This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't Delete File Reference From Registry [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys -

I've been cleaning up my mom's computer from several infections, and I think I got everything (I hope); but there's a file reference in the registry that absolutely will not let me delete it, and it pops up every time I restart the computer:

"Could not load or run 'C:\Users\marytsc\LOCALS~1\Temp\b9fbfffe00014604.exe' specified in the registry. Make sure the file exists on your computer or remove the reference to it in the registry."

I can't seem to figure out how to gain access to the registry as the administrator so that it will allow me to delete the file.

I've pasted a copy of my Hijackthis file below - ANY help with this will be greatly appreciated!

Thank you,

Teresa


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:27:06 PM, on 4/30/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Users\marytsc\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\marytsc\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\marytsc\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\marytsc\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\marytsc\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\marytsc\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\marytsc\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher…d&%language
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file)
R3 - URLSearchHook: (no name) - {2c1e21b5-5666-4cd5-8152-96b690b7216e} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {f897eb0e-a3a4-46c3-80eb-2729699d8892} - (no file)
F3 - REG:win.ini: load=C:\Users\marytsc\LOCALS~1\Temp\b9fbfffe00014604.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Zynga - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
O4 - HKCU\..\Run: [Google Update] "C:\Users\marytsc\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: vToolbarUpdater11.0.2 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

–
End of file - 9002 bytes
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


R3 - URLSearchHook: (no name) - {2c1e21b5-5666-4cd5-8152-96b690b7216e} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {f897eb0e-a3a4-46c3-80eb-2729699d8892} - (no file)
F3 - REG:win.ini: load=C:\Users\marytsc\LOCALS~1\Temp\b9fbfffe00014604.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Okay, here are the four files: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 12:44:34 on 2012-05-01 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1917.1109 [GMT -4:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\agrsmsvc.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Flip Video\FlipShare\FlipShareService.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Toshiba\Utilities\KeNotify.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Users\marytsc\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uSearch Bar = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s uURLSearchHooks: H - No File mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\prxtbZyn0.dll uWindows: Load=c:\users\marytsc\locals~1\temp\b9fbfffe00014604.exe BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\prxtbZyn0.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.0.0.9\AVG Secure Search_toolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\prxtbZyn0.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.0.0.9\AVG Secure Search_toolbar.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: {B80F591E-FE9A-46CF-A13E-180377240586} - No File TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {22E03916-85C5-44B0-8DC9-1830C11238D9} - No File TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File TB: {A608C70C-2888-4073-BAEE-968F3FA69E5C} - No File TB: {82BD588C-ACD8-417D-A32E-EF441492B9F6} - No File TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} TB: {2C1E21B5-5666-4CD5-8152-96B690B7216E} - No File TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File TB: {F897EB0E-A3A4-46C3-80EB-2729699D8892} - No File uRun: [Google Update] "c:\users\marytsc\appdata\local\google\update\GoogleUpdate.exe" /c mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Skytel] Skytel.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{C1E71E4B-A292-4617-AED9-119AF17C1F21} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D9D3812D-53FD-43DC-A606-5627303D6653} : DhcpNameServer = [removed] [removed] Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\11.0.2\ViProtocol.dll SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-6-26 21504] R2 vToolbarUpdater11.0.2;vToolbarUpdater11.0.2;c:\program files\common files\avg secure search\vtoolbarupdater\11.0.2\ToolbarUpdater.exe [2012-4-29 932736] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-11 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-11 253088] S3 GamesAppService;GamesAppService;c:\program files\wildtangent games\app\GamesAppService.exe [2010-10-12 206072] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-11 136176] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-04-30 20:30:17 ——– d—–w- c:\program files\MSECache 2012-04-29 23:08:06 ——– d—–w- c:\users\marytsc\appdata\local\AVG Secure Search 2012-04-29 03:12:17 ——– d—–w- c:\program files\Trend Micro 2012-04-27 18:53:52 ——– d—–w- c:\program files\Rovio 2012-04-22 22:00:14 ——– d—–w- c:\users\marytsc\appdata\roaming\AVG 2012-04-22 05:26:06 6734704 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{3c863386-de18-4553-aa67-ef23c71fe819}\mpengine.dll 2012-04-12 07:18:53 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 07:18:53 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 07:18:53 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 07:18:53 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 07:17:25 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-12 07:17:25 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-12 07:16:47 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-04-11 23:28:17 ——– d—–w- c:\programdata\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} 2012-04-11 23:16:14 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2012-04-11 15:37:01 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe . ==================== Find3M ==================== . 2012-04-13 18:14:14 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-05 23:19:07 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-23 14:18:36 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll 2012-02-07 15:02:40 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys 2010-12-01 15:27:42 2735200 —-a-w- c:\program files\tbZyng.dll 2002-07-26 21:02:06 153088 —-a-w- c:\program files\UNWISE.EXE . ============= FINISH: 12:45:06.98 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 9/16/2007 6:43:38 AM System Uptime: 5/1/2012 8:44:15 AM (4 hours ago) . Motherboard: TOSHIBA | | JASAA Processor: AMD Turion™ 64 X2 Mobile Technology TL-58 | Socket M2/S1G1 | 1800/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 148 GiB total, 94.222 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e965-e325-11ce-bfc1-08002be10318} Description: CD-ROM Drive Device ID: IDE\CDROMPIONEER_DVD-RW_DVR-K17LF________________4.53____\5&383A5E59&0&0.0.0 Manufacturer: (Standard CD-ROM drives) Name: PIONEER DVD-RW DVR-K17LF ATA Device PNP Device ID: IDE\CDROMPIONEER_DVD-RW_DVR-K17LF________________4.53____\5&383A5E59&0&0.0.0 Service: cdrom . ==== System Restore Points =================== . RP629: 4/19/2012 10:41:34 AM - Scheduled Checkpoint RP630: 4/20/2012 12:00:04 AM - Scheduled Checkpoint RP631: 4/21/2012 12:00:04 AM - Scheduled Checkpoint RP632: 4/21/2012 6:42:44 PM - Removed Angry Birds RP633: 4/22/2012 1:23:45 AM - Windows Update RP634: 4/22/2012 1:20:15 PM - Installed Angry Birds Seasons RP635: 4/26/2012 8:14:54 PM - Scheduled Checkpoint RP636: 4/27/2012 1:38:08 PM - Removed Angry Birds Seasons RP637: 4/27/2012 1:53:46 PM - Removed Angry Birds Seasons RP638: 4/27/2012 2:26:39 PM - Installed Angry Birds Seasons RP639: 4/27/2012 2:33:59 PM - Removed Angry Birds Seasons RP640: 4/27/2012 2:53:31 PM - Installed Angry Birds RP641: 4/27/2012 5:38:16 PM - Windows Update RP642: 4/28/2012 2:07:27 PM - Installed Angry Birds Seasons RP643: 4/28/2012 11:11:55 PM - Installed HiJackThis RP644: 4/28/2012 11:19:25 PM - Removed HiJackThis RP645: 4/28/2012 11:22:56 PM - Installed HiJackThis RP646: 4/29/2012 7:37:08 PM - Scheduled Checkpoint RP647: 4/30/2012 4:30:20 PM - Installed Compatibility Pack for the 2007 Office system RP648: 4/30/2012 4:44:07 PM - Windows Update RP649: 5/1/2012 3:00:12 AM - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Activation Assistant for the 2007 Microsoft Office suites Adobe AIR Adobe Flash Player 11 ActiveX Adobe Reader 8.3.1 Amazon Kindle Angry Birds Angry Birds Seasons ATI Catalyst Install Manager AVG 2012 AVG Security Toolbar Bejeweled 2 Deluxe Bejeweled 3 Big Fish Games: Game Manager Bluetooth Stack for Windows by Toshiba BookWorm Deluxe 1.02 Camera Assistant Software for Toshiba Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Vista Catalyst Control Center Localization Chinese Standard Catalyst Control Center Localization Chinese Traditional Catalyst Control Center Localization Czech Catalyst Control Center Localization Danish Catalyst Control Center Localization Dutch Catalyst Control Center Localization Finnish Catalyst Control Center Localization French Catalyst Control Center Localization German Catalyst Control Center Localization Greek Catalyst Control Center Localization Hungarian Catalyst Control Center Localization Italian Catalyst Control Center Localization Japanese Catalyst Control Center Localization Korean Catalyst Control Center Localization Norwegian Catalyst Control Center Localization Polish Catalyst Control Center Localization Portuguese Catalyst Control Center Localization Russian Catalyst Control Center Localization Spanish Catalyst Control Center Localization Swedish Catalyst Control Center Localization Thai Catalyst Control Center Localization Turkish ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CD/DVD Drive Acoustic Silencer Compatibility Pack for the 2007 Office system Coupon Printer for Windows DVD MovieFactory for TOSHIBA EPSON Print CD EPSON Printer Software EPSON Scan Feedback Tool FlipShare Google Chrome Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Java Auto Updater Java™ 6 Update 31 Jewel Quest Heritage Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Microsoft XML Parser MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) OGA Notifier 2.0.0048.0 PCStitch Pattern Viewer Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Skins Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. Tile Blazer Special Edition TIPCI TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Flash Cards Support Utility TOSHIBA Hardware Setup Toshiba Registration TOSHIBA SD Memory Utilities TOSHIBA Software Modem TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password TOSHIBA Value Added Package Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update Installer for WildTangent Games App Utility Common Driver WildTangent Games WildTangent Games App (Toshiba Games) Windows Media Encoder 9 Series Zynga Toolbar . ==== Event Viewer Messages From Past Week ======== . 5/1/2012 8:45:35 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Cdr4_xp 5/1/2012 8:45:35 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 5/1/2012 8:44:56 AM, Error: EventLog [6008] - The previous system shutdown at 3:04:14 AM on 5/1/2012 was unexpected. 4/30/2012 8:28:24 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer HOME-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{D9D3812D-53FD-43DC-A606-5627303D66. The master browser is stopping or an election is being forced. 4/29/2012 8:49:36 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 001B9E522176 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 4/29/2012 8:48:16 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 001B9E522176 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 4/28/2012 5:39:14 PM, Error: netbt [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.3. The computer with the IP address 192.168.1.5 did not allow the name to be claimed by this computer. 4/28/2012 5:31:37 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001B9E522176. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 4/27/2012 8:19:06 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx86 Avgmfx86 Cdr4_xp cdrom spldr Wanarpv6 4/27/2012 8:19:06 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 8:18:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 4/27/2012 8:18:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 4/27/2012 8:18:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 4/27/2012 8:17:58 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 4/27/2012 6:11:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx86 Avgmfx86 Avgtdix Cdr4_xp cdrom DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:11:16 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 4/27/2012 6:10:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 4/27/2012 6:10:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 4/24/2012 6:56:40 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.4 for the Network Card with network address 001B9E522176 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-01 12:53:57 —————————– 12:53:57.123 OS Version: Windows 6.0.6002 Service Pack 2 12:53:57.123 Number of processors: 2 586 0x6801 12:53:57.138 ComputerName: MARYTSC-PC UserName: marytsc 12:53:58.995 Initialize success 12:57:27.810 AVAST engine defs: 12050100 12:58:19.290 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 12:58:19.290 Disk 0 Vendor: Hitachi_HTS541616J9SA00 SB4OC7DP Size: 152627MB BusType: 3 12:58:19.321 Disk 0 MBR read successfully 12:58:19.321 Disk 0 MBR scan 12:58:19.336 Disk 0 Windows VISTA default MBR code 12:58:19.368 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 12:58:19.383 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 151126 MB offset 3074048 12:58:19.399 Disk 0 scanning sectors +312580096 12:58:19.461 Disk 0 scanning C:\Windows\system32\drivers 12:58:31.520 Service scanning 12:59:03.594 Modules scanning 12:59:11.456 Disk 0 trace - called modules: 12:59:11.487 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 12:59:12.002 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84761ac8] 12:59:12.002 3 CLASSPNP.SYS[878ab8b3] -> nt!IofCallDriver -> [0x84647428] 12:59:12.018 5 acpi.sys[871d66bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84625b98] 12:59:12.938 AVAST engine scan C:\Windows 12:59:16.105 AVAST engine scan C:\Windows\system32 13:03:59.338 AVAST engine scan C:\Windows\system32\drivers 13:04:14.080 AVAST engine scan C:\Users\marytsc 13:06:31.579 AVAST engine scan C:\ProgramData 13:08:51.511 Scan finished successfully 13:11:37.089 Disk 0 MBR has been saved successfully to "C:\Users\marytsc\Desktop\MBR.dat" 13:11:37.089 The log file has been saved successfully to "C:\Users\marytsc\Desktop\aswMBR.txt"

Attachments:

hi,

Please do the following;

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Okay, CatByte : ) here's the C/F file:



ComboFix 12-05-01.02 - marytsc 05/01/2012 13:53:15.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1917.1038 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\CouponAlert_2pEI
c:\program files\INSTALL.LOG
c:\program files\TotalRecipeSearch_14EI
c:\program files\UNWISE.EXE
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\marytsc\AppData\Roaming\PriceGong
c:\users\marytsc\AppData\Roaming\PriceGong\Data\1.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\a.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\b.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\c.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\d.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\e.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\f.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\g.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\h.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\i.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\j.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\k.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\l.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\m.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\mru.xml
c:\users\marytsc\AppData\Roaming\PriceGong\Data\n.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\o.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\p.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\q.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\r.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\s.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\t.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\u.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\v.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\w.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\wlu.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\x.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\y.txt
c:\users\marytsc\AppData\Roaming\PriceGong\Data\z.txt
c:\users\marytsc\xobglu32.dll
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-04-01 to 2012-05-01 )))))))))))))))))))))))))))))))
.
.
2012-05-01 18:00 . 2012-05-01 18:00 ——– d—–w- c:\users\marytsc\AppData\Local\temp
2012-04-30 20:30 . 2012-04-30 20:30 ——– d—–w- c:\program files\MSECache
2012-04-29 23:08 . 2012-04-29 23:08 ——– d—–w- c:\users\marytsc\AppData\Local\AVG Secure Search
2012-04-29 03:12 . 2012-04-29 03:12 ——– d—–w- c:\program files\Trend Micro
2012-04-27 21:40 . 2012-04-27 21:40 ——– d—–w- c:\program files\Microsoft Silverlight
2012-04-27 18:53 . 2012-04-28 18:08 ——– d—–w- c:\program files\Rovio
2012-04-22 22:00 . 2012-04-22 22:00 ——– d—–w- c:\users\marytsc\AppData\Roaming\AVG
2012-04-22 05:26 . 2012-04-13 07:36 6734704 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3C863386-DE18-4553-AA67-EF23C71FE819}\mpengine.dll
2012-04-12 07:18 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-12 07:18 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-12 07:18 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-12 07:18 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 07:17 . 2012-03-06 06:39 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 07:17 . 2012-03-06 06:39 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-12 07:16 . 2012-04-12 07:16 ——– d-sh–w- c:\windows\system32\%APPDATA%
2012-04-11 23:28 . 2012-04-11 23:28 ——– d—–w- c:\programdata\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46}
2012-04-11 23:16 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-04-11 15:37 . 2012-04-13 18:14 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 18:14 . 2011-06-15 20:13 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-05 23:19 . 2012-03-05 23:20 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-02-23 14:18 . 2010-06-23 18:11 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-02-14 15:45 . 2012-03-14 13:56 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45 . 2012-03-14 13:56 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-02-13 14:12 . 2012-03-14 13:56 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-02-13 13:47 . 2012-03-14 13:56 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-02-13 13:44 . 2012-03-14 13:56 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-02-07 15:02 . 2012-02-07 15:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-02 15:16 . 2012-03-14 13:56 2044416 —-a-w- c:\windows\system32\win32k.sys
2010-12-01 15:27 . 2011-05-11 23:38 2735200 —-a-w- c:\program files\tbZyng.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2011-05-09 09:49 176936 —-a-w- c:\program files\Zynga\prxtbZyn0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-04-29 19:34 2067328 —-a-w- c:\program files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\prxtbZyn0.dll" [2011-05-09 176936]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll" [2012-04-29 2067328]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\prxtbZyn0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-07 4669440]
"Skytel"="Skytel.exe" [2007-06-16 1826816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-04-29 1116544]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-16 928096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2007-05-22 17:50 413696 —-a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 18:14]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-11 21:17]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-11 21:17]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2664181028-2477016499-3871223464-1000Core.job
- c:\users\marytsc\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-14 09:27]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2664181028-2477016499-3871223464-1000UA.job
- c:\users\marytsc\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-14 09:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{B80F591E-FE9A-46CF-A13E-180377240586} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{22E03916-85C5-44B0-8DC9-1830C11238D9} - (no file)
WebBrowser-{A608C70C-2888-4073-BAEE-968F3FA69E5C} - (no file)
WebBrowser-{82BD588C-ACD8-417D-A32E-EF441492B9F6} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{2C1E21B5-5666-4CD5-8152-96B690B7216E} - (no file)
WebBrowser-{F897EB0E-A3A4-46C3-80EB-2729699D8892} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-!SASWinLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-01 14:00
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"=hex:51,66,7a,6c,4c,1d,38,12,50,ef,00,
7f,a8,d7,1e,0e,c6,dd,65,57,bd,6c,7c,36
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,
02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
"{E61C78EB-4EAA-440A-8B84-ABA0359B4AB4}"=hex:51,66,7a,6c,4c,1d,38,12,85,7b,0f,
e2,98,00,64,01,f4,92,e8,e0,30,c5,0e,a0
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:2f,d7,32,21,3f,26,cd,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2012-05-01 14:02:49
ComboFix-quarantined-files.txt 2012-05-01 18:02
.
Pre-Run: 100,595,277,824 bytes free
Post-Run: 100,622,213,120 bytes free
.
- - End Of File - - CA22D5EC3F38D4D49D5AAB5243C2D410
Hi,

Please run the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi CatByte, I installed and did the MBAM scan, no problem. But the Eset scanner didn't want to load. I disabled the AVG, and also had to disable Defender. Unfortunately, AVG will only allow you to disable for 15 minutes, maximum, before it re-enables itself. I don't know if that was what the problem was, but since I thought it might be, I uninstalled AVG with the intention of re-installing it after Eset was done and I had posted both reports to you. No matter what I did, Eset took so long to load, and then when it said it was 100%, it would give me an error message (no explanation of the error). So, I gave up on Eset and have been trying, all day, to reload AVG - but it's been at 46% for hours now. Any suggestions? By the way, I want to make sure and let you know how much I appreciate all your help with this laptop (and other previous computers) - I don't know what I'd do without you guys and your expertise!
use the AVG removal tool to remove all traces of AVG from your computer that may be blocking the re-install,
http://www.avg.com/filedir/util/avg_arm_su…/avgremover.exe



give Microsoft Security Essentials a try, it's excellent and free

http://www.microsoft.com/security_essentials/


run a full scan with MSSE and let me know if it finds anything.

(ESET sometimes refuses to run on some machines without really knowing why)


NEXT


Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.



How is the computer running now? Are there any outstanding issues?
Thanks so much, CatByte, Well, ironically, it seems like when I open a browser, now, it seems to be much slower than it was - even with Chrome. But maybe after getting her laptop completely straightened out, that will iron itself out. Fingers crossed! I'll go follow your most recent instructions and post back to you soon : )
I also meant to let you know that the "can't run or load" error message on start-up seems to be gone now :D Thank you VERY much!
Hey CatByte - Sorry it's taken awhile to get back with you. I was finally able to get AVG to download, although it took until this morning. Now I've been trying to get it to update most of the day - still waiting. I tried for quite some time to download MSSE, as you suggested, but it was taking so long and kept timing out, that I got frustrated and went back to trying to download AVG. This computer has become outrageously slow when trying to download everything; and I'm wondering if I inadvertently changed some settings somewhere along the way. Do you guys ever look at computers using the remote feature? Understandable if you don't. Just to make sure you know, and I hope it wasn't something I shouldn't have done, but I did a system restore back to 4/30; but the error message showed up again, so, I reversed the restore back to today. I just did a new MBAM scan, and wanted to give you the report. It says there were no malicious items detected : ) Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.04.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 marytsc :: MARYTSC-PC [administrator] 5/4/2012 2:49:13 PM mbam-log-2012-05-04 (14-49-13).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207715 Time elapsed: 3 minute(s), 2 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
please run the following:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs


NEXT

First open an elevated Command Prompt
  • Go to Start > All Programs > Accessories
  • right click on the Command Prompt and choose “Run as administrator”
  • Type the following see how much your hard drive is fragmented (in this example, your C:\ drive):
  • defrag c: -a (be patient, this can take a while)
  • The resulting analysis will tell you a “Percent file fragmentation” and at the bottom, if you need to defragment the drive or not.
  • To fully defragment your C:\ drive type the following:
  • defrag c: -w
  • Give it time to run (it can take a while, best to leave the computer alone) and then you’re done!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI