This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Behaving Suspiciously

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there. I have a Dell XPS 1530 and because of my accidental cover i got it refurbished after it developed hardware problems. Anyways, now i have pretty much a brand new laptop n its been working fine up until the last few weeks. My boot up has slowed down from 1:13 seconds to 2:50 seconds. What annoys me the most is that my wifi stops working randomly. It takes 3 mins just to go on google. The weird thing is, i can play on my ps3, use the internet on my fone or my brothers laptop all using that same wifi while im having trouble using it on my laptop. So im pretty sure its got nothing to do with my wifi connection n that the problem is with my laptop. i am posting my dds log file hope u guys can help. Thanks
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 20:47:05.22 on 04/05/2011 Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_22 . ============== Running Processes =============== . . ============== Pseudo HJT Report =============== . mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d uURLSearchHooks: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\4.3\youtubedownloaderToolbarIE.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Download Manager Browser Helper Object: {19c8e43b-07b3-49cb-bffc-6777b593e6f8} - c:\progra~1\common~1\fluxdvd\downlo~1\XEBDLH~1.DLL BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: eSnipsBHO Class: {b530a9a4-1722-4d16-aad6-aa85e3ad2ade} - c:\program files\logia\esnipsdownloader\eSnipsBHO.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\4.3\youtubedownloaderToolbarIE.dll TB: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\4.3\youtubedownloaderToolbarIE.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup mRun: [] mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: DisableCAD = 1 (0x1) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Free YouTube to MP3 Converter - c:\users\excell\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: psfus - c:\windows\system32\psqlpwd.dll AppInit_DLLs: c:\windows\system32\guard32.dll LSA: Notification Packages = scecli psqlpwd . ================= FIREFOX =================== . FF - ProfilePath - c:\users\excell\appdata\roaming\mozilla\firefox\profiles\a9zmt3eo.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8 FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll FF - component: c:\program files\logia\esnipsdownloader\ext\components\eSnipsXPCOM.dll FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - plugin: c:\program files\common files\fluxdvd\apix\NPAPIX.dll FF - plugin: c:\program files\common files\fluxdvd\browserintegration\NPFluxBrowserHelper.dll FF - plugin: c:\program files\common files\mpdrm\NPMPDRM.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll . ============= SERVICES / DRIVERS =============== . . =============== Created Last 30 ================ . 2011-05-04 11:32:30 ——– d—–w- c:\users\excell\appdata\local\{BABFFBF0-CB60-477D-BE58-D05D80E8F851} 2011-05-03 18:47:50 ——– d—–w- c:\users\excell\appdata\local\{C8AC50DF-0A43-40C9-95CF-F4A9A2A43972} 2011-05-02 21:10:33 ——– d—–w- c:\users\excell\appdata\local\{620EB4B7-02F7-43FB-97F9-915CEAA22DF1} 2011-05-01 23:00:10 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-05-01 23:00:10 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-05-01 23:00:10 465880 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-05-01 23:00:10 1974616 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll 2011-05-01 23:00:10 1892184 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll 2011-05-01 23:00:10 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-05-01 23:00:10 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-05-01 23:00:10 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-05-01 14:59:11 ——– d—–w- c:\users\excell\appdata\local\{C7758D0B-A31C-4FED-AFB5-ACC707FE42C5} 2011-04-30 21:13:59 ——– d—–w- c:\users\excell\appdata\local\{4CC4D866-DECF-4F4E-B243-AE53374CFE50} 2011-04-29 20:01:42 ——– d—–w- c:\users\excell\appdata\local\Adobe 2011-04-29 19:38:13 ——– d—–w- c:\users\excell\appdata\local\{3D7554E8-D491-47A7-9643-F0402014FBEA} 2011-04-28 20:58:05 ——– d—–w- c:\users\excell\appdata\local\{54E279CE-1F5C-4377-975E-9EDAD5ACAF24} 2011-04-28 08:32:21 ——– d—–w- c:\users\excell\appdata\local\{B419B144-940F-4C8E-ACFC-97D33A3B064F} 2011-04-27 20:49:45 ——– d—–w- c:\program files\Internet Cyclone 2011-04-27 19:49:45 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2011-04-27 19:49:45 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2011-04-27 19:48:19 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-04-27 19:43:04 ——– d—–w- c:\users\excell\appdata\local\{BFFD2B0A-FF9C-4096-9AC3-2B815D52704E} 2011-04-26 21:23:55 ——– d—–w- c:\users\excell\appdata\local\{86134DE3-CAE6-46A3-B905-3DDDA4A4D0A9} 2011-04-26 09:23:33 ——– d—–w- c:\users\excell\appdata\local\{697421A0-E4A4-4586-A635-24609F485104} 2011-04-25 20:50:10 ——– d—–w- c:\users\excell\appdata\local\{645A6CC2-659D-4227-AD72-522482686AE8} 2011-04-25 01:25:52 ——– d—–w- c:\users\excell\appdata\local\{4590A734-F852-4998-B289-19F830CF9E09} 2011-04-24 12:21:11 ——– d—–w- c:\users\excell\appdata\local\{A5A1474A-F92A-4555-9C49-DA6173A0888E} 2011-04-23 11:00:00 ——– d—–w- c:\users\excell\appdata\local\{CD633A71-8ED5-4520-9882-EDC3CB209611} 2011-04-22 22:59:36 ——– d—–w- c:\users\excell\appdata\local\{5A9956A3-DF4A-45BA-9125-FA45371A1167} 2011-04-22 10:59:13 ——– d—–w- c:\users\excell\appdata\local\{A9FEEA30-56EB-4DD0-A5E7-5BF8F69892F5} 2011-04-21 22:58:51 ——– d—–w- c:\users\excell\appdata\local\{72EF516C-1967-4D28-BBAD-CB8C89BF5758} 2011-04-21 10:58:28 ——– d—–w- c:\users\excell\appdata\local\{A4A4AFD4-F201-4443-9701-BD8D6DD9C5AC} 2011-04-20 22:21:53 ——– d—–w- c:\users\excell\appdata\local\{3C97D950-DB41-4673-A7C3-BB63197B94EA} 2011-04-20 10:17:31 ——– d—–w- c:\users\excell\appdata\local\{0AF2143B-B2D3-4793-B44C-DC90C4B1EC28} 2011-04-20 00:35:33 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-04-19 22:22:40 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys 2011-04-19 22:22:20 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-04-19 22:22:20 ——– d—–w- c:\users\excell\appdata\local\Sunbelt Software 2011-04-19 22:20:18 ——– d—–w- c:\progra~2\NVIDIA Corporation 2011-04-19 22:20:13 ——– d—–w- c:\program files\NVIDIA Corporation 2011-04-19 22:16:24 ——– dc-h–w- c:\progra~2\{AA5544E4-9BBC-419B-9204-40B5924D26AA} 2011-04-19 22:16:16 ——– d—–w- c:\program files\Lavasoft 2011-04-19 18:09:17 ——– d—–w- c:\progra~2\Skype Extras 2011-04-19 13:45:41 ——– d—–w- c:\users\excell\appdata\local\{C69783B7-B45B-4BBF-A63F-5E7289641227} 2011-04-17 18:51:03 ——– d—–w- c:\users\excell\appdata\local\{F7C38C3C-7FB0-482F-9070-B90B62B4E2E7} 2011-04-16 21:23:28 ——– d—–w- c:\users\excell\appdata\local\{DFEFD1AA-D8EF-4E83-AE44-B25294D83125} 2011-04-16 01:16:41 ——– d—–w- c:\users\excell\appdata\local\Trusteer 2011-04-15 15:43:16 ——– d—–w- c:\users\excell\appdata\local\{21A3C44A-E0B6-42CB-B0B7-D626B54A4350} 2011-04-14 22:34:04 ——– d—–w- c:\users\excell\appdata\local\{A4016E36-B7F0-480F-B078-33570073C6AD} 2011-04-13 23:31:23 ——– d—–w- c:\users\excell\appdata\local\{A65F3E55-EC92-490D-9980-98988A6BA311} 2011-04-13 11:30:54 ——– d—–w- c:\users\excell\appdata\local\{F6290FFD-F9E1-4A23-8E3A-BA4E83A10CD5} 2011-04-12 22:36:51 ——– d—–w- c:\users\excell\appdata\roaming\DVDVideoSoftIEHelpers 2011-04-12 22:35:27 ——– d—–w- c:\program files\DVDVideoSoft 2011-04-12 22:35:27 ——– d—–w- c:\program files\common files\DVDVideoSoft 2011-04-12 22:29:50 ——– d—–w- c:\program files\YouTube Downloader Toolbar 2011-04-12 22:29:50 ——– d—–w- c:\program files\common files\Spigot 2011-04-12 22:29:50 ——– d—–w- c:\program files\Application Updater 2011-04-12 22:29:33 ——– d—–w- c:\program files\YouTube Downloader 2011-04-12 22:25:18 ——– d—–w- c:\users\excell\appdata\roaming\NetMedia Providers 2011-04-12 22:16:42 ——– d—–w- c:\users\excell\appdata\local\Sony 2011-04-12 21:49:46 ——– d—–w- c:\program files\Sony 2011-04-12 21:10:13 ——– d—–w- c:\users\excell\appdata\local\{9970EEEE-87A7-48DB-9C3E-2976749BF6E8} 2011-04-12 13:08:18 ——– d—–w- c:\users\excell\appdata\local\{AAD184F9-6D04-4A7E-BFB2-ABD889EF11BF} 2011-04-11 13:12:17 ——– d—–w- c:\users\excell\appdata\local\{5CBA3A40-787A-4005-BAE4-3B1EEB3B08A5} 2011-04-09 19:59:17 ——– d—–w- c:\users\excell\appdata\local\{1696EDF9-A04A-4187-863C-DA5769EC09DE} 2011-04-09 17:16:03 ——– d—–w- c:\program files\Nuclear Coffee 2011-04-08 13:38:06 ——– d—–w- c:\users\excell\appdata\local\{A17DCD1F-0B7B-41A9-BE93-8A8D1E88C88E} 2011-04-08 09:17:38 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys 2011-04-07 21:49:31 ——– d—–w- c:\users\excell\appdata\local\{D96A1BA5-21E9-4088-A881-28AD8A332E63} 2011-04-06 19:47:12 ——– d—–w- c:\users\excell\appdata\local\{41561AC3-9BE1-4FEA-8315-AFEE43972787} 2011-04-05 23:33:51 ——– d—–w- c:\users\excell\appdata\local\{8900F692-F989-42E8-B632-6EF47A88B6FD} 2011-04-05 11:33:21 ——– d—–w- c:\users\excell\appdata\local\{5D9B7796-574B-4252-BDC3-CDEF627CFE42} . ==================== Find3M ==================== . 2011-03-25 23:48:06 4284416 —-a-w- c:\windows\system32\GPhotos.scr 2011-03-13 21:13:01 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll 2011-03-03 15:42:03 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-03 15:40:07 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll 2011-03-03 15:40:05 542720 —-a-w- c:\windows\apppatch\AcLayers.dll 2011-03-03 15:40:05 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2011-03-03 15:40:04 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll 2011-03-03 13:25:11 2041856 —-a-w- c:\windows\system32\win32k.sys 2011-03-02 15:44:27 86528 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-02-22 14:13:01 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-22 13:33:12 1068544 —-a-w- c:\windows\system32\DWrite.dll 2011-02-22 13:33:09 797696 —-a-w- c:\windows\system32\FntCache.dll 2011-02-22 06:21:28 916480 —-a-w- c:\windows\system32\wininet.dll 2011-02-22 06:17:08 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-22 06:16:53 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-02-22 06:16:40 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-02-22 06:16:40 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-02-22 05:20:39 385024 —-a-w- c:\windows\system32\html.iec 2011-02-22 04:43:54 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-02-22 04:42:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-02-17 06:23:50 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-02-16 16:16:37 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-02-16 14:02:23 292864 —-a-w- c:\windows\system32\atmfd.dll . ============= FINISH: 20:48:16.76 ===============

Attachments:

Hi excelserious,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

µTorrent
You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

You've got some nasty's in there that typically come with downloading from files sharing sites.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk. Thanks for replying. I have uninstalled UTorrent and did as you instructed. Combofix did not ask me to install the windows recovery console or anything like that. The log it produced is pasted below. Also, i am having that internet problem right now otherwise i would have posted this a few hours ago.
ComboFix 11-05-06.05 - excell 07/05/2011 21:55:16.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3581.2362 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-07 to 2011-05-07 )))))))))))))))))))))))))))))))
.
.
2011-05-07 21:04 . 2011-05-07 21:04 0 —ha-w- c:\users\excell\AppData\Local\BITD70C.tmp
2011-05-07 20:51 . 2011-05-07 20:53 ——– d—–w- C:\32788R22FWJFW
2011-05-07 18:20 . 2011-05-07 18:20 ——– d—–w- c:\users\excell\AppData\Local\{AF235023-E2C4-4775-AB10-48B79016AEFA}
2011-05-06 21:48 . 2011-05-06 21:48 ——– d—–w- c:\users\excell\AppData\Local\{4C187D52-10B9-4004-9287-25340BF6652D}
2011-05-06 09:48 . 2011-05-06 09:48 ——– d—–w- c:\users\excell\AppData\Local\{F5FE8FC4-C05B-4B92-8099-984008344AF8}
2011-05-05 14:32 . 2011-05-05 14:32 ——– d—–w- c:\users\excell\AppData\Local\{9F811721-EE46-49ED-A510-5194454EEDF7}
2011-05-05 00:36 . 2011-05-05 00:37 ——– d—–w- c:\users\excell\AppData\Local\{0431DF45-3BE8-4E7E-9C12-F8A48E732B83}
2011-05-04 11:32 . 2011-05-04 11:32 ——– d—–w- c:\users\excell\AppData\Local\{BABFFBF0-CB60-477D-BE58-D05D80E8F851}
2011-05-03 18:47 . 2011-05-03 18:48 ——– d—–w- c:\users\excell\AppData\Local\{C8AC50DF-0A43-40C9-95CF-F4A9A2A43972}
2011-05-02 21:10 . 2011-05-02 21:10 ——– d—–w- c:\users\excell\AppData\Local\{620EB4B7-02F7-43FB-97F9-915CEAA22DF1}
2011-05-01 23:00 . 2011-04-14 16:41 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-01 23:00 . 2011-04-14 16:41 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-01 23:00 . 2011-04-14 16:41 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-01 23:00 . 2011-04-14 16:41 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-01 23:00 . 2011-04-14 16:41 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-01 23:00 . 2011-04-14 16:41 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-01 23:00 . 2010-01-01 08:00 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-01 23:00 . 2010-01-01 08:00 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-05-01 14:59 . 2011-05-01 14:59 ——– d—–w- c:\users\excell\AppData\Local\{C7758D0B-A31C-4FED-AFB5-ACC707FE42C5}
2011-04-30 21:13 . 2011-04-30 21:14 ——– d—–w- c:\users\excell\AppData\Local\{4CC4D866-DECF-4F4E-B243-AE53374CFE50}
2011-04-29 20:01 . 2011-04-29 20:01 ——– d—–w- c:\users\excell\AppData\Local\Adobe
2011-04-29 19:38 . 2011-04-29 19:38 ——– d—–w- c:\users\excell\AppData\Local\{3D7554E8-D491-47A7-9643-F0402014FBEA}
2011-04-28 20:58 . 2011-04-28 20:58 ——– d—–w- c:\users\excell\AppData\Local\{54E279CE-1F5C-4377-975E-9EDAD5ACAF24}
2011-04-28 08:32 . 2011-04-28 08:32 ——– d—–w- c:\users\excell\AppData\Local\{B419B144-940F-4C8E-ACFC-97D33A3B064F}
2011-04-27 21:00 . 2011-04-27 21:00 ——– d—–w- c:\users\Default\AppData\Roaming\Trusteer
2011-04-27 19:49 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 19:49 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 19:48 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-27 19:43 . 2011-04-27 19:43 ——– d—–w- c:\users\excell\AppData\Local\{BFFD2B0A-FF9C-4096-9AC3-2B815D52704E}
2011-04-26 21:23 . 2011-04-26 21:24 ——– d—–w- c:\users\excell\AppData\Local\{86134DE3-CAE6-46A3-B905-3DDDA4A4D0A9}
2011-04-26 09:23 . 2011-04-26 09:23 ——– d—–w- c:\users\excell\AppData\Local\{697421A0-E4A4-4586-A635-24609F485104}
2011-04-25 20:50 . 2011-04-25 20:50 ——– d—–w- c:\users\excell\AppData\Local\{645A6CC2-659D-4227-AD72-522482686AE8}
2011-04-25 01:25 . 2011-04-25 01:26 ——– d—–w- c:\users\excell\AppData\Local\{4590A734-F852-4998-B289-19F830CF9E09}
2011-04-24 12:21 . 2011-04-24 12:21 ——– d—–w- c:\users\excell\AppData\Local\{A5A1474A-F92A-4555-9C49-DA6173A0888E}
2011-04-23 11:00 . 2011-04-23 11:00 ——– d—–w- c:\users\excell\AppData\Local\{CD633A71-8ED5-4520-9882-EDC3CB209611}
2011-04-22 22:59 . 2011-04-22 22:59 ——– d—–w- c:\users\excell\AppData\Local\{5A9956A3-DF4A-45BA-9125-FA45371A1167}
2011-04-22 10:59 . 2011-04-22 10:59 ——– d—–w- c:\users\excell\AppData\Local\{A9FEEA30-56EB-4DD0-A5E7-5BF8F69892F5}
2011-04-21 22:58 . 2011-04-21 22:59 ——– d—–w- c:\users\excell\AppData\Local\{72EF516C-1967-4D28-BBAD-CB8C89BF5758}
2011-04-21 10:58 . 2011-04-21 10:58 ——– d—–w- c:\users\excell\AppData\Local\{A4A4AFD4-F201-4443-9701-BD8D6DD9C5AC}
2011-04-20 22:21 . 2011-04-20 22:22 ——– d—–w- c:\users\excell\AppData\Local\{3C97D950-DB41-4673-A7C3-BB63197B94EA}
2011-04-20 10:17 . 2011-04-20 10:17 ——– d—–w- c:\users\excell\AppData\Local\{0AF2143B-B2D3-4793-B44C-DC90C4B1EC28}
2011-04-20 00:35 . 2011-04-18 10:23 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-04-19 22:22 . 2011-04-19 00:00 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-04-19 22:22 . 2011-04-19 22:22 ——– d—–w- c:\users\excell\AppData\Local\Sunbelt Software
2011-04-19 22:22 . 2011-04-19 22:22 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-19 22:20 . 2011-04-19 22:20 ——– d—–w- c:\programdata\NVIDIA Corporation
2011-04-19 22:20 . 2011-04-19 22:21 ——– d—–w- c:\program files\NVIDIA Corporation
2011-04-19 22:16 . 2011-04-19 22:16 ——– dc-h–w- c:\programdata\{AA5544E4-9BBC-419B-9204-40B5924D26AA}
2011-04-19 22:16 . 2011-04-19 22:21 ——– d—–w- c:\programdata\Lavasoft
2011-04-19 22:16 . 2011-04-19 22:16 ——– d—–w- c:\program files\Lavasoft
2011-04-19 18:09 . 2011-04-19 18:09 ——– d—–w- c:\programdata\Skype Extras
2011-04-19 18:07 . 2011-04-19 18:07 ——– d—–w- c:\program files\Common Files\Skype
2011-04-19 13:45 . 2011-04-19 13:45 ——– d—–w- c:\users\excell\AppData\Local\{C69783B7-B45B-4BBF-A63F-5E7289641227}
2011-04-17 18:51 . 2011-04-17 18:51 ——– d—–w- c:\users\excell\AppData\Local\{F7C38C3C-7FB0-482F-9070-B90B62B4E2E7}
2011-04-16 21:23 . 2011-04-16 21:23 ——– d—–w- c:\users\excell\AppData\Local\{DFEFD1AA-D8EF-4E83-AE44-B25294D83125}
2011-04-16 01:16 . 2011-04-16 01:16 ——– d—–w- c:\users\excell\AppData\Local\Trusteer
2011-04-15 15:43 . 2011-04-15 15:43 ——– d—–w- c:\users\excell\AppData\Local\{21A3C44A-E0B6-42CB-B0B7-D626B54A4350}
2011-04-14 22:34 . 2011-04-14 22:34 ——– d—–w- c:\users\excell\AppData\Local\{A4016E36-B7F0-480F-B078-33570073C6AD}
2011-04-13 23:31 . 2011-04-13 23:31 ——– d—–w- c:\users\excell\AppData\Local\{A65F3E55-EC92-490D-9980-98988A6BA311}
2011-04-13 11:30 . 2011-04-13 11:31 ——– d—–w- c:\users\excell\AppData\Local\{F6290FFD-F9E1-4A23-8E3A-BA4E83A10CD5}
2011-04-12 22:36 . 2011-04-12 22:36 ——– d—–w- c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\DVDVideoSoft
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Publish Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\NetMedia Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Sony
2011-04-12 22:16 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Local\Sony
2011-04-12 21:49 . 2011-04-12 21:49 ——– d—–w- c:\program files\Sony
2011-04-12 21:10 . 2011-04-12 21:10 ——– d—–w- c:\users\excell\AppData\Local\{9970EEEE-87A7-48DB-9C3E-2976749BF6E8}
2011-04-12 13:08 . 2011-04-12 13:08 ——– d—–w- c:\users\excell\AppData\Local\{AAD184F9-6D04-4A7E-BFB2-ABD889EF11BF}
2011-04-11 13:12 . 2011-04-11 13:12 ——– d—–w- c:\users\excell\AppData\Local\{5CBA3A40-787A-4005-BAE4-3B1EEB3B08A5}
2011-04-09 19:59 . 2011-04-09 19:59 ——– d—–w- c:\users\excell\AppData\Local\{1696EDF9-A04A-4187-863C-DA5769EC09DE}
2011-04-09 17:16 . 2011-04-09 17:18 ——– d—–w- c:\program files\Nuclear Coffee
2011-04-08 13:38 . 2011-04-08 13:38 ——– d—–w- c:\users\excell\AppData\Local\{A17DCD1F-0B7B-41A9-BE93-8A8D1E88C88E}
2011-04-08 09:17 . 2011-04-08 09:17 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-04-07 21:49 . 2011-04-07 21:49 ——– d—–w- c:\users\excell\AppData\Local\{D96A1BA5-21E9-4088-A881-28AD8A332E63}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-07 21:06 . 2011-05-07 21:06 0 —ha-w- c:\users\excell\AppData\Local\BITB481.tmp
2011-03-25 23:48 . 2011-03-25 23:48 4284416 —-a-w- c:\windows\system32\GPhotos.scr
2011-03-13 21:13 . 2011-03-13 21:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-11 23:17 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-03 15:40 . 2011-04-27 19:49 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 19:49 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 19:49 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 19:49 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-23 22:39 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 22:39 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 22:39 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-02-07 12:13 . 2010-12-29 01:41 80064 —-a-w- c:\windows\system32\drivers\inspect.sys
2011-02-07 12:13 . 2010-12-29 01:41 34744 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-02-07 12:13 . 2010-12-29 01:41 236600 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-02-07 12:13 . 2010-12-29 01:41 17256 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-04-14 16:41 . 2011-05-01 23:00 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 19:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-10-25 167936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-02-07 2548552]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-16 49168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-24 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-16 22:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Users^excell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 12:49 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 —-a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CinemaNowMediaManagerApp]
2008-09-05 09:43 2017640 —-a-w- c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 13:49 405639 ——w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 14:46 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-02-15 01:32 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eSnips_Downloader]
2010-05-24 11:30 1234432 —-a-w- c:\program files\Logia\eSnipsDownloader\eSnips_Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 10:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-11-10 02:54 4240760 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 17:01 36864 —-a-w- c:\windows\OEM02Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 11:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-19 15232]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Apache2.2;Remote Access Media Server;c:\program files\Common Files\Dell\apache\bin\httpd.exe [2007-09-21 15872]
R4 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2008-09-05 137080]
R4 dsl-db;Remote Access DB;c:\program files\Common Files\Dell\MySQL\bin\mysqld.exe [2007-09-14 5730304]
R4 dsl-fs-sync;Remote Access File Sync Service;c:\program files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [2009-04-13 189680]
R4 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-19 64512]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-04-08 53816]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2011-02-07 17256]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-02-07 236600]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-02-07 34744]
S1 RapportCerberus_26169;RapportCerberus_26169;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\26169\RapportCerberus_26169.sys [2011-05-02 57144]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-04-08 66360]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-04-08 158904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe [2007-09-20 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-05-02 2146496]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-04-08 870200]
S2 uvnc_service;UltraVNC Server;c:\programdata\UltraVNC\winvnc.exe [2008-08-31 1519168]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-30 144128]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-19 15:14]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-06 c:\windows\Tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job
- c:\windows\system32\msfeedssync.exe [2011-04-14 04:43]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to MP3 Converter - c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\excell\AppData\Roaming\Mozilla\Firefox\Profiles\a9zmt3eo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-07 22:05
Windows 6.0.6002 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1654437360-1725257235-4155127740-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*µ*~*%\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'Explorer.exe'(1372)
c:\windows\system32\guard32.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
.
**************************************************************************
.
Completion time: 2011-05-07 22:10:04 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-07 21:10
.
Pre-Run: 74,564,980,736 bytes free
Post-Run: 73,830,756,352 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=66 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,
56,57,58,59,60,61,62,63,64,65,66
- - End Of File - - 389938CC5D7609E9A8D82D1E13B9B4C7
excelserious,

I'm not sure that this will cure your problems… but let's tidy up a bit.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\users\excell\AppData\Local\BITD70C.tmp
    
    Folder::
    C:\32788R22FWJFW
    c:\users\excell\AppData\Local\{AF235023-E2C4-4775-AB10-48B79016AEFA}
    c:\users\excell\AppData\Local\{4C187D52-10B9-4004-9287-25340BF6652D}
    c:\users\excell\AppData\Local\{F5FE8FC4-C05B-4B92-8099-984008344AF8}
    c:\users\excell\AppData\Local\{9F811721-EE46-49ED-A510-5194454EEDF7}
    c:\users\excell\AppData\Local\{0431DF45-3BE8-4E7E-9C12-F8A48E732B83}
    c:\users\excell\AppData\Local\{BABFFBF0-CB60-477D-BE58-D05D80E8F851}
    c:\users\excell\AppData\Local\{C8AC50DF-0A43-40C9-95CF-F4A9A2A43972}
    c:\users\excell\AppData\Local\{620EB4B7-02F7-43FB-97F9-915CEAA22DF1}
    c:\users\excell\AppData\Local\{C7758D0B-A31C-4FED-AFB5-ACC707FE42C5}
    c:\users\excell\AppData\Local\{4CC4D866-DECF-4F4E-B243-AE53374CFE50}
    c:\users\excell\AppData\Local\{3D7554E8-D491-47A7-9643-F0402014FBEA}
    c:\users\excell\AppData\Local\{54E279CE-1F5C-4377-975E-9EDAD5ACAF24}
    c:\users\excell\AppData\Local\{B419B144-940F-4C8E-ACFC-97D33A3B064F}
    c:\users\excell\AppData\Local\{BFFD2B0A-FF9C-4096-9AC3-2B815D52704E}
    c:\users\excell\AppData\Local\{86134DE3-CAE6-46A3-B905-3DDDA4A4D0A9}
    c:\users\excell\AppData\Local\{697421A0-E4A4-4586-A635-24609F485104}
    c:\users\excell\AppData\Local\{645A6CC2-659D-4227-AD72-522482686AE8}
    c:\users\excell\AppData\Local\{4590A734-F852-4998-B289-19F830CF9E09}
    c:\users\excell\AppData\Local\{A5A1474A-F92A-4555-9C49-DA6173A0888E}
    c:\users\excell\AppData\Local\{CD633A71-8ED5-4520-9882-EDC3CB209611}
    c:\users\excell\AppData\Local\{5A9956A3-DF4A-45BA-9125-FA45371A1167}
    c:\users\excell\AppData\Local\{A9FEEA30-56EB-4DD0-A5E7-5BF8F69892F5}
    c:\users\excell\AppData\Local\{72EF516C-1967-4D28-BBAD-CB8C89BF5758}
    c:\users\excell\AppData\Local\{A4A4AFD4-F201-4443-9701-BD8D6DD9C5AC}
    c:\users\excell\AppData\Local\{3C97D950-DB41-4673-A7C3-BB63197B94EA}
    c:\users\excell\AppData\Local\{0AF2143B-B2D3-4793-B44C-DC90C4B1EC28}
    c:\users\excell\AppData\Local\{C69783B7-B45B-4BBF-A63F-5E7289641227}
    c:\users\excell\AppData\Local\{F7C38C3C-7FB0-482F-9070-B90B62B4E2E7}
    c:\users\excell\AppData\Local\{DFEFD1AA-D8EF-4E83-AE44-B25294D83125}
    c:\users\excell\AppData\Local\{21A3C44A-E0B6-42CB-B0B7-D626B54A4350}
    c:\users\excell\AppData\Local\{A4016E36-B7F0-480F-B078-33570073C6AD}
    c:\users\excell\AppData\Local\{A65F3E55-EC92-490D-9980-98988A6BA311}
    c:\users\excell\AppData\Local\{F6290FFD-F9E1-4A23-8E3A-BA4E83A10CD5}
    c:\users\excell\AppData\Local\{9970EEEE-87A7-48DB-9C3E-2976749BF6E8}
    c:\users\excell\AppData\Local\{AAD184F9-6D04-4A7E-BFB2-ABD889EF11BF}
    c:\users\excell\AppData\Local\{5CBA3A40-787A-4005-BAE4-3B1EEB3B08A5}
    c:\users\excell\AppData\Local\{1696EDF9-A04A-4187-863C-DA5769EC09DE}
    c:\users\excell\AppData\Local\{A17DCD1F-0B7B-41A9-BE93-8A8D1E88C88E}
    c:\users\excell\AppData\Local\{D96A1BA5-21E9-4088-A881-28AD8A332E63}
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi Tomk. I did as you instructed. Combofix asked me if i wanted to update to the latest version of Combofix, i clicked no and continued with it. The log it produced is pasted below, however, it wouldnt let me open anything after it was finished as it would come up with an error saying illegal registry entry marked for deletion or something like tht. So i restarted it and it seems to be working like before now.


ComboFix 11-05-06.05 - excell 08/05/2011 20:52:04.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3581.2388 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\excell\Desktop\CFScript.txt
AV: COMODO Antivirus *Disabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\excell\AppData\Local\BITD70C.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\excell\AppData\Local\{0431DF45-3BE8-4E7E-9C12-F8A48E732B83}
c:\users\excell\AppData\Local\{0AF2143B-B2D3-4793-B44C-DC90C4B1EC28}
c:\users\excell\AppData\Local\{1696EDF9-A04A-4187-863C-DA5769EC09DE}
c:\users\excell\AppData\Local\{21A3C44A-E0B6-42CB-B0B7-D626B54A4350}
c:\users\excell\AppData\Local\{3C97D950-DB41-4673-A7C3-BB63197B94EA}
c:\users\excell\AppData\Local\{3D7554E8-D491-47A7-9643-F0402014FBEA}
c:\users\excell\AppData\Local\{4590A734-F852-4998-B289-19F830CF9E09}
c:\users\excell\AppData\Local\{4C187D52-10B9-4004-9287-25340BF6652D}
c:\users\excell\AppData\Local\{4CC4D866-DECF-4F4E-B243-AE53374CFE50}
c:\users\excell\AppData\Local\{54E279CE-1F5C-4377-975E-9EDAD5ACAF24}
c:\users\excell\AppData\Local\{5A9956A3-DF4A-45BA-9125-FA45371A1167}
c:\users\excell\AppData\Local\{5CBA3A40-787A-4005-BAE4-3B1EEB3B08A5}
c:\users\excell\AppData\Local\{620EB4B7-02F7-43FB-97F9-915CEAA22DF1}
c:\users\excell\AppData\Local\{645A6CC2-659D-4227-AD72-522482686AE8}
c:\users\excell\AppData\Local\{697421A0-E4A4-4586-A635-24609F485104}
c:\users\excell\AppData\Local\{72EF516C-1967-4D28-BBAD-CB8C89BF5758}
c:\users\excell\AppData\Local\{86134DE3-CAE6-46A3-B905-3DDDA4A4D0A9}
c:\users\excell\AppData\Local\{9970EEEE-87A7-48DB-9C3E-2976749BF6E8}
c:\users\excell\AppData\Local\{9F811721-EE46-49ED-A510-5194454EEDF7}
c:\users\excell\AppData\Local\{A17DCD1F-0B7B-41A9-BE93-8A8D1E88C88E}
c:\users\excell\AppData\Local\{A4016E36-B7F0-480F-B078-33570073C6AD}
c:\users\excell\AppData\Local\{A4A4AFD4-F201-4443-9701-BD8D6DD9C5AC}
c:\users\excell\AppData\Local\{A5A1474A-F92A-4555-9C49-DA6173A0888E}
c:\users\excell\AppData\Local\{A65F3E55-EC92-490D-9980-98988A6BA311}
c:\users\excell\AppData\Local\{A9FEEA30-56EB-4DD0-A5E7-5BF8F69892F5}
c:\users\excell\AppData\Local\{AAD184F9-6D04-4A7E-BFB2-ABD889EF11BF}
c:\users\excell\AppData\Local\{AF235023-E2C4-4775-AB10-48B79016AEFA}
c:\users\excell\AppData\Local\{B419B144-940F-4C8E-ACFC-97D33A3B064F}
c:\users\excell\AppData\Local\{BABFFBF0-CB60-477D-BE58-D05D80E8F851}
c:\users\excell\AppData\Local\{BFFD2B0A-FF9C-4096-9AC3-2B815D52704E}
c:\users\excell\AppData\Local\{C69783B7-B45B-4BBF-A63F-5E7289641227}
c:\users\excell\AppData\Local\{C7758D0B-A31C-4FED-AFB5-ACC707FE42C5}
c:\users\excell\AppData\Local\{C8AC50DF-0A43-40C9-95CF-F4A9A2A43972}
c:\users\excell\AppData\Local\{CD633A71-8ED5-4520-9882-EDC3CB209611}
c:\users\excell\AppData\Local\{D96A1BA5-21E9-4088-A881-28AD8A332E63}
c:\users\excell\AppData\Local\{DFEFD1AA-D8EF-4E83-AE44-B25294D83125}
c:\users\excell\AppData\Local\{F5FE8FC4-C05B-4B92-8099-984008344AF8}
c:\users\excell\AppData\Local\{F6290FFD-F9E1-4A23-8E3A-BA4E83A10CD5}
c:\users\excell\AppData\Local\{F7C38C3C-7FB0-482F-9070-B90B62B4E2E7}
.
.
((((((((((((((((((((((((( Files Created from 2011-04-08 to 2011-05-08 )))))))))))))))))))))))))))))))
.
.
2011-05-08 19:58 . 2011-05-08 19:58 ——– d—–w- c:\users\excell\AppData\Local\temp
2011-05-08 19:58 . 2011-05-08 19:58 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2011-05-08 19:58 . 2011-05-08 19:58 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-05-08 19:29 . 2011-05-08 19:29 ——– d—–w- c:\users\excell\AppData\Local\{2BDB1B79-2FD9-4C42-95A2-A5F64D5B86CC}
2011-05-08 13:15 . 2011-05-08 13:15 ——– d—–w- c:\users\excell\AppData\Local\{9C71CD59-1CEF-42C0-9E68-059CE85059C2}
2011-05-01 23:00 . 2011-04-14 16:41 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-01 23:00 . 2011-04-14 16:41 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-01 23:00 . 2011-04-14 16:41 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-01 23:00 . 2011-04-14 16:41 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-01 23:00 . 2011-04-14 16:41 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-01 23:00 . 2011-04-14 16:41 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-01 23:00 . 2010-01-01 08:00 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-01 23:00 . 2010-01-01 08:00 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-29 20:01 . 2011-04-29 20:01 ——– d—–w- c:\users\excell\AppData\Local\Adobe
2011-04-27 21:00 . 2011-04-27 21:00 ——– d—–w- c:\users\Default\AppData\Roaming\Trusteer
2011-04-27 19:49 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 19:49 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 19:48 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-20 00:35 . 2011-04-18 10:23 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-04-19 22:22 . 2011-04-19 00:00 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-04-19 22:22 . 2011-04-19 22:22 ——– d—–w- c:\users\excell\AppData\Local\Sunbelt Software
2011-04-19 22:22 . 2011-04-19 22:22 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-19 22:20 . 2011-04-19 22:20 ——– d—–w- c:\programdata\NVIDIA Corporation
2011-04-19 22:20 . 2011-04-19 22:21 ——– d—–w- c:\program files\NVIDIA Corporation
2011-04-19 22:16 . 2011-04-19 22:16 ——– dc-h–w- c:\programdata\{AA5544E4-9BBC-419B-9204-40B5924D26AA}
2011-04-19 22:16 . 2011-04-19 22:21 ——– d—–w- c:\programdata\Lavasoft
2011-04-19 22:16 . 2011-04-19 22:16 ——– d—–w- c:\program files\Lavasoft
2011-04-19 18:09 . 2011-04-19 18:09 ——– d—–w- c:\programdata\Skype Extras
2011-04-19 18:07 . 2011-04-19 18:07 ——– d—–w- c:\program files\Common Files\Skype
2011-04-16 01:16 . 2011-04-16 01:16 ——– d—–w- c:\users\excell\AppData\Local\Trusteer
2011-04-12 22:36 . 2011-04-12 22:36 ——– d—–w- c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\DVDVideoSoft
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Publish Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\NetMedia Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Sony
2011-04-12 22:16 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Local\Sony
2011-04-12 21:49 . 2011-04-12 21:49 ——– d—–w- c:\program files\Sony
2011-04-09 17:16 . 2011-04-09 17:18 ——– d—–w- c:\program files\Nuclear Coffee
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-08 09:17 . 2011-04-08 09:17 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-03-25 23:48 . 2011-03-25 23:48 4284416 —-a-w- c:\windows\system32\GPhotos.scr
2011-03-13 21:13 . 2011-03-13 21:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-11 23:17 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-03 15:40 . 2011-04-27 19:49 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 19:49 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 19:49 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 19:49 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-23 22:39 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 22:39 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 22:39 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-04-14 16:41 . 2011-05-01 23:00 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 19:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-10-25 167936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-02-07 2548552]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-16 49168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-24 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-16 22:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Users^excell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 12:49 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 —-a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CinemaNowMediaManagerApp]
2008-09-05 09:43 2017640 —-a-w- c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 13:49 405639 ——w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 14:46 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-02-15 01:32 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eSnips_Downloader]
2010-05-24 11:30 1234432 —-a-w- c:\program files\Logia\eSnipsDownloader\eSnips_Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 10:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-11-10 02:54 4240760 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 17:01 36864 —-a-w- c:\windows\OEM02Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 11:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-05-02 2146496]
R2 uvnc_service;UltraVNC Server;c:\programdata\UltraVNC\winvnc.exe [2008-08-31 1519168]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-19 15232]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Apache2.2;Remote Access Media Server;c:\program files\Common Files\Dell\apache\bin\httpd.exe [2007-09-21 15872]
R4 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2008-09-05 137080]
R4 dsl-db;Remote Access DB;c:\program files\Common Files\Dell\MySQL\bin\mysqld.exe [2007-09-14 5730304]
R4 dsl-fs-sync;Remote Access File Sync Service;c:\program files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [2009-04-13 189680]
R4 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-19 64512]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-04-08 53816]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2011-02-07 17256]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-02-07 236600]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-02-07 34744]
S1 RapportCerberus_26169;RapportCerberus_26169;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\26169\RapportCerberus_26169.sys [2011-05-02 57144]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-04-08 66360]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-04-08 158904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe [2007-09-20 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-04-08 870200]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-30 144128]
S3 RapportIaso;RapportIaso;c:\programdata\Trusteer\Rapport\store\exts\RapportMS\24413\RapportIaso.sys [2011-04-15 18872]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - RAPPORTIASO
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-07 c:\windows\Tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job
- c:\windows\system32\msfeedssync.exe [2011-04-14 04:43]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to MP3 Converter - c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\excell\AppData\Roaming\Mozilla\Firefox\Profiles\a9zmt3eo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-08 20:58
Windows 6.0.6002 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1654437360-1725257235-4155127740-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*µ*~*%\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'Explorer.exe'(3732)
c:\windows\system32\guard32.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
Completion time: 2011-05-08 21:00:13
ComboFix-quarantined-files.txt 2011-05-08 20:00
ComboFix2.txt 2011-05-07 21:10
.
Pre-Run: 66,246,402,048 bytes free
Post-Run: 66,155,421,696 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=66 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,
56,57,58,59,60,61,62,63,64,65,66
- - End Of File - - 6559CDDC39E3CFA41B6047CFC95F55A4
I'm not really finding the cause of your problem. However,

AV: COMODO Antivirus *Disabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}

Running two AV programs can cause problems. I suggest you uninstall Lavasoft Ad-Watch.

This is just a little more straightening up. If Combofix asks to update… let it.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    FixCSet::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Ok i have uninstalled the AdAware software u asked me to uninstall. My brother installed bitdefender on my laptop yesterday so when i tried to run ComboFix yday bitdefender wouldnt let me. So i allowed all actions by combofix as i couldnt figure out how to disable BitDefender. So then my laptop restarted n it opened the combofix command window and stayed there for like 2 hours so i had to turn it off manually. I tried to run it tday by disabling bitdefender and this time combofix tried to delete one bitdefenders files and then it got stuck after the restart for like an hour so i have closed it manually again. Now i keep getting the error from bitdefender for that missing file every 5 mins :(
You want one… and only one anti-virus running or it will cause you problems. You already have Comodo running. Why did your brother install Bitdefender? I suggest that you uninstall Bitdefender… Either that or you uninstall Comodo but be aware that when you do, you will also be uninstalling your firewall so you want to be sure you get a new one running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI