Hi Nettie724
Please let me know if you are still having problems with the AVG LinkScanner and how is your computer running now?
Hi, Robybell!
I am still having the same problem with my laptop as when I started this topic. The AVG message is still popping up. I noticed when I went out of town on a business trip this week my yahoo homepage showed weather from the city that I was staying in. But as soon as I came back home it was showing Colorado again. I do not live now there near Colorado. Everytime I try to change the location to my city, the Colorado page appears again. My Facebook page is still saying I am signing in from an unknown location as well even after I changed all my passwords again.
Hi Nettie724
Please follow all previous instructions regarding security programs.
Open a new Notepad session
Click the Start button, click run in the run box type notepad click ok In the notepad, Click "Format" and be certain that Word Wrap is not checked .
Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Folder::
c:\users\Owner\AppData\Roaming\AVG2012
c:\program files\AVG\
Firefox::
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bohdrddy.default\
FF - ExtSQL: 2012-09-10 11:12; {1E73965B-8B48-48be-9C8D-68B920ABC1C4}; c:\program files (x86)\AVG\AVG2012\Firefox4
In the notepad
Click File , Save as …, and set the Save in to your Desktop In the filename box, type (including quotation marks) as the filename: "CFScript.txt" Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.
This will start ComboFix again.
Close all browser/windows first.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
[external image: Posted Image]
Next
Post a new OTL log
Hi, Robybel!
Here is the new OTL log.
ComboFix 12-11-04.01 - Owner 11/04/2012 13:32:06.4.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2807.1705 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
FW: Online Armor Firewall *Disabled* {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Owner\AppData\Roaming\AVG2012
c:\users\Owner\AppData\Roaming\AVG2012\cfgall\userawacs.cfg
.
.
((((((((((((((((((((((((( Files Created from 2012-10-04 to 2012-11-04 )))))))))))))))))))))))))))))))
.
.
2012-11-04 19:42 . 2012-11-04 19:42 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-11-04 19:42 . 2012-11-04 19:42 ——– d—–w- c:\users\Guest\AppData\Local\temp
2012-11-04 19:42 . 2012-11-04 19:42 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-11-04 16:18 . 2012-11-04 16:18 69000 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FFEB4E27-6395-4479-9A35-1F94481405B1}\offreg.dll
2012-11-04 16:15 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FFEB4E27-6395-4479-9A35-1F94481405B1}\mpengine.dll
2012-11-03 22:29 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-21 13:49 . 2012-10-21 13:49 ——– d—–w- C:\_OTL
2012-10-20 02:27 . 2012-09-29 08:56 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB9996B4-A9B4-4EA1-89A1-31126A91E5DD}\gapaengine.dll
2012-10-18 04:05 . 2012-10-18 04:05 ——– d—–w- c:\program files (x86)\SpywareBlaster
2012-10-18 03:59 . 2012-10-18 03:59 ——– d—–w- c:\users\Owner\AppData\Roaming\Firetrust
2012-10-18 03:58 . 2012-10-18 03:58 ——– d—–w- c:\program files (x86)\Firetrust
2012-10-18 03:57 . 2012-10-18 03:59 ——– d—–w- c:\programdata\Firetrust
2012-10-17 20:28 . 2012-10-17 22:51 ——– d—–w- c:\programdata\OnlineArmor
2012-10-17 20:28 . 2012-10-17 20:28 ——– d—–w- c:\users\Owner\AppData\Roaming\OnlineArmor
2012-10-17 20:26 . 2012-10-24 16:43 35376 —-a-w- c:\windows\system32\drivers\OAnet.sys
2012-10-17 20:26 . 2012-10-24 16:43 40520 —-a-w- c:\windows\SysWow64\drivers\OAmon.sys
2012-10-17 20:26 . 2012-10-24 16:43 61632 —-a-w- c:\windows\SysWow64\drivers\OADriver.sys
2012-10-17 20:26 . 2012-10-18 20:47 62016 —-a-w- c:\windows\SysWow64\drivers\oahlp64.sys
2012-10-17 20:26 . 2012-10-24 18:14 ——– d—–w- c:\program files (x86)\Online Armor
2012-10-16 02:49 . 2012-10-16 02:49 289768 —-a-w- c:\windows\system32\javaws.exe
2012-10-16 02:49 . 2012-10-16 02:49 1034216 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-10-16 02:49 . 2012-10-16 02:49 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-16 02:49 . 2012-10-16 02:49 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-10-16 02:49 . 2012-10-16 02:49 189416 —-a-w- c:\windows\system32\javaw.exe
2012-10-16 02:49 . 2012-10-16 02:49 188904 —-a-w- c:\windows\system32\java.exe
2012-10-16 02:49 . 2012-10-16 02:49 ——– d—–w- c:\program files\Java
2012-10-13 23:52 . 2012-10-13 23:52 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes
2012-10-13 23:52 . 2012-10-13 23:52 ——– d—–w- c:\programdata\Malwarebytes
2012-10-13 23:52 . 2012-10-13 23:52 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-13 23:52 . 2012-09-07 22:04 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-10-10 21:13 . 2012-08-20 18:38 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-10-10 21:13 . 2012-08-20 17:32 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2012-10-10 21:13 . 2012-08-20 17:32 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2012-10-10 21:13 . 2012-08-20 18:38 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-10-10 21:13 . 2012-08-20 18:38 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-10-10 21:13 . 2012-08-20 15:38 2048 —-a-w- c:\windows\SysWow64\user.exe
2012-10-10 21:13 . 2012-08-24 18:05 220160 —-a-w- c:\windows\system32\wintrust.dll
2012-10-10 21:13 . 2012-08-24 16:57 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
2012-10-10 21:13 . 2012-09-14 19:19 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-10 21:13 . 2012-09-14 18:28 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-10-10 21:13 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll
2012-10-10 21:13 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll
2012-10-10 21:12 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll
2012-10-10 21:12 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 21:12 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll
2012-10-10 21:12 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-10 21:12 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-10 21:12 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-18 14:03 . 2012-04-21 04:32 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-18 14:03 . 2011-08-02 20:49 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-11 14:55 . 2011-07-28 17:44 65309168 —-a-w- c:\windows\system32\MRT.exe
2012-09-30 23:34 . 2011-07-28 17:35 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll
2012-09-30 23:34 . 2011-07-28 17:35 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll
2012-09-29 08:56 . 2011-08-12 00:50 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-08-31 03:03 . 2012-08-31 03:03 228768 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-31 03:03 . 2010-10-25 02:25 128456 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-24 11:15 . 2012-09-26 15:34 17810944 —-a-w- c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-26 15:34 10925568 —-a-w- c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-26 15:34 2312704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-26 15:34 1346048 —-a-w- c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-26 15:34 1392128 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-26 15:34 1494528 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-26 15:34 237056 —-a-w- c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-26 15:34 85504 —-a-w- c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-26 15:34 173056 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-26 15:34 816640 —-a-w- c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-26 15:34 599040 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-26 15:34 2144768 —-a-w- c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-26 15:34 729088 —-a-w- c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-26 15:34 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-26 15:34 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-26 15:34 248320 —-a-w- c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-26 15:34 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-26 15:34 1129472 —-a-w- c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-26 15:34 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-26 15:34 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-26 15:34 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-26 15:34 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 13:39 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 13:39 950128 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 13:39 376688 —-a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 13:39 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-26 15:43 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-08-20 17:38 . 2012-10-10 21:14 44032 —-a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-06-16 6276408]
"Facebook Update"="c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2012-05-29 25249400]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-09-30 39408]
"InstallIQUpdater"="c:\program files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2010-05-25 258304]
"VideoWebCamera"="c:\program files (x86)\VideoWebCamera\VideoWebCamera.exe" [2010-05-26 1545568]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-06-22 968272]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"FUFAXSTM"="c:\program files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872]
"LTCM Client"="c:\program files (x86)\LTCM Client\ltcmClient.exe" [2009-08-05 1596096]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-09-30 296096]
.
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ZooskMessenger.lnk - c:\program files (x86)\ZooskMessenger\ZooskMessenger.exe [N/A]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 oahlpXX;Online Armor helper driver;c:\windows\syswow64\drivers\oahlp64.sys [2012-10-18 62016]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SvcOnlineArmor;Online Armor;c:\program files (x86)\Online Armor\oasrv.exe [2012-10-24 4463864]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-05-24 246304]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-07-28 1255736]
S1 OADevice;OADriver;c:\windows\SysWow64\Drivers\OADriver.sys [2012-10-24 61632]
S1 OAmon;OAmon;c:\windows\SysWOW64\Drivers\OAmon.sys [2012-10-24 40520]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-15 759048]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-08-19 2399560]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-06-22 321104]
S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2010-06-11 868896]
S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [2010-01-08 23584]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2010-05-25 255744]
S2 OAcat;Online Armor Helper Service;c:\program files (x86)\Online Armor\OAcat.exe [2012-10-24 216072]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2010-01-28 243232]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-13 135560]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-03 271872]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-05-15 384040]
S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2012-10-24 35376]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 14:03]
.
2012-11-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3957855987-223762927-1437166113-1000Core.job
- c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-01 23:07]
.
2012-11-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3957855987-223762927-1437166113-1000UA.job
- c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-01 23:07]
.
2012-11-04 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2012-01-23 21:24]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-02 06:44]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-02 06:44]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957855987-223762927-1437166113-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-17 16:54]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957855987-223762927-1437166113-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-17 16:54]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-10 206208]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2010-06-11 861216]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304]
"lxcrmon.exe"="c:\program files (x86)\Lexmark 2400 Series\lxcrmon.exe" [2009-05-01 291496]
"EzPrint"="c:\program files (x86)\Lexmark 2400 Series\ezprint.exe" [2009-05-01 82600]
"LXCRCATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXCRtime.dll" [2006-11-21 31744]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704]
"@OnlineArmor GUI"="c:\program files (x86)\Online Armor\oaui.exe" [2012-10-24 2415104]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=nv55c&r=27360711m475l0404z1k5a47l2j274
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=nv55c&r=27360711m475l0404z1k5a47l2j274
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bohdrddy.default\
FF - ExtSQL: 2012-09-10 11:12; {1E73965B-8B48-48be-9C8D-68B920ABC1C4}; c:\program files (x86)\AVG\AVG2012\Firefox4
FF - ExtSQL: 2012-09-30 18:35; {0153E448-190B-4987-BDE1-F256CADA672F}; c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Vid-Saver - c:\program files (x86)\Vid-Saver\Uninstall.exe
AddRemove-{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406} - c:\programdata\{B49A644A-1076-4A3D-B124-DAA7862F2318}\iLividSetupV1.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-04 14:01:27
ComboFix-quarantined-files.txt 2012-11-04 20:01
ComboFix2.txt 2012-11-02 15:34
.
Pre-Run: 243,044,343,808 bytes free
Post-Run: 242,969,550,848 bytes free
.
- - End Of File - - EEB67A65E2C335F0168C8A657C5ACE38
Hi, Robybel!
When I went to drop that notepad code into CF, I was prompted to check Window Defender. It was turned off. I haven't been able to turn it back on from any of the 4 attempts made within four hours or so. I am still noticing my yahoo page redirecting to the Denver, CO page. Also, I'm still receiving the AVG reboot message.
Hi Nettie724
Please follow these steps:
Show hidden files and folders :
Click on
Start
Click on
Control Panel
Click on
Folder Options
Click on
View Tab
Check :
Show hidden files,folders, or drives, press OK
======================================================
***NOTE: Be sure to re-hide hidden files and folders when mission is accomplished!
Next
Reboot Your System in Safe Mode
Restart the computer. As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears. Use the arrow keys to select the Safe mode menu item Press Enter.
Using
Windows Explorer (Windows Key + E), locate the following folder, and
DELETE it
c:\program files(x86)\
AVG
Exit Explorer , and
REBOOT BACK INTO NORMAL MODE
Empty Recycle bin
Please let me know if you are still having problems with the AVG
Hi, Robybel!
Thank you so much. That step seemed to have fixed the AVG problem. But I noticed upon signing onto my laptop, my icons were made smaller and they seem to be partitioned off as if the screen is divided as if a row was missing vertically and horizontally. In just looking at it again. I noticed my Yahoo Messenger was definitely moved to the opposite side of my desktop. Upon signing into Yahoo, I noticed it is still showing Denver, CO as my hometown and I still can't change it back to my actual city and state. I am getting an "Unable to update/save/retrieve my location. Please try again," message. Also, I also notice a cursor on the pages when I sign onto them, whether it be the WTT forum, Yahoo, or Facebook, etc. I'm pretty sure that isn't suppose to happen.
Hi Nettie724
Please download Windows Repair (all in one) from
here
Install the program then run it
Go to step 2 and allow it to run
Disk check
[external image: Posted Image]
Once that is done then go to step 3 and allow it to run
SFC
[external image: Posted Image]
On the the
Start Repairs tab => Click the
Start
[external image: Posted Image]
Click on the
select all check box and then click on
Start
DON'T use the computer while each scan is in progress.
Restart may be needed to finish the repair procedure
Next
Please download ServicesRepair and save it to your desktop.
Double-click ServicesRepair.exe . If security notifications appear, click Continue or Run and then click Yes when asked if you want to proceed. Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart. A log will be saved in the CCSupport folder the tool created on your desktop, please post the content in your next reply.
Please let me know, how is your computer running now?
On your next reply please post :
Let me know if you have any problems in performing with the steps above or any questions you may have.
Good Day!
Hi, Robybel!
Here is the Service Repair log.
Log Opened: 2012-11-06 @ 17:58:14
17:58:14 - —————–
17:58:14 - | Begin Logging |
17:58:14 - —————–
17:58:14 - Fix started on a WIN_7 X64 computer
17:58:14 - Prep in progress. Please Wait.
17:58:36 - Prep complete
17:58:36 - Repairing Services Now. Please wait…
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BFE.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BITS.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\iphlpsvc.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\MpsSvc.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\SharedAccess.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\WinDefend.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wscsvc.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wuauserv.sddl'
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
INFORMATION: Restoring SD of:
SetACL finished successfully.
17:58:58 - Services Repair Complete.
17:59:03 - Reboot Initiated
I'm still getting the Colorado page when I sign onto Yahoo. Yahoo is not showing my signature that I told it to use from last week. When I try to sign onto a webpage, I notice the little circle turning to the left, then it pauses and then redirects itself to the right. Not sure if that means anything. Still getting the message "Facebook login from unrecognized device." My pages is still freezing up.
Will wait for your next set of instructions. Hope you have a good night.
Hi Nettie724
I notice the little circle turning to the left, then it pauses and then redirects itself to the right
No problem, this is normal
I see from your logs that your yahoo problem does not depend on malware, therefore, I ask you to open a new thread in
this forum , so that an expert try to solve your, yahoo problem
meanwhile
Please follow this step
Clean up with
OTL:
Double-click OTL.exe to start the program. Close all other programs apart from OTL as this step will require a reboot On the OTL main screen, press the CLEANUP button Say Yes to the prompt and then allow the program to reboot your computer.
Unistall AdwCleaner
Double click on adwcleaner.exe to run the tool. Click on Uninstall. Confirm with yes.
Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
Hi, Robybel!
Thanks for all of your help. I will definitely start a new thread. And have deleted some of the logs and other things that was cluttering up my desktop.
Wishing you cont'd success in your training in becoming a WTT leader.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.