Tomk,
Many thanks for your help. Couple of observations before I post your requested info: 1. "Attach" shows Ad-Aware as installed, but I uninstalled it a long time ago. 2. "DDS" shows Trend Microvirus and Lavasoft at top: both uninstalled a long time ago. 3. The Windows Defender disable instructions did not match my Windows Defender options, I hope I turned it off correctly.
Here is the DDS.txt report:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:43:45.34 on Mon 07/06/2009
Internet Explorer: 7.0.6000.16851 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1225 [GMT -4:00]
AV: Trend Micro AntiVirus - Virus Protection *On-access scanning enabled* (Updated) {9596F8E6-38C3-4C51-80B9-8C94D2E25B07}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Trend Micro AntiVirus - Spyware Protection *enabled* (Updated) {7241C815-3D0F-4059-9AF4-BF225B1D78B9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\hp\kbd\kbd.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Tomas de Torquemada\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://broadband.zoomtown.com
mStart Page = hxxp://broadband.zoomtown.com
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\tomasd~1\appdata\roaming\mozilla\firefox\profiles\6ar7u071.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.catholicculture.org/culture/liturgicalyear/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-21 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-22 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-22 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-22 298776]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
=============== Created Last 30 ================
2009-06-30 17:55 –d—– c:\program files\Trend Micro
2009-06-28 01:44 –d—– C:\PerfLogs
2009-06-27 22:24 –d—– C:\b144cf093e9e7c9bcf1b
2009-06-25 17:32 –d—– c:\program files\Microsoft
2009-06-24 22:55 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-24 22:55 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-24 22:55 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-24 22:55 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-24 22:55 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-24 22:55 11,264 a——- c:\windows\system32\icardres.dll
2009-06-24 22:55 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-24 22:55 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-24 22:44 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-24 22:44 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-24 22:43 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-24 22:43 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-24 22:43 83,968 a——- c:\windows\system32\mscories.dll
2009-06-24 22:36 696,832 a——- c:\windows\system32\localspl.dll
2009-06-24 22:36 2,028,032 a——- c:\windows\system32\win32k.sys
2009-06-24 22:35 788,992 a——- c:\windows\system32\rpcrt4.dll
2009-06-23 08:44 –d-h— C:\$AVG8.VAULT$
2009-06-22 09:30 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-22 09:30 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 09:30 327,688 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 09:30 –d—– c:\windows\system32\drivers\Avg
2009-06-22 09:30 –d—– c:\programdata\AVG Security Toolbar
2009-06-22 09:30 –d—– c:\progra~2\AVG Security Toolbar
2009-06-22 09:29 –d—– c:\program files\AVG
2009-06-17 21:55 –d—– c:\users\tomas de torquemada\{f3ac81ae-0593-4ff7-90fc-fce7e128dee5}
2009-06-13 21:14 428,032 a——- c:\windows\system32\EncDec.dll
2009-06-13 21:14 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-13 21:14 292,352 a——- c:\windows\system32\psisdecd.dll
2009-06-13 21:14 1,244,672 a——- c:\windows\system32\mcmde.dll
2009-06-13 21:14 177,152 a——- c:\windows\system32\mpg2splt.ax
2009-06-13 21:14 68,608 a——- c:\windows\system32\Mpeg2Data.ax
2009-06-13 21:14 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-13 21:14 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-10 15:26 –d—– c:\users\tomasd~1\appdata\roaming\PCToolsFirewallPlus
2009-06-10 15:21 –d—– c:\program files\ThreatFire
2009-06-09 22:19 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 22:19 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-09 22:19 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-09 18:17 a-d—– c:\programdata\TEMP
2009-06-09 18:17 –d—– c:\program files\common files\PC Tools
2009-06-06 14:30 213 a——- c:\windows\Quicken.ini
2009-06-06 14:30 –d—– c:\program files\common files\Palo Alto Software
2009-06-06 14:30 –d—– c:\program files\common files\Intuit
==================== Find3M ====================
2009-06-25 17:35 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-25 17:35 51,200 a——- c:\windows\inf\infpub.dat
2009-06-25 17:34 86,016 a——- c:\windows\inf\infstor.dat
2009-04-24 12:22 827,392 a——- c:\windows\system32\wininet.dll
2009-04-24 12:14 56,320 a——- c:\windows\system32\iesetup.dll
2009-04-24 12:14 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 12:14 52,736 a——- c:\windows\apppatch\iebrshim.dll
2009-04-24 12:11 72,704 a——- c:\windows\system32\admparse.dll
2009-04-24 09:53 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-24 08:25 48,128 a——- c:\windows\system32\mshtmler.dll
2009-04-11 17:49 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-11 07:32 174 a–sh— c:\program files\desktop.ini
2008-06-12 07:53 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-08-25 15:37 22 a–sh— c:\windows\sminst\HPCD.sys
============= FINISH: 10:44:23.37 ===============
The Attach.txt file is uploaded. Thanks.