This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish computer

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer is running very slowly. No pop ups or other overt signs of infection, but screens aren't smoothly transitioning and there is periodic freezing. I've run Ad-Aware and Spybot. Hasn't helped.

Below is the hijack this log. Thanks for your help. Anna

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:40:40 PM, on 9/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\Home\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3007394
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
R3 - URLSearchHook: Messenger Plus Live CA-EN Toolbar - {437c4386-9237-441f-a940-009430030ee0} - C:\Program Files\Messenger_Plus_Live_CA-EN\prxtbMes0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Softonic-Eng7 - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
O2 - BHO: Messenger Plus Live CA-EN - {437c4386-9237-441f-a940-009430030ee0} - C:\Program Files\Messenger_Plus_Live_CA-EN\prxtbMes0.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
O3 - Toolbar: Messenger Plus Live CA-EN Toolbar - {437c4386-9237-441f-a940-009430030ee0} - C:\Program Files\Messenger_Plus_Live_CA-EN\prxtbMes0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1277442894703
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 9685 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi xbears,

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post the logs created by DDS and GMER. :)
Below are the results of the scans. Thanks for your help. gmr.txt is attached. Anna DDS Notepad . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 18:12:10 on 2011-09-02 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.786 [GMT -4:00] . AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxpers.exe C:\WINDOWS\System32\igfxsrvc.exe C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe C:\Program Files\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3007394 uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll uURLSearchHooks: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\prxtbSof0.dll uURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files\messenger_plus_live_ca-en\prxtbMes0.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\prxtbSof0.dll BHO: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files\messenger_plus_live_ca-en\prxtbMes0.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll TB: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\prxtbSof0.dll TB: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files\messenger_plus_live_ca-en\prxtbMes0.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SecurDisc] c:\program files\nero\nero 7\incd\NBHGui.exe mRun: [InCD] c:\program files\nero\nero 7\incd\InCD.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1277442894703 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] TCP: Interfaces\{E0CCCD2D-9E36-40B9-98AB-88D29CBE61E7} : DhcpNameServer = [removed] Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - WhiteSmoke Bar Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://blackle.com/ FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko19.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko5.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko6.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\FFExternalAlert.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCoreGecko19.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCore.dll FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ClickPotatoLiteSA.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed] FF - Ext: WhiteSmoke Bar Community Toolbar: {167d9323-f7cc-48f5-948a-6f012831a69f} - %profile%\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} FF - Ext: Messenger Plus Live CA-EN Community Toolbar: {437c4386-9237-441f-a940-009430030ee0} - %profile%\extensions\{437c4386-9237-441f-a940-009430030ee0} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4 FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-2-14 64512] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 297168] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-6-25 54760] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-12-3 2151640] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-20 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-20 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-20 27216] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-6-25 1691480] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-6 1025352] S3 cpuz132;cpuz132;\??\c:\docume~1\home\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\home\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872] . =============== Created Last 30 ================ . 2011-08-20 23:47:52 ——– d—–w- c:\documents and settings\home\application data\WhiteSmoke 2011-08-20 23:47:13 ——– d—–w- c:\program files\WhiteSmoke 2011-08-20 23:47:12 ——– d—–w- c:\documents and settings\home\local settings\application data\Temp 2011-08-10 21:50:30 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-10 21:50:17 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys . ==================== Find3M ==================== . 2011-08-21 02:37:42 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-30 17:55:43 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 —-a-w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll . ============= FINISH: 18:12:54.62 =============== DDS Attach Log . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 6/24/2010 10:29:31 PM System Uptime: 9/2/2011 8:37:55 AM (10 hours ago) . Motherboard: Intel Corporation | | D945GCPE Processor: Genuine Intel® CPU 2140 @ 1.60GHz | LGA 775 | 1596/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 205.367 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP480: 6/6/2011 6:40:01 AM - System Checkpoint RP481: 6/7/2011 6:54:42 AM - System Checkpoint RP482: 6/8/2011 7:34:40 AM - System Checkpoint RP483: 6/9/2011 8:34:40 AM - System Checkpoint RP484: 6/10/2011 8:46:40 AM - System Checkpoint RP485: 6/11/2011 11:35:47 AM - System Checkpoint RP486: 6/12/2011 1:27:58 PM - System Checkpoint RP487: 6/13/2011 2:12:21 PM - System Checkpoint RP488: 6/13/2011 8:55:32 PM - Installed Java™ 6 Update 26 RP489: 6/15/2011 3:00:28 AM - Software Distribution Service 3.0 RP490: 6/16/2011 6:36:49 AM - System Checkpoint RP491: 6/17/2011 6:39:05 AM - System Checkpoint RP492: 6/18/2011 11:42:09 AM - System Checkpoint RP493: 6/20/2011 6:41:54 AM - System Checkpoint RP494: 6/21/2011 7:13:07 AM - System Checkpoint RP495: 6/22/2011 7:49:21 AM - System Checkpoint RP496: 6/23/2011 9:19:40 AM - System Checkpoint RP497: 6/24/2011 10:01:51 AM - System Checkpoint RP498: 6/27/2011 6:39:10 AM - System Checkpoint RP499: 6/28/2011 6:45:04 AM - System Checkpoint RP500: 6/29/2011 6:48:34 AM - System Checkpoint RP501: 6/29/2011 6:14:09 PM - Software Distribution Service 3.0 RP502: 6/30/2011 6:45:02 PM - System Checkpoint RP503: 7/2/2011 2:34:04 PM - System Checkpoint RP504: 7/7/2011 11:47:55 AM - System Checkpoint RP505: 7/8/2011 6:07:53 PM - System Checkpoint RP506: 7/10/2011 9:22:16 AM - System Checkpoint RP507: 7/11/2011 9:44:59 AM - System Checkpoint RP508: 7/13/2011 6:44:24 AM - System Checkpoint RP509: 7/14/2011 3:00:19 AM - Software Distribution Service 3.0 RP510: 7/15/2011 6:40:18 AM - System Checkpoint RP511: 7/17/2011 10:00:28 AM - System Checkpoint RP512: 7/18/2011 10:26:43 AM - System Checkpoint RP513: 7/19/2011 11:26:43 AM - System Checkpoint RP514: 7/20/2011 12:38:43 PM - System Checkpoint RP515: 7/21/2011 1:26:43 PM - System Checkpoint RP516: 7/22/2011 2:26:43 PM - System Checkpoint RP517: 7/23/2011 11:51:19 PM - System Checkpoint RP518: 7/25/2011 6:42:00 AM - System Checkpoint RP519: 7/26/2011 6:45:11 AM - System Checkpoint RP520: 7/27/2011 7:35:38 AM - System Checkpoint RP521: 7/28/2011 8:50:08 AM - System Checkpoint RP522: 7/29/2011 9:47:38 AM - System Checkpoint RP523: 7/30/2011 11:26:18 PM - System Checkpoint RP524: 7/31/2011 11:40:06 PM - System Checkpoint RP525: 8/2/2011 6:43:13 AM - System Checkpoint RP526: 8/3/2011 6:50:18 AM - System Checkpoint RP527: 8/4/2011 7:35:37 AM - System Checkpoint RP528: 8/5/2011 7:43:00 AM - System Checkpoint RP529: 8/6/2011 11:59:14 AM - System Checkpoint RP530: 8/7/2011 3:19:32 PM - System Checkpoint RP531: 8/8/2011 3:43:00 PM - System Checkpoint RP532: 8/9/2011 4:55:00 PM - System Checkpoint RP533: 8/10/2011 5:14:05 PM - System Checkpoint RP534: 8/11/2011 3:00:25 AM - Software Distribution Service 3.0 RP535: 8/12/2011 6:41:26 AM - System Checkpoint RP536: 8/14/2011 10:34:03 AM - System Checkpoint RP537: 8/15/2011 11:07:49 AM - System Checkpoint RP538: 8/16/2011 3:14:32 PM - System Checkpoint RP539: 8/17/2011 6:08:10 PM - System Checkpoint RP540: 8/18/2011 9:24:04 PM - System Checkpoint RP541: 8/19/2011 3:00:14 AM - Software Distribution Service 3.0 RP542: 8/20/2011 12:25:23 PM - System Checkpoint RP543: 8/20/2011 10:22:22 PM - Removed Bing Bar RP544: 8/20/2011 10:43:44 PM - Removed LimeWire Toolbar. RP545: 8/22/2011 11:05:27 AM - System Checkpoint RP546: 8/23/2011 3:13:04 PM - System Checkpoint RP547: 8/24/2011 7:11:15 PM - System Checkpoint RP548: 8/25/2011 3:00:15 AM - Software Distribution Service 3.0 RP549: 8/26/2011 6:57:50 AM - System Checkpoint RP550: 8/28/2011 10:34:33 PM - System Checkpoint RP551: 8/30/2011 6:40:22 AM - System Checkpoint RP552: 8/31/2011 6:40:34 AM - System Checkpoint RP553: 9/1/2011 6:43:13 AM - System Checkpoint RP554: 9/2/2011 6:44:32 AM - System Checkpoint . ==== Installed Programs ====================== . Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.5 ArcSoft Software Suite AVG 2011 AVG PC Tuneup 2011 DivX Setup Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Intel® Graphics Media Accelerator Driver Java Auto Updater Java™ 6 Update 26 Junk Mail filter update Lexmark 730 Series Messenger Plus Live CA-EN Toolbar Messenger Plus! 5 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox (3.6.7) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6 Service Pack 2 (KB973686) Nero 7 Essentials neroxml REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office Groove 2007 (KB2494047) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB913433) Segoe UI Softonic-Eng7 Toolbar Spybot - Search & Destroy Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Outlook 2007 (KB2509470) Update for Outlook 2007 Junk Email Filter (KB2586924) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB982632) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB971029) VC80CRTRedist - 8.0.50727.4053 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows Imaging Component Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 9/2/2011 8:40:29 AM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk4\D. 9/2/2011 8:40:29 AM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\D. 9/1/2011 6:28:19 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\D. 9/1/2011 6:25:55 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the lxcf_device service to connect. 9/1/2011 6:25:55 PM, error: Service Control Manager [7000] - The lxcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 9/1/2011 6:25:54 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service lxcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E44106F} 8/27/2011 2:22:12 PM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. . ==== End Of File ===========================

Attachments:

Hi xbears,

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features. A list of installed programs will populate

Remove the following programs:

Messenger Plus Live CA-EN Toolbar
Softonic-Eng7 Toolbar

———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

In your next reply please post the log created by ComboFix. :)
Combofix log:

ComboFix 11-09-03.01 - Home 09/03/2011 15:19:48.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1470 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Home\Application Data\PriceGong
c:\documents and settings\Home\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Home\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Home\Local Settings\Temporary Internet Files\cookies.sqlite
c:\program files\messenger\msmsgsin.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-03 to 2011-09-03 )))))))))))))))))))))))))))))))
.
.
2011-09-03 18:59 . 2011-09-03 18:59 ——– d-sh–w- c:\documents and settings\Home\IECompatCache
2011-08-20 23:47 . 2011-08-20 23:47 ——– d—–w- c:\documents and settings\Home\Application Data\WhiteSmoke
2011-08-20 23:47 . 2011-08-21 02:20 ——– d—–w- c:\program files\WhiteSmoke
2011-08-20 23:47 . 2011-08-20 23:47 ——– d—–w- c:\documents and settings\Home\Local Settings\Application Data\Temp
2011-08-10 21:50 . 2011-06-24 14:10 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 21:50 . 2011-07-08 14:02 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-21 02:37 . 2011-05-18 02:32 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2002-08-29 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2002-08-29 12:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-30 17:55 . 2011-02-14 18:53 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10 . 2010-06-25 02:25 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2006-06-23 18:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2002-08-29 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2002-08-29 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2002-08-29 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 14:15 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2007-07-11 131072]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2007-07-11 155648]
"Persistence"="c:\windows\System32\igfxpers.exe" [2007-07-11 131072]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"RTHDCPL"="RTHDCPL.EXE" [2010-06-09 19552872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 7:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 6:48 AM 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/14/2011 2:54 PM 64512]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 6:48 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 6:49 AM 297168]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/25/2010 1:52 AM 1691480]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/6/2011 7:01 PM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/18/2011 5:39 PM 7398752]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/20/2010 12:42 AM 134480]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/20/2010 12:42 AM 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/20/2010 12:42 AM 27216]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 5:05 AM 2151640]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/3/2010 5:05 AM 15232]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 07:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3007394
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke Bar Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://blackle.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - Ext: WhiteSmoke Bar Community Toolbar: {167d9323-f7cc-48f5-948a-6f012831a69f} - %profile%\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Messenger Plus Live CA-EN Community Toolbar: {437c4386-9237-441f-a940-009430030ee0} - %profile%\extensions\{437c4386-9237-441f-a940-009430030ee0}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-03 15:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-09-03 15:27:26
ComboFix-quarantined-files.txt 2011-09-03 19:27
.
Pre-Run: 221,206,851,584 bytes free
Post-Run: 221,599,010,816 bytes free
.
- - End Of File - - A5C4218DBE48EFCE9003B23C625A34EE
Hi xbears,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3007394
uURLSearchHooks: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\prxtbSof0.dll
uURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files\messenger_plus_live_ca-en\prxtbMes0.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\prxtbSof0.dll
BHO: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files\messenger_plus_live_ca-en\prxtbMes0.dll

Firefox::
FF - ProfilePath - c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke Bar Customized Web Search
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko5.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko6.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCore.dll
FF - component: c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ClickPotatoLiteSA.dll
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - Ext: WhiteSmoke Bar Community Toolbar: {167d9323-f7cc-48f5-948a-6f012831a69f} - %profile%\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Messenger Plus Live CA-EN Community Toolbar: {437c4386-9237-441f-a940-009430030ee0} - %profile%\extensions\{437c4386-9237-441f-a940-009430030ee0}

Folder::
c:\documents and settings\Home\Application Data\WhiteSmoke
c:\program files\WhiteSmoke
c:\program files\softonic-eng7
c:\program files\messenger_plus_live_ca-en

Registry::
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"=-
"{437c4386-9237-441f-a940-009430030ee0}"=-


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
———-
ComboFix 11-09-03.01 - Home 09/03/2011 19:21:56.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1171 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Home\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\chrome.manifest
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\chrome\whitesmoke_bar.jar
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCore.xpt
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko19.dll
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko5.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\components\RadioWMPCoreGecko6.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\alertSettingsComponent.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\appContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\engineContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\engineSettings.json
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\fbAlert.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\getAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\postAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\toolbarContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\defaults\unsharedAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\INSTALL.LOG
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\install.rdf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\META-INF\manifest.mf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\META-INF\zigbert.rsa
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\META-INF\zigbert.sf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Chat.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\DataStructures.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\EBEncryption.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\ExternalLibraryLoader.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\HTTP.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\IO.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Log.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\MainSingleton.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\MD5.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Notifications.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\ObserversAndEvents.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Prefs.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\SearchProtector.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\SearchSuggestIO.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\String.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\TEAEncryption.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Timer.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Twitter.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\URL.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\Windows.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\modules\XML.jsm
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\searchplugin\conduit.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\setup.ini
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}\version.txt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\chrome.manifest
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\chrome\softonic-eng7.jar
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitToolbar.idl
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitToolbar.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitToolbar.xpt
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\FFExternalAlert.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\FFExternalAlert.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\default_radio_skin.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\fbAlert.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\install.rdf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\lib\xpcom.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\manifest.mf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\zigbert.rsa
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\zigbert.sf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.gif
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.ico
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.PNG
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.src
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\version.txt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\chrome.manifest
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\chrome\messenger_plus_live_ca-en.jar
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\ConduitToolbar.idl
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\ConduitToolbar.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\ConduitToolbar.xpt
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.xpt
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCoreGecko19.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\alertSettingsComponent.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\appContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\engineContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\engineSettings.json
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\fbAlert.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\getAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\postAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\toolbarContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\defaults\unsharedAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\install.rdf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\lib\xpcom.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\META-INF\manifest.mf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\META-INF\zigbert.rsa
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\META-INF\zigbert.sf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\searchplugin\conduit.gif
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\searchplugin\conduit.ico
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\searchplugin\conduit.PNG
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\searchplugin\conduit.src
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\searchplugin\conduit.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\version.txt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\chrome.manifest
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\chrome\conduitengine.jar
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\ConduitToolbar.idl
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\ConduitToolbar.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\ConduitToolbar.xpt
c:\documents and settings\home\application data\mozilla\firefox\profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCore.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCore.xpt
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\alertSettingsComponent.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\appContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\engineContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\engineSettings.json
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\fbAlert.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\getAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\postAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\toolbarContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\defaults\unsharedAppsContextMenu.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\DualPackage\install.rdf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\install.rdf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\lib\xpcom.js
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\META-INF\manifest.mf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\META-INF\zigbert.rsa
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\META-INF\zigbert.sf
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\searchplugin\conduit.gif
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\searchplugin\conduit.ico
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\searchplugin\conduit.PNG
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\searchplugin\conduit.src
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\searchplugin\conduit.xml
c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\extensions\[removed]\version.txt
c:\documents and settings\Home\Application Data\WhiteSmoke
c:\documents and settings\Home\Application Data\WhiteSmoke\stat.log
c:\program files\conduitengine\prxConduitEngine.dll
c:\program files\WhiteSmoke
.
.
((((((((((((((((((((((((( Files Created from 2011-08-03 to 2011-09-03 )))))))))))))))))))))))))))))))
.
.
2011-09-03 18:59 . 2011-09-03 18:59 ——– d-sh–w- c:\documents and settings\Home\IECompatCache
2011-08-20 23:47 . 2011-08-20 23:47 ——– d—–w- c:\documents and settings\Home\Local Settings\Application Data\Temp
2011-08-10 21:50 . 2011-06-24 14:10 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 21:50 . 2011-07-08 14:02 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-21 02:37 . 2011-05-18 02:32 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2002-08-29 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2002-08-29 12:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-30 17:55 . 2011-02-14 18:53 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10 . 2010-06-25 02:25 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2006-06-23 18:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2002-08-29 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2002-08-29 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2002-08-29 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 14:15 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2007-07-11 131072]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2007-07-11 155648]
"Persistence"="c:\windows\System32\igfxpers.exe" [2007-07-11 131072]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"RTHDCPL"="RTHDCPL.EXE" [2010-06-09 19552872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 7:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 6:48 AM 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/14/2011 2:54 PM 64512]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 6:48 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 6:49 AM 297168]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 5:05 AM 2151640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/20/2010 12:42 AM 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/20/2010 12:42 AM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/20/2010 12:42 AM 27216]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/25/2010 1:52 AM 1691480]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/6/2011 7:01 PM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/18/2011 5:39 PM 7398752]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/3/2010 5:05 AM 15232]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 07:40]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\
FF - prefs.js: browser.startup.homepage - hxxp://blackle.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-03 19:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-09-03 19:27:28
ComboFix-quarantined-files.txt 2011-09-03 23:27
ComboFix2.txt 2011-09-03 19:27
.
Pre-Run: 221,663,768,576 bytes free
Post-Run: 221,650,878,464 bytes free
.
- - End Of File - - 270362F653F6149F9DB6143B2B0F7D88
Hi xbears,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET Online Scanner. :)
Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7659 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 9/5/2011 5:34:04 PM mbam-log-2011-09-05 (17-34-04).txt Scan type: Quick scan Objects scanned: 158504 Time elapsed: 4 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESCAN Log C:\Documents and Settings\Home\Application Data\AVG\Rescue\PC Tuneup 2011\101121174831453.rsc multiple threats C:\Documents and Settings\Home\Desktop\MsgPlusLive-484.exe a variant of Win32/MessengerPlus application
Hi xbears,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Home\Application Data\AVG\Rescue\PC Tuneup 2011\101121174831453.rsc
C:\Documents and Settings\Home\Desktop\MsgPlusLive-484.exe


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
———-


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.4.5 first. Be sure to move any PDF documents to another folder first though.
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

In your next reply please post the log created by ComboFix and let me know how your system is running. :)
Log posted below. Computer still seems slow (a bit better, but still slow)

ComboFix 11-09-06.01 - Home 09/06/2011 8:24.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.976 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-08-06 to 2011-09-06 )))))))))))))))))))))))))))))))
.
.
2011-09-05 22:06 . 2011-09-05 22:06 ——– d—–w- c:\program files\ESET
2011-09-05 21:29 . 2011-09-05 21:29 ——– d—–w- c:\documents and settings\Home\Application Data\Malwarebytes
2011-09-05 21:28 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-05 21:28 . 2011-09-05 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-05 21:28 . 2011-09-05 21:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-09-05 21:28 . 2011-07-06 23:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-03 18:59 . 2011-09-03 18:59 ——– d-sh–w- c:\documents and settings\Home\IECompatCache
2011-08-20 23:47 . 2011-08-20 23:47 ——– d—–w- c:\documents and settings\Home\Local Settings\Application Data\Temp
2011-08-10 21:50 . 2011-06-24 14:10 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 21:50 . 2011-07-08 14:02 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-21 02:37 . 2011-05-18 02:32 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2002-08-29 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2002-08-29 12:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-30 17:55 . 2011-02-14 18:53 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10 . 2010-06-25 02:25 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2006-06-23 18:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2002-08-29 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2002-08-29 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2002-08-29 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 14:15 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2007-07-11 131072]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2007-07-11 155648]
"Persistence"="c:\windows\System32\igfxpers.exe" [2007-07-11 131072]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"RTHDCPL"="RTHDCPL.EXE" [2010-06-09 19552872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 7:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 6:48 AM 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/14/2011 2:54 PM 64512]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 6:48 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 6:49 AM 297168]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/5/2011 5:28 PM 366640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/20/2010 12:42 AM 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/20/2010 12:42 AM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/20/2010 12:42 AM 27216]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 5:05 AM 2152152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/5/2011 5:28 PM 22712]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/25/2010 1:52 AM 1691480]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/6/2011 7:01 PM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/18/2011 5:39 PM 7398752]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/3/2010 5:05 AM 15232]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - IPFILTERDRIVER
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSERVICE
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 07:40]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Home\Application Data\Mozilla\Firefox\Profiles\w4u1t0yx.default\
FF - prefs.js: browser.startup.homepage - hxxp://blackle.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-06 08:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3692)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-09-06 08:30:55
ComboFix-quarantined-files.txt 2011-09-06 12:30
ComboFix2.txt 2011-09-03 23:27
ComboFix3.txt 2011-09-03 19:27
.
Pre-Run: 220,934,868,992 bytes free
Post-Run: 220,949,970,944 bytes free
.
- - End Of File - - A70AD0B77878DDA8A9B6F22AD83D7A7A
Hi xbears,

I notice that you have both AVG and Lavasoft running at the same time. Having more than one antivirus program running at the same time can seriously degrade the performance of your system. Please uninstall either AVG or Lavasoft (which ever you prefer) using either the provided uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel). As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.

I have provided the removal tool for AVG as it is sometimes difficult to remove completely if you choose to remove it:
AVG

Here are some other free Antivirus Programs that you could choose to use as well that are light on resources and could help with the speed of your system.
Microsoft Security Essentials
Avast
———-

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
———-

Could you now please run DDS once more and post both of the logs into your next reply so we can have one last look. Let me know how your system runs now too. :)
Due to lack of response … this Topic has been closed. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI