This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC non responsive, slow, self rebooting.....

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'll be happy to take a look at the laptop. We can do that right in this thread. There is no need to open a new one. I would like to use a different tool than OTL to get a scan though.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt
hi it just comes up as blank page when i click on the link well a turn of events has occured. i can access the internet via my pc through Internet Explorer with no problems what so ever, infact i have been able to download DDS and transfer it to the laptop via usb stick. i am wondering if the problem with my pc is infact google chrome!! i shall post the logs from the scan on the laptop.
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume1 Install Date: 30/01/2012 10:00:36 System Uptime: 19/07/2012 16:09:41 (8 hours ago) . Motherboard: TOSHIBA | | NBWAE Processor: AMD Sempron™ SI-42 | Socket M2/S1G1 | 1050/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 193.93 GiB free. D: is Removable E: is CDROM (CDFS) F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP39: 03/06/2012 19:21:17 - Removed Facebook Messenger 2.1.4520.0 RP40: 04/06/2012 13:14:55 - Windows Update RP41: 07/06/2012 19:10:01 - Windows Update RP42: 14/06/2012 00:29:18 - Windows Update RP43: 14/06/2012 22:24:07 - Windows Update RP44: 19/06/2012 16:10:22 - Windows Update RP45: 19/06/2012 16:16:34 - Windows Update RP46: 26/06/2012 22:31:55 - Windows Update RP47: 01/07/2012 16:12:33 - Windows Update RP48: 06/07/2012 22:18:49 - Windows Update RP49: 12/07/2012 17:08:22 - Windows Update RP50: 12/07/2012 23:47:31 - Windows Update RP51: 18/07/2012 20:37:06 - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Adobe AIR Adobe Reader X (10.1.3) Apple Application Support Apple Mobile Device Support Apple Software Update avast! Free Antivirus Bonjour Facebook Video Calling 1.2.0.159 Google Chrome iTunes MagicDisc 2.7.106 Malwarebytes' Anti-Malware McAfee Security Scan Plus Microsoft .NET Framework 4 Client Profile Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Picasa 3 Realtek 8136 8168 8169 Ethernet Driver Realtek WLAN Driver Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition TOSHIBA Web Camera Application Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Yontoo 1.10.02 . ==== Event Viewer Messages From Past Week ======== . 20/07/2012 00:02:49, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR5. 19/07/2012 23:53:28, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR4. 19/07/2012 23:28:57, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Lisa-PC\Lisa SID (S-1-5-21-3561299463-2961446174-593319071-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 19/07/2012 18:56:21, Error: atikmdag [43029] - Display is not active 19/07/2012 13:58:11, Error: Service Control Manager [7023] - The Offline Files service terminated with the following error: The system cannot find the path specified. 19/07/2012 13:58:08, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter . ==== End Of File =========================== . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 0:03:49 on 2012-07-20 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.56 [GMT 1:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Media Finder\Media Finder.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\rundll32.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo\YontooIEClient.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [Google Update] "c:\users\lisa\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Facebook Update] "c:\users\lisa\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [Media Finder] "c:\program files\media finder\Media Finder.exe" /opentotray mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download with &Media Finder - c:\program files\media finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{3A38CA1A-8A0F-4B64-A7D2-74F5E09F122E} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\35B4957383935383 : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\4514C4B44514C4B4D2436464449364 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\C6963756E6564777F627B6 : DhcpNameServer = 192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-30 721000] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-30 353688] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-30 21256] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-1-30 57656] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-7-10 44808] R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2012-2-4 24064] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2012-1-30 167936] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2012-1-30 859136] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-4-10 1343400] . =============== Created Last 30 ================ . 2012-07-18 19:39:21 6891424 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{d33eab24-1800-4f66-a649-be35f3ecec4e}\mpengine.dll 2012-07-12 22:50:16 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-12 22:50:06 293376 —-a-w- c:\windows\system32\browserchoice.exe 2012-07-12 16:20:32 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-12 16:20:32 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-07-12 16:20:31 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-07-12 16:20:30 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-07-12 16:20:30 225280 —-a-w- c:\windows\system32\schannel.dll 2012-07-12 16:20:16 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-07-12 16:20:14 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-07-12 16:20:13 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-12 16:20:03 1019904 —-a-w- c:\program files\common files\system\ado\msado15.dll 2012-07-12 16:20:00 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-07-12 16:19:58 352256 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2012-07-12 16:19:56 57344 —-a-w- c:\program files\common files\system\ado\msador15.dll 2012-07-12 16:19:54 212992 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2012-07-12 16:19:53 372736 —-a-w- c:\program files\common files\system\ado\msadox.dll 2012-07-12 16:19:53 143360 —-a-w- c:\program files\common files\system\ado\msjro.dll . ==================== Find3M ==================== . 2012-07-03 16:21:53 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21:53 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21:53 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21:32 41224 —-a-w- c:\windows\avastSS.scr 2012-06-02 22:12:32 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12:13 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 14:19:42 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 14:12:20 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 08:33:25 1800192 —-a-w- c:\windows\system32\jscript9.dll 2012-06-02 08:25:08 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-06-02 08:25:03 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-02 08:20:33 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-02 08:16:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-05-31 11:25:14 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-05-01 04:44:12 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17:07 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45:55 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45:54 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41:16 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 04:36:42 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 04:36:42 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36:42 103936 —-a-w- c:\windows\system32\cryptnet.dll . ============= FINISH: 0:05:18.21 ===============
Fantastic! I know what files we need to target at this point. Let's go ahead and run Combofix and see which ones it removes for us and then we will remove what we need to. Media Finder is not good to have on your machine so we are giong to want to remove it. But let's see if Combofix removes it for us, if not we will do it with a script. We will do the Babylon with a script as well on the 2nd pass of Combofix as well :)
Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi, it didnt give me the chance to save to my desktop it just started to run without me accepting,so im not sure where its saved to. The laptop is running ok but just have this yontoo,media finder and babylon which i would very much like removing. ComboFix 12-07-21.01 - Lisa 23/07/2012 0:27.1.1 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.248 [GMT 1:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\DEBUG.log . . ((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 ))))))))))))))))))))))))))))))) . . 2012-07-22 23:36 . 2012-07-22 23:36 ——– d—–w- c:\users\Lisa\AppData\Local\temp 2012-07-22 23:36 . 2012-07-22 23:36 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-20 10:47 . 2012-06-29 08:44 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\mpengine.dll 2012-07-12 22:50 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-12 22:50 . 2010-02-11 07:10 293376 —-a-w- c:\windows\system32\browserchoice.exe 2012-07-12 16:20 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-07-12 16:20 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-12 16:20 . 2012-06-02 04:39 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-07-12 16:20 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-07-12 16:20 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll 2012-07-12 16:20 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-07-12 16:20 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-07-12 16:20 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-12 16:20 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-12 16:20 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-07-12 16:19 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-12 16:19 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-12 16:19 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-12 16:19 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll 2012-07-12 16:19 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-03 16:21 . 2012-01-30 12:48 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-07-03 16:21 . 2012-05-06 20:39 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21 . 2012-01-30 12:48 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-07-03 16:21 . 2012-01-30 12:48 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-07-03 16:21 . 2012-01-30 12:48 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21 . 2012-01-30 12:48 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21 . 2012-01-30 12:47 41224 —-a-w- c:\windows\avastSS.scr 2012-07-03 16:21 . 2012-01-30 12:47 227648 —-a-w- c:\windows\system32\aswBoot.exe 2012-06-02 22:19 . 2012-06-19 15:11 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-19 15:11 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-19 15:11 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-19 15:11 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2012-06-19 15:11 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:12 . 2012-06-19 15:11 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12 . 2012-06-19 15:11 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 14:19 . 2012-06-19 15:10 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 14:12 . 2012-06-19 15:10 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-05-31 11:25 . 2012-02-12 16:07 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-05-27 21:51 . 2012-05-27 21:51 161792 —-a-w- c:\windows\system32\msls31.dll 2012-05-27 21:51 . 2012-05-27 21:51 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-05-27 21:51 . 2012-05-27 21:51 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-05-27 21:51 . 2012-05-27 21:51 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-05-27 21:51 . 2012-05-27 21:51 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-05-27 21:51 . 2012-05-27 21:51 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-05-27 21:51 . 2012-05-27 21:51 367104 —-a-w- c:\windows\system32\html.iec 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-05-27 21:51 . 2012-05-27 21:51 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-27 21:51 . 2012-05-27 21:51 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-05-27 21:51 . 2012-05-27 21:51 152064 —-a-w- c:\windows\system32\wextract.exe 2012-05-27 21:51 . 2012-05-27 21:51 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-05-27 21:51 . 2012-05-27 21:51 11776 —-a-w- c:\windows\system32\mshta.exe 2012-05-27 21:51 . 2012-05-27 21:51 101888 —-a-w- c:\windows\system32\admparse.dll 2012-05-27 21:51 . 2012-05-27 21:51 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-05-01 04:44 . 2012-06-13 23:41 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17 . 2012-06-13 23:42 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45 . 2012-06-13 23:41 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45 . 2012-06-13 23:41 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41 . 2012-06-13 23:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 04:36 . 2012-06-13 23:40 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 04:36 . 2012-06-13 23:40 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-13 23:40 103936 —-a-w- c:\windows\system32\cryptnet.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096] "Media Finder"="c:\program files\Media Finder\Media Finder.exe" [2012-05-23 8630272] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download with &Media Finder - c:\program files\Media Finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-23 00:40:39 ComboFix-quarantined-files.txt 2012-07-22 23:40 . Pre-Run: 211,279,200,256 bytes free Post-Run: 212,743,454,720 bytes free
If Combofix didn't save to your desktop, please go ahead and download it again and make sure it saves to your desktop (but don't run it again). That is going to be very important in order for you to complete the next steps.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Program Files\Media Finder\Media Finder.exe

Folder::
C:\Program Files\Media Finder

DDS::
uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d
uRun: [Media Finder] "c:\program files\media finder\Media Finder.exe" /opentotray
IE: Download with &Media Finder - c:\program files\media finder\hook.html


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
hi it still gives me no option to save it anywhere, it automatically goes to downloads, ive tried to move it from there to the desktop but it only creates a shortcut. i thought it best to check with you first to see if i can change any settings to avoid it going straight to downloads :)
What browser are you using? That will help me to help you with the problem :) Also, do you still have a copy on your USB? You could cut and paste the copy from the USB to your desktop. That would work as well.
If you are using Chrome, the default download automatically goes to your downloads folder. You can click on the arrow next to the download in the browser screen and have it open the location when done with the download (vs. clicking the actual download to run it) and CUT and paste to your desktop. Alternatively, you can click on the little wrench in the top right corner of your screen and then choose downloads. Towards the upper portion of the screen should be a link to open your downloads folder. Once you do that you can find the Combofix download and CUT and paste it to your desktop. Let me know if you are still having trouble getting it on your desktop.
ComboFix 12-07-21.01 - Lisa 23/07/2012 13:09:34.2.1 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.323 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Lisa\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files\Media Finder\Media Finder.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Media Finder c:\program files\Media Finder\borlndmm.dat c:\program files\Media Finder\borlndmm.dll c:\program files\media finder\Media Finder.exe c:\program files\Media Finder\Plugins\_4shared.dll c:\program files\Media Finder\Plugins\depositfiles.dll c:\program files\Media Finder\Plugins\extabit.dll c:\program files\Media Finder\Plugins\filepost.dll c:\program files\Media Finder\Plugins\furk.dll c:\program files\Media Finder\Plugins\hotfile.dll c:\program files\Media Finder\Plugins\letitbit.dll c:\program files\Media Finder\Plugins\madshare.dll c:\program files\Media Finder\Plugins\oron.dll c:\program files\Media Finder\Plugins\rapidshare.dll c:\program files\Media Finder\Plugins\turbobit.dll c:\program files\Media Finder\Plugins\unibytes.dll c:\program files\Media Finder\Plugins\uploading.dll c:\program files\Media Finder\Plugins\uploadstation.dll . . ((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 ))))))))))))))))))))))))))))))) . . 2012-07-23 12:17 . 2012-07-23 12:17 ——– d—–w- c:\users\Lisa\AppData\Local\temp 2012-07-23 12:17 . 2012-07-23 12:17 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-23 02:13 . 2012-07-23 02:13 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\offreg.dll 2012-07-20 10:47 . 2012-06-29 08:44 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\mpengine.dll 2012-07-12 22:50 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-12 22:50 . 2010-02-11 07:10 293376 —-a-w- c:\windows\system32\browserchoice.exe 2012-07-12 16:20 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-07-12 16:20 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-12 16:20 . 2012-06-02 04:39 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-07-12 16:20 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-07-12 16:20 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll 2012-07-12 16:20 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-07-12 16:20 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-07-12 16:20 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-12 16:20 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-12 16:20 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-07-12 16:19 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-12 16:19 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-12 16:19 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-12 16:19 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll 2012-07-12 16:19 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-03 16:21 . 2012-01-30 12:48 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-07-03 16:21 . 2012-05-06 20:39 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21 . 2012-01-30 12:48 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-07-03 16:21 . 2012-01-30 12:48 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-07-03 16:21 . 2012-01-30 12:48 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21 . 2012-01-30 12:48 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21 . 2012-01-30 12:47 41224 —-a-w- c:\windows\avastSS.scr 2012-07-03 16:21 . 2012-01-30 12:47 227648 —-a-w- c:\windows\system32\aswBoot.exe 2012-06-02 22:19 . 2012-06-19 15:11 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-19 15:11 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-19 15:11 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-19 15:11 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2012-06-19 15:11 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:12 . 2012-06-19 15:11 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12 . 2012-06-19 15:11 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 14:19 . 2012-06-19 15:10 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 14:12 . 2012-06-19 15:10 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-05-31 11:25 . 2012-02-12 16:07 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-05-27 21:51 . 2012-05-27 21:51 161792 —-a-w- c:\windows\system32\msls31.dll 2012-05-27 21:51 . 2012-05-27 21:51 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-05-27 21:51 . 2012-05-27 21:51 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-05-27 21:51 . 2012-05-27 21:51 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-05-27 21:51 . 2012-05-27 21:51 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-05-27 21:51 . 2012-05-27 21:51 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-05-27 21:51 . 2012-05-27 21:51 367104 —-a-w- c:\windows\system32\html.iec 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-05-27 21:51 . 2012-05-27 21:51 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-27 21:51 . 2012-05-27 21:51 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-05-27 21:51 . 2012-05-27 21:51 152064 —-a-w- c:\windows\system32\wextract.exe 2012-05-27 21:51 . 2012-05-27 21:51 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-05-27 21:51 . 2012-05-27 21:51 11776 —-a-w- c:\windows\system32\mshta.exe 2012-05-27 21:51 . 2012-05-27 21:51 101888 —-a-w- c:\windows\system32\admparse.dll 2012-05-27 21:51 . 2012-05-27 21:51 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-05-01 04:44 . 2012-06-13 23:41 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17 . 2012-06-13 23:42 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45 . 2012-06-13 23:41 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45 . 2012-06-13 23:41 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41 . 2012-06-13 23:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-07-22_23.36.37 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:55 . 2012-07-23 01:14 43956 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2012-01-30 00:54 . 2012-07-23 11:30 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-01-30 00:54 . 2012-07-22 23:31 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-01-30 00:54 . 2012-07-22 23:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-01-30 00:54 . 2012-07-23 11:30 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:41 . 2012-07-23 11:30 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:41 . 2012-07-22 23:31 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-07-21 22:05 . 2012-07-21 22:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-23 01:13 . 2012-07-23 01:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-07-21 22:05 . 2012-07-21 22:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-07-23 01:13 . 2012-07-23 01:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 02:05 . 2012-07-23 09:53 628460 c:\windows\System32\perfh009.dat - 2009-07-14 02:05 . 2012-07-22 22:20 628460 c:\windows\System32\perfh009.dat - 2009-07-14 02:05 . 2012-07-22 22:20 110612 c:\windows\System32\perfc009.dat + 2009-07-14 02:05 . 2012-07-23 09:53 110612 c:\windows\System32\perfc009.dat - 2009-07-14 04:47 . 2012-07-20 22:46 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 04:47 . 2012-07-23 00:01 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . 2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-23 13:21:37 ComboFix-quarantined-files.txt 2012-07-23 12:21 ComboFix2.txt 2012-07-22 23:40 . Pre-Run: 211,860,103,168 bytes free Post-Run: 211,563,491,328 bytes free . - - End Of File - - A3320245DEA7FB99B06C67A09D406E58

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI