This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser hijacker, trojans, I need help please

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I'm new here and need your help. I clicked on a link on tuesday and ended up noticing all my search results were being redirected in both IE and Mozilla Firefox. I got warnings from AVG about trojan viruses, so I did all my scans, AVG free, spybot, ad-aware, malwarebytes and tonight Super Anti Spyware. I had trojans and browser hijackers. After putting them in quarantine, I'm still having the same problems, alot of redirects. I have Hijack this if you want me to scan it and post here. Please help me, I'm at my wits end. I am also not that pc savvy, so I need someone patient. Thanks for any help you can give me. Kathy
Hello Chestersmama and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

I am also not that pc savvy, so I need someone patient.

Don't worry. if you have any questions or are unsure about anything at all just ask :)

Lets begin with a couple of system scans:


  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Right click on the DDS icon and select "Run as Administrator" to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you have any trouble getting the scans to complete come back and let me know.
Hi JonTom, thank you for your quick reply and for the patience. :thumbup: Here are the results from the first scans. DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 11:31:08.08 on 29/01/2011 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.4056.2090 [GMT -5:00] AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6} AV: AVG Internet Security 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Internet Security 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} ============== Running Processes =============== C:\PROGRA~2\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Program Files\Tablet\Pen\Pen_TouchService.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\AVG\AVG10\avgfws.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\rundll32.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\AVG\AVG10\avgam.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\conhost.exe C:\Windows\system32\Dwm.exe C:\Program Files\Tablet\Pen\Pen_TabletUser.exe C:\Windows\Explorer.EXE C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Tablet\Pen\Pen_TouchUser.exe C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe C:\Windows\system32\conhost.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\System32\StikyNot.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conhost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\conhost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\system32\sppsvc.exe C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe C:\PROGRA~2\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\servicing\TrustedInstaller.exe C:\Users\Kat\Desktop\dds(2).scr C:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uSearch Page = uStart Page = hxxp://ca.yahoo.com/?fr=fptb-msgr uSearch Bar = uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll uURLSearchHooks: H - No File mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe StartupFolder: C:\Users\Kat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe StartupFolder: C:\Users\Kat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLRE~1.LNK - c:\Windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C411C0047CC5.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Chuzzle%20Deluxe/Images/stg_drm.ocx DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-ca/wlscctrl2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Chuzzle%20Deluxe/Images/armhelper.ocx Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe mRun-x64: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe ================= FIREFOX =================== FF - ProfilePath - C:\Users\Kat\AppData\Roaming\Mozilla\Firefox\Profiles\v4ndfdaz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://search.avg.com/?d=4d3e674c&i;=23&tp;=ab&nt;=1&q;= FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll FF - component: C:\Program Files (x86)\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Kat\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll FF - plugin: C:\Users\Kat\AppData\Roaming\Mozilla\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Oberon GamesBar: [removed] - %profile%\extensions\[removed] FF - Ext: XUL Cache: {8bbe70ac-cb6e-4cb6-9799-5f41f1869c19} - %profile%\extensions\{8bbe70ac-cb6e-4cb6-9799-5f41f1869c19} FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - C:\Program Files (x86)\McAfee\SiteAdvisor FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox —- FIREFOX POLICIES —- FF - user.js: google.toolbar.linkdoctor.enabled - false ============= SERVICES / DRIVERS =============== R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288] R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2010-6-4 69152] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-1-13 55280] R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2010-7-12 57696] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752] R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-1-24 2850296] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136] R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG10\avgfws.exe [2010-11-22 3226632] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-7-12 1402272] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2011-1-13 101048] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-10 1153368] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-1-13 689472] R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2010-8-9 7329648] R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-8-9 719216] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-1-13 215552] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-17 136176] S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2011-1-24 84752] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-12-27 48488] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2010-8-11 17440] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-8-9 18288] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-13 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] =============== Created Last 30 ================ 2011-01-29 02:39:01 ——– d—–w- C:\Users\Kat\AppData\Roaming\SUPERAntiSpyware.com 2011-01-29 02:39:01 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com 2011-01-29 02:38:54 ——– d—–w- C:\PROGRA~3\!SASCORE 2011-01-29 02:38:51 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2011-01-27 05:03:04 388096 —-a-r- C:\Users\Kat\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-01-27 03:38:04 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-01-26 17:30:45 ——– d—–w- C:\PROGRA~3\XoftSpySE 2011-01-26 05:14:13 ——– d—–w- C:\Users\Kat\AppData\Roaming\Malwarebytes 2011-01-26 05:14:08 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-01-26 05:14:07 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-01-26 05:14:03 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-01-26 05:14:03 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-01-25 06:14:08 ——– d–h–w- C:\$AVG 2011-01-25 06:02:25 ——– d—–w- C:\Users\Kat\AppData\Roaming\AVG10 2011-01-25 06:01:39 ——– d–h–w- C:\PROGRA~3\Common Files 2011-01-25 06:01:11 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-01-25 06:00:01 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-01-25 06:00:01 ——– d—–w- C:\PROGRA~3\AVG10 2011-01-25 05:59:16 ——– d—–w- C:\Program Files (x86)\AVG 2011-01-25 05:52:21 ——– d—–w- C:\PROGRA~3\MFAData 2011-01-24 16:47:23 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware 2011-01-23 05:21:40 ——– d—–w- C:\Users\Kat\AppData\Roaming\PC Tools 2011-01-23 05:21:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2011-01-23 05:20:05 ——– d—–w- C:\PROGRA~3\PC Tools 2011-01-23 04:40:26 14336 —-a-w- C:\Windows\System32\drivers\sffp_sd.sys 2011-01-23 04:21:31 77312 —-a-w- C:\Windows\SysWow64\ztvunace26.dll 2011-01-23 04:21:31 75264 —-a-w- C:\Windows\SysWow64\unacev2.dll 2011-01-23 04:21:31 69632 —-a-w- C:\Windows\SysWow64\ztvcabinet.dll 2011-01-23 04:21:31 162304 —-a-w- C:\Windows\SysWow64\ztvunrar36.dll 2011-01-23 04:21:31 153088 —-a-w- C:\Windows\SysWow64\unrar3.dll 2011-01-21 06:34:01 ——– d-sh–w- C:\PROGRA~3\573C378827FA540FAC0018382186D4EE 2011-01-15 05:49:27 ——– d—–w- C:\Users\Kat\AppData\Local\Opera ==================== Find3M ==================== 2011-01-25 05:45:59 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2010-12-08 09:12:36 308304 —-a-w- C:\Windows\System32\drivers\avgldx64.sys 2010-12-06 14:07:37 15880 —-a-w- C:\Windows\System32\lsdelete.exe 2010-12-03 06:47:07 952 –sha-w- C:\PROGRA~3\KGyGaAvL.sys 2010-12-03 06:47:07 88 –sh–r- C:\PROGRA~3\65ADCA5E85.sys 2010-11-29 22:38:30 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2010-11-12 18:19:38 382032 —-a-w- C:\Windows\System32\drivers\avgtdia.sys 2010-11-10 07:54:18 49016 —-a-w- C:\Windows\SysWow64\sirenacm.dll 2010-11-10 07:28:46 301936 —-a-w- C:\Windows\WLXPGSS.SCR 2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll 2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec 2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-11-03 16:06:09 49752 —-a-w- C:\Windows\System32\drivers\SBREDrv.sys 2010-11-02 05:21:51 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2010-11-02 05:18:59 662528 —-a-w- C:\Windows\System32\XpsPrint.dll 2010-11-02 05:18:59 229888 —-a-w- C:\Windows\System32\XpsRasterService.dll 2010-11-02 05:18:58 470016 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll 2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll 2010-11-02 05:17:38 1169408 —-a-w- C:\Windows\System32\taskschd.dll 2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll 2010-11-02 05:12:53 1133568 —-a-w- C:\Windows\System32\FntCache.dll 2010-11-02 05:12:25 1540608 —-a-w- C:\Windows\System32\DWrite.dll 2010-11-02 05:12:08 1837568 —-a-w- C:\Windows\System32\d3d10warp.dll 2010-11-02 05:12:07 320512 —-a-w- C:\Windows\System32\d3d10_1core.dll 2010-11-02 05:12:06 902656 —-a-w- C:\Windows\System32\d2d1.dll 2010-11-02 05:12:06 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe 2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe 2010-11-02 04:59:08 144384 —-a-w- C:\Windows\System32\cdd.dll 2010-11-02 04:41:36 442880 —-a-w- C:\Windows\SysWow64\XpsPrint.dll 2010-11-02 04:41:36 283648 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2010-11-02 04:41:36 135168 —-a-w- C:\Windows\SysWow64\XpsRasterService.dll 2010-11-02 04:40:36 496128 —-a-w- C:\Windows\SysWow64\taskschd.dll 2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll 2010-11-02 04:35:51 1074176 —-a-w- C:\Windows\SysWow64\DWrite.dll 2010-11-02 04:35:35 1170944 —-a-w- C:\Windows\SysWow64\d3d10warp.dll 2010-11-02 04:35:34 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2010-11-02 04:35:34 218624 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll 2010-11-02 04:35:34 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe 2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe 2010-11-02 02:50:58 258048 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys ============= FINISH: 11:32:48.80 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 20/01/2010 12:35:14 PM System Uptime: 29/01/2011 11:22:18 AM (0 hours ago) Motherboard: Dell Inc. | | 0G848F Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz | Microprocessor | 2100/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 451 GiB total, 359.939 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP391: 22/01/2011 12:53:40 AM - Windows Update RP392: 22/01/2011 11:39:12 PM - Windows Update RP393: 22/01/2011 11:55:06 PM - Windows Update RP394: 23/01/2011 1:10:14 AM - Windows Update RP395: 23/01/2011 10:10:20 PM - Windows Update RP396: 24/01/2011 3:51:08 PM - Windows Update RP397: 25/01/2011 12:43:46 AM - Removed Java™ 6 Update 23 RP398: 25/01/2011 12:45:33 AM - Installed Java™ 6 Update 23 RP399: 25/01/2011 12:59:03 AM - Installed AVG 2011 RP400: 25/01/2011 12:59:25 AM - Installed AVG 2011 RP401: 26/01/2011 11:53:28 PM - Installed HiJackThis RP402: 27/01/2011 12:01:29 AM - Removed HiJackThis RP403: 27/01/2011 12:02:53 AM - Installed HiJackThis ==== Installed Programs ====================== Ad-Aware Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Illustrator 10 Adobe Photoshop CS2 Adobe Photoshop Elements 7.0 Adobe Premiere Elements 7.0 Adobe Reader 9.4.1 Adobe SVG Viewer 3.0 Akamai NetSession Interface Alien Skin Eye Candy 5 Impact Alien Skin Eye Candy 5 Nature Apple Application Support Apple Software Update ArtRage 2 Artweaver 1.0 AV Bros. Page Curl Pro 2.1 (Remove Only) Bamboo Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Color Efex Pro 3.0 Wacom Edition 3 Compatibility Pack for the 2007 Office system Contextual Tool Egoads Core FTP LE 2.1 Cozi D3DX10 Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell Getting Started Guide Dell Remote Access Dell Support Center (Support Software) Emsisoft Anti-Malware 5.1 Eye Candy 4000 Facebook Plug-In Filter Forge 1.009 Filter Forge Freepack 1 - Metals 1.012 Filter Forge Freepack 2 - Photo Effects 1.012 Filters Unlimited 2.0 Free RAR Extract Frog FrostWire 4.21.3 GIMP 2.6.9 Google Earth Plug-in Google Update Helper GoToAssist 8.0.0.514 Harry's Filters 3.01 HiJackThis Hoyle Slots 2010 (remove only) Inkscape 0.47 Jasc Animation Shop 3 Jasc Paint Shop Pro 9 Java Auto Updater Java™ 6 Update 23 Junk Mail filter update Kai's Power Tools 5 Malwarebytes' Anti-Malware McAfee Security Scan Plus McAfee SiteAdvisor Mesh Runtime Messenger Companion Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Suite Activation Assistant Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works Mozilla Firefox (3.6.13) MSVCRT MSVCRT_amd64 PowerDVD DX QuickTime Roll Roxio Burn Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2289158) Security Update for 2007 Microsoft Office System (KB2344875) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft Office Excel 2007 (KB2345035) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office PowerPoint Viewer (KB2413381) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) SmartSound Quicktracks for Premiere Elements Spelling Dictionaries Support For Adobe Reader 9 Spybot - Search & Destroy Ulead ArtTexture.Plugin 1.0 Ulead FantasyWarp.Plugin 1.0 Ulead Particle.Plugin 1.0 Update for 2007 Microsoft Office System (KB2284654) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual Studio 2008 x64 Redistributables WebTablet IE Plugin WebTablet Netscape Plugin WildTangent Games Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live OneCare safety scanner Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Yahoo! Messenger Yahoo! Software Update ==== Event Viewer Messages From Past Week ======== 28/01/2011 4:07:24 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service. 28/01/2011 10:28:32 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 27/01/2011 11:24:03 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. 27/01/2011 11:04:38 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 27/01/2011 10:23:04 PM, Error: NetBT [4321] - The name "LENOVO-70BF13AF:0" could not be registered on the interface with IP address 192.168.2.3. The computer with the IP address 192.168.2.2 did not allow the name to be claimed by this computer. 26/01/2011 2:07:08 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TouchServicePen service. 26/01/2011 12:49:07 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 26/01/2011 12:49:07 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 26/01/2011 12:49:06 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 26/01/2011 12:49:03 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 26/01/2011 12:48:57 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 26/01/2011 12:48:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 26/01/2011 12:48:33 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error Code: 21 26/01/2011 12:48:20 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache spldr Wanarpv6 26/01/2011 11:37:45 AM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file. 26/01/2011 1:34:42 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 26/01/2011 1:34:42 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 25/01/2011 1:02:19 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 25/01/2011 1:02:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 25/01/2011 1:02:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 25/01/2011 1:01:25 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgfwfd Avgldx64 Avgmfx64 Avgtdia DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr Tcpip tdx vwififlt Wanarpv6 WfpLwf 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:25 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 25/01/2011 1:01:22 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:22 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:22 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 25/01/2011 1:01:22 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 24/01/2011 4:05:17 PM, Error: Microsoft Antimalware [3002] - 24/01/2011 11:18:51 AM, Error: Service Control Manager [7022] - The Windows Font Cache Service service hung on starting. 24/01/2011 11:07:58 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr Tcpip tdx vwififlt Wanarpv6 WfpLwf 24/01/2011 11:07:53 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00009088 (0xfffff880067f1880, 0xfffff880067f1884, 0xfffff880067f1890, 0xfffff880067f1894). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 012411-18454-01. 22/01/2011 11:52:04 PM, Error: Service Control Manager [7034] - The CNG Key Isolation service terminated unexpectedly. It has done this 1 time(s). ==== End Of File ===========================
Here's the GMR results.

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-29 12:06:51
Windows 6.1.7600
Running: gmer.exe


—- Registry - GMER 1.0.15 —-

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7C0F003-EDC4-9EE7-2FA3-3A3EF086BEB7}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7C0F003-EDC4-9EE7-2FA3-3A3EF086BEB7}@hanoolmkjeeflfeg 0x6A 0x61 0x64 0x69 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7C0F003-EDC4-9EE7-2FA3-3A3EF086BEB7}@iapockfcoebjbccdlo 0x69 0x61 0x66 0x69 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7C0F003-EDC4-9EE7-2FA3-3A3EF086BEB7}@haciekfcjenieknk 0x64 0x63 0x6F 0x63 …

—- EOF - GMER 1.0.15 —-
Hello Chestersmama

Thank you for the logs.

so I did all my scans

I would like to take a look at the AVG scan log and the MBAM log that were created after you ran the tools. You will be able to find the MBAM log by opening MBAM and clicking on the "Logs" tab.

  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have FrostWire 4.21.3. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on the "Windows Orb" (bottom left hand corner of your screen), then on "Conrol Panel" and then on the "Programs and Features" tab.
    • A list of currently installed programs will be displayed.
    • Find the "FrostWire 4.21.3" program, click on it once and then click on the "Uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Please download GooredFix by JPShortstuff


    • Please download GooredFix from one of the locations below and save it to your Desktop.

    Download Mirror #1
    Download Mirror #2

    • Ensure all Firefox windows are closed.
    • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista/Win7).
    • When prompted to run the scan, click Yes.
    • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

    Please post the AVG log, the MBAM log and ther GooredFix log in your next reply :)
Hello, here are my scan results for MBAM and GooderFix. I can't find the scan log for avg. I still have the items in quarantine, but I checked the history and it's empty. Let me know if you want me to tell you what's in the virus vault. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5606 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 26/01/2011 12:19:54 AM mbam-log-2011-01-26 (00-19-54).txt Scan type: Quick scan Objects scanned: 159790 Time elapsed: 2 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 5 Files Infected: 9 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Kat\AppData\Roaming\SysWin (Trojan.Agent) -> Quarantined and deleted successfully. c:\program files (x86)\f3setupinstall (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\sysmon\exie2411 (Trojan.P2P.Downloader) -> Quarantined and deleted successfully. c:\sysmon\f3install (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\sysmon\flvdirect (Adware.Dropper) -> Quarantined and deleted successfully. Files Infected: c:\programdata\api-ms-win-core-misc-l1-1-032.dll.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully. c:\Windows\nethwow.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully. c:\Windows\nlslexicons0007wow.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully. c:\Windows\x3daudio1_5wow.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully. c:\program files (x86)\f3setupinstall\f3initialsetup1.0.1.1.inf (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files (x86)\f3setupinstall\f3Setup1.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\sysmon\exie2411\powx7354.exe (Trojan.P2P.Downloader) -> Quarantined and deleted successfully. c:\sysmon\f3install\csrmf13171.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\sysmon\flvdirect\flvsetup.exe (Adware.Dropper) -> Quarantined and deleted successfully. GooredFix by jpshortstuff (03.07.10.1) Log created at 23:01 on 29/01/2011 (Kat) Firefox version 3.6.13 (en-US) ========== GooredScan ========== Deleting "C:\Users\Kat\Application Data\Mozilla\Firefox\Profiles\v4ndfdaz.default\extensions\{8bbe70ac-cb6e-4cb6-9799-5f41f1869c19}" -> Success! ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [03:57 26/01/2011] {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [15:28 02/04/2010] {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [03:53 06/05/2010] {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [14:55 16/08/2010] {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [01:47 23/10/2010] {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [05:46 25/01/2011] C:\Users\Kat\Application Data\Mozilla\Firefox\Profiles\v4ndfdaz.default\extensions\ [removed] [07:36 12/12/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [16:35 24/12/2010] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files (x86)\AVG\AVG10\Firefox\" [06:00 25/01/2011] -=E.O.F=- Thanks for your help so far. :)
Hello Chestersmama

Thank you for the logs

GooredFix has removed a malicious item from your system. Can you please check and let me know if you are still being redirected?
Hi JonTom, I think you've fixed the problem. I did alot of searches and was not redirected. Thank you for everything. :thumbup: Let me know if there is anything else I should do. Also, I am wondering if AVG free and Adware, Spybot and Superantispyware are good enough protection. I also still have MBAM on my pc as well. Do I need all of that or just one or two of them on top of the AVG.
Hello Chestersmama

Thank you for letting me know.

Do I need all of that or just one or two of them on top of the AVG

If you just wanted to keep one of them I would recommend MBAM, but they are all good programs for "on-demand" scans. I try to recommend a layered approach to system security as no one product is perfect, and what one scanner may miss another may pick up.

Let me know if there is anything else I should do.

Please work your way through the following steps:


  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Right click the TFC icon and select "Run as Administrator" to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM log and the ESET log in your next reply and let me know how the machine is running now :)
Here's the MBAM log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5643 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 30/01/2011 9:19:55 PM mbam-log-2011-01-30 (21-19-55).txt Scan type: Quick scan Objects scanned: 27398 Time elapsed: 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here's the result of the ESET scan, I hope I did it right. C:\Users\Kat\Desktop\GooredFix Backups\C\Users\Kat\Application Data\Mozilla\Firefox\Profiles\v4ndfdaz.default\extensions\{8bbe70ac-cb6e-4cb6-9799-5f41f1869c19}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Users\Kat\Desktop\GooredFix Backups\C\Users\Kat\Application Data\Mozilla\Firefox\Profiles\v4ndfdaz.default\extensions\{8bbe70ac-cb6e-4cb6-9799-5f41f1869c19}\chrome\xulcache.jar JS/Agent.NCP trojan
Hello Chestersmama

I hope I did it right

You did :)

There should now be a folder on your desktop called "GooredFix Backups".

Please drag the "GooredFix Backups" folder to your Recycle Bin and then empty the bin (Do Not open the folder).

Once you have completed the above, please scan your system with DDS again and post the log created :)
:) DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 14:29:58.48 on 31/01/2011 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.4056.1787 [GMT -5:00] AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6} AV: AVG Internet Security 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Internet Security 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} ============== Running Processes =============== C:\PROGRA~2\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Program Files\Tablet\Pen\Pen_TouchService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\AVG\AVG10\avgfws.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\Windows\system32\rundll32.exe C:\Windows\SysWOW64\rundll32.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\AVG\AVG10\avgam.exe C:\Program Files\Tablet\Pen\Pen_TabletUser.exe C:\Windows\system32\Dwm.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\Explorer.EXE C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\System32\StikyNot.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conhost.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\conhost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe C:\Windows\system32\taskhost.exe C:\Program Files\Tablet\Pen\Pen_TouchUser.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\AVG\AVG10\avgscana.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\SysWOW64\notepad.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Kat\Desktop\dds(2).scr C:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uSearch Page = uStart Page = hxxp://ca.yahoo.com/?fr=fptb-msgr uSearch Bar = uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll uURLSearchHooks: H - No File mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe StartupFolder: C:\Users\Kat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe StartupFolder: C:\Users\Kat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLRE~1.LNK - c:\Windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C411C0047CC5.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Chuzzle%20Deluxe/Images/stg_drm.ocx DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-ca/wlscctrl2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Chuzzle%20Deluxe/Images/armhelper.ocx Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe mRun-x64: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe ================= FIREFOX =================== FF - ProfilePath - C:\Users\Kat\AppData\Roaming\Mozilla\Firefox\Profiles\v4ndfdaz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://search.avg.com/?d=4d3e674c&i;=23&tp;=ab&nt;=1&q;= FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll FF - component: C:\Program Files (x86)\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Kat\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll FF - plugin: C:\Users\Kat\AppData\Roaming\Mozilla\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Oberon GamesBar: [removed] - %profile%\extensions\[removed] FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - C:\Program Files (x86)\McAfee\SiteAdvisor FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox —- FIREFOX POLICIES —- FF - user.js: google.toolbar.linkdoctor.enabled - false ============= SERVICES / DRIVERS =============== R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288] R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2010-6-4 69152] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-1-13 55280] R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2010-7-12 57696] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752] R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-1-24 2850296] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136] R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG10\avgfws.exe [2010-11-22 3226632] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-7-12 1402272] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2011-1-13 101048] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-10 1153368] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-1-13 689472] R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2010-8-9 7329648] R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-8-9 719216] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920] R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2010-8-11 17440] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-1-13 215552] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-17 136176] S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2011-1-24 84752] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-12-27 48488] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-8-9 18288] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-13 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] =============== Created Last 30 ================ 2011-01-29 02:39:01 ——– d—–w- C:\Users\Kat\AppData\Roaming\SUPERAntiSpyware.com 2011-01-29 02:39:01 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com 2011-01-29 02:38:54 ——– d—–w- C:\PROGRA~3\!SASCORE 2011-01-29 02:38:51 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2011-01-27 03:38:04 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-01-26 17:30:45 ——– d—–w- C:\PROGRA~3\XoftSpySE 2011-01-26 05:14:13 ——– d—–w- C:\Users\Kat\AppData\Roaming\Malwarebytes 2011-01-26 05:14:08 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-01-26 05:14:07 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-01-26 05:14:03 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-01-26 05:14:03 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-01-25 06:14:08 ——– d–h–w- C:\$AVG 2011-01-25 06:02:25 ——– d—–w- C:\Users\Kat\AppData\Roaming\AVG10 2011-01-25 06:01:39 ——– d–h–w- C:\PROGRA~3\Common Files 2011-01-25 06:01:11 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-01-25 06:00:01 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-01-25 06:00:01 ——– d—–w- C:\PROGRA~3\AVG10 2011-01-25 05:59:16 ——– d—–w- C:\Program Files (x86)\AVG 2011-01-25 05:52:21 ——– d—–w- C:\PROGRA~3\MFAData 2011-01-24 16:47:23 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware 2011-01-23 05:21:40 ——– d—–w- C:\Users\Kat\AppData\Roaming\PC Tools 2011-01-23 05:21:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2011-01-23 05:20:05 ——– d—–w- C:\PROGRA~3\PC Tools 2011-01-23 04:40:26 14336 —-a-w- C:\Windows\System32\drivers\sffp_sd.sys 2011-01-23 04:21:31 77312 —-a-w- C:\Windows\SysWow64\ztvunace26.dll 2011-01-23 04:21:31 75264 —-a-w- C:\Windows\SysWow64\unacev2.dll 2011-01-23 04:21:31 69632 —-a-w- C:\Windows\SysWow64\ztvcabinet.dll 2011-01-23 04:21:31 162304 —-a-w- C:\Windows\SysWow64\ztvunrar36.dll 2011-01-23 04:21:31 153088 —-a-w- C:\Windows\SysWow64\unrar3.dll 2011-01-21 06:34:01 ——– d-sh–w- C:\PROGRA~3\573C378827FA540FAC0018382186D4EE 2011-01-15 05:49:27 ——– d—–w- C:\Users\Kat\AppData\Local\Opera ==================== Find3M ==================== 2011-01-25 05:45:59 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2010-12-08 09:12:36 308304 —-a-w- C:\Windows\System32\drivers\avgldx64.sys 2010-12-06 14:07:37 15880 —-a-w- C:\Windows\System32\lsdelete.exe 2010-12-03 06:47:07 952 –sha-w- C:\PROGRA~3\KGyGaAvL.sys 2010-12-03 06:47:07 88 –sh–r- C:\PROGRA~3\65ADCA5E85.sys 2010-11-29 22:38:30 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2010-11-12 18:19:38 382032 —-a-w- C:\Windows\System32\drivers\avgtdia.sys 2010-11-10 07:54:18 49016 —-a-w- C:\Windows\SysWow64\sirenacm.dll 2010-11-10 07:28:46 301936 —-a-w- C:\Windows\WLXPGSS.SCR 2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll 2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec 2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-11-03 16:06:09 49752 —-a-w- C:\Windows\System32\drivers\SBREDrv.sys ============= FINISH: 14:30:51.32 ===============
Hello Chestersmama

Your log appears to be clean :thumbup:

Provided you are no longer experiencing any problems I believe we are just about done.

Lets create a new system restore point on your machine and then remove the tools we used:


  • Please create a new System Restore point


    • Click on your "Windows Orb".
    • Right click on "Computer" and then select "Properties".
    • Click on the "Sytem Protection" link.
    • Select the "System Protection" tab and click on "Create".
    • Give the restore point a name (for example, todays date) then click on "Create".
    • You should receive notification that the restore point was created.

  • Removal of Tools


    • You no longer need DDS, GMER or GooredFix. Please delete them from your system.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
:thumbup: You rock! Thank you so much for all your help and patience. My pc is running like a dream and no more redirected searches. I have read all your hints and tips and will continue to educate myself more. Thanks again JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI