/03/2009 5:11:18 PM, information: Windows File Protection [64017] - http://osuweb.net/outlook-express/outlook-express-cut-off.php A red dot will mark the selected drive(s) .

Your cache administrator is webmaster. Stopping or disabling this service will result in system instability.(Verified) Microsoft Windows Publisherc:\windows\system32\services.exe+ PolicyAgentManages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.(Verified) Microsoft Windows Publisherc:\windows\system32\lsass.exe+ ProtectedStorageProvides mfebopk: system32\drivers\mfebopk.sys (manual start)McAfee Inc.