This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

pc infected with pup blubber and risktool.killfiles [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi all,
back with my mums pc as stated malware bytes eset and spybot detected threats but as they are in registry and malwarebytes would not remove the pup blabber i thought it best to ask for professional advice. i have downloaded dds:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 19:18:27.06 on 10/10/2012
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.339 [GMT 1:00]
.
AV: AVG Internet Security 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2013 *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\TalkTalk\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mapp\mbamservice.exe
C:\Program Files\Mapp\mbamscheduler.exe
C:\Program Files\Aqua Dock\Aqua Dock.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\F6D4050\v1\Belkinwcui.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TalkTalk\agent\bin\bcont_nm.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\lisa\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.talktalk.co.uk/
uInternet Settings,ProxyOverride = ;*.local
mURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aol talktalk toolbar 5.0\aoltb.dll
mURLSearchHooks: H - No File
BHO: {00cbb66b-1d3b-46d3-9577-323a336acb50} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {193d7001-bd9f-48c2-b5c7-69775aa2201d} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol talktalk toolbar 5.0\aoltb.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll
BHO: {963B125B-8B21-49A2-A3A8-E37092276531} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: AOL TalkTalk Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol talktalk toolbar 5.0\aoltb.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Openwares LiveUpdate] c:\program files\liveupdate\LiveUpdate.exe
mRun: [Aqua Dock] c:\program files\aqua dock\Aqua Dock.exe
mRun: [EPSON Stylus D68 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB002" /M "Stylus D68"
mRun: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe
mRun: [TalkTalk] "c:\program files\talktalk\bin\sprtcmd.exe" /P TalkTalk
mRun: [Epson 68] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAAE.EXE /P8 "Epson 68" /O6 "USB001" /M "Stylus D68"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [ROC_ROC_NT] "c:\program files\avg secure search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin wireless networking utility.lnk - c:\program files\belkin\f6d4050\v1\Belkinwcui.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee security scan.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
IE: &AOL Toolbar Search - c:\program files\aol\aol talktalk toolbar 5.0\resources\en-gb\local\search.html
IE: {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\12.2.6\ViProtocol.dll
Notify: igfxcui - igfxsrvc.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-9-17 51936]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-8-9 178656]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-8-10 35168]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-8-13 176096]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-8-10 19808]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-9-12 151648]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-9-14 89440]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-12 164704]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-10-5 27496]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-8-20 184304]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-4-6 54760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\mapp\mbamscheduler.exe [2012-10-10 399432]
R2 MBAMService;MBAMService;c:\program files\mapp\mbamservice.exe [2012-4-1 676936]
R2 sprtsvc_TalkTalk;SupportSoft Sprocket Service (TalkTalk);c:\program files\talktalk\bin\sprtsvc.exe [2007-10-12 202016]
R2 tgsrvc_TalkTalk;SupportSoft Repair Service (TalkTalk);c:\program files\common files\supportsoft\bin\tgsrvc.exe [2007-8-2 148768]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files\common files\avg secure search\vtoolbarupdater\12.2.6\ToolbarUpdater.exe [2012-10-5 722528]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-3-31 22856]
S1 MpKsld0342547;MpKsld0342547;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{710f7aaf-faf2-4b83-8030-343e23c65aeb}\mpksld0342547.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{710f7aaf-faf2-4b83-8030-343e23c65aeb}\MpKsld0342547.sys [?]
S2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2012-8-20 1286392]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-8-20 5751928]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-13 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-13 250808]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [2006-10-10 131072]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\drivers\CnxEtU.sys [2006-10-10 614272]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver;c:\windows\system32\drivers\CnxTgNW.sys [2006-10-10 53248]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-7-13 136176]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2011-7-27 637952]
.
=============== Created Last 30 ================
.
2012-10-10 17:49:02 54016 —-a-w- c:\windows\system32\drivers\svrdcep.sys
2012-10-07 20:19:25 ——– d—–w- c:\docume~1\lisa\applic~1\PriceGong
2012-10-05 20:54:24 ——– d—–w- c:\program files\AVG Secure Search
2012-10-05 20:41:41 ——– d—–w- c:\docume~1\lisa\applic~1\AVG2013
2012-10-05 20:34:55 ——– d—–w- c:\docume~1\lisa\locals~1\applic~1\AVG Secure Search
2012-10-05 20:34:55 ——– d—–w- c:\docume~1\lisa\applic~1\TuneUp Software
2012-10-05 20:34:41 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG Secure Search
2012-10-05 20:34:27 ——– d—–w- c:\docume~1\lisa\applic~1\AVG Secure Search
2012-10-05 20:34:24 27496 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-10-05 20:34:18 ——– d—–w- c:\program files\common files\AVG Secure Search
2012-10-05 20:31:51 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG2013
2012-10-05 20:28:42 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files
2012-10-05 20:28:42 ——– d—–w- c:\docume~1\lisa\locals~1\applic~1\MFAData
2012-10-05 20:28:42 ——– d—–w- c:\docume~1\lisa\locals~1\applic~1\Avg2013
2012-10-05 19:47:08 ——– dcsha-r- C:\cmdcons
2012-10-05 19:43:41 98816 —-a-w- c:\windows\sed.exe
2012-10-05 19:43:41 518144 —-a-w- c:\windows\SWREG.exe
2012-10-05 19:43:41 256000 —-a-w- c:\windows\PEV.exe
2012-10-05 19:43:41 208896 —-a-w- c:\windows\MBR.exe
2012-09-17 17:58:56 51936 —-a-w- c:\windows\system32\drivers\avgidshx.sys
2012-09-12 10:47:22 164704 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2012-09-12 10:47:04 151648 —-a-w- c:\windows\system32\drivers\avgldx86.sys
.
==================== Find3M ====================
.
2012-10-10 12:31:25 73656 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 12:31:25 696760 -c–a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-28 15:14:53 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14:53 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 —-a-w- c:\windows\system32\html.iec
.
============= FINISH: 19:20:14.67 ===============
Hello lisafunkypants and welcome back to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

I notice you have run ComboFix which is not recommended. ComboFix is a VERY powerful tool that can reduce a computer to a useless piece of metal without expert guidance.

Please send the log from when you ran it. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

===================================================

Disable Spybot’s TeaTimer

Spybot’s TeaTimer can sometimes prevent some things from being fixed.

Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.
  • open Spybot Search & Destroy
  • in the Mode menu click "Advanced mode" if not already selected
  • choose "Yes" at the Warning prompt
  • expand the "Tools" menu
  • click "Resident"
  • uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box
  • in the File menu click "Exit" to exit Spybot Search & Destroy.
===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
Please could you also send the Malwarebytes, (MBAM), log from when you ran it, Attach.txt from when you ran DDS and the first ComboFix log that was produced..

Attach.txt should be om your desktop or in the same place you found the DDS log.

You can find the MBAM log here:

C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Thanks

Satchfan
hi thanks for help here is what youve requested;

ComboFix 12-10-04.02 - lisa 05/10/2012 20:52:46.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.660 [GMT 1:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\lisa\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\lisa\Application Data\PriceGong
c:\documents and settings\lisa\Application Data\PriceGong\Data\1.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\a.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\b.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\c.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\d.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\e.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\f.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\g.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\h.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\i.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\J.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\k.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\l.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\m.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\n.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\o.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\p.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\q.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\r.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\s.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\t.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\u.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\v.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\w.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\x.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\y.xml
c:\documents and settings\lisa\Application Data\PriceGong\Data\z.xml
c:\documents and settings\lisa\Application Data\result.db
c:\documents and settings\lisa\Local Settings\Temp\IadHide5.dll
c:\program files\BrowserCompanion
c:\program files\BrowserCompanion\BCHelper.exe
c:\program files\BrowserCompanion\blabbers-ff-full.xpi
c:\program files\BrowserCompanion\jsloader.dll
c:\program files\BrowserCompanion\logo.ico
c:\program files\BrowserCompanion\tdataprotocol.dll
c:\program files\BrowserCompanion\toolbar.dll
c:\program files\BrowserCompanion\uninstall.exe
c:\program files\BrowserCompanion\updatebhoWin32.dll
c:\program files\BrowserCompanion\updater.ini
c:\program files\BrowserCompanion\widgetserv.exe
c:\program files\Downloaded Installers
c:\program files\Downloaded Installers\{9CAD26F9-54E3-4CBD-A8CA-C7C0E80F65E3}\setup.msi
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\SETD.tmp
c:\windows\system32\SETE.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_EPSONSTATUSAGENT2
——-\Service_EPSONStatusAgent2
.
.
((((((((((((((((((((((((( Files Created from 2012-09-05 to 2012-10-05 )))))))))))))))))))))))))))))))
.
.
2012-09-30 12:50 . 2012-08-30 08:17 6980552 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{710F7AAF-FAF2-4B83-8030-343E23C65AEB}\mpengine.dll
2012-09-23 17:23 . 2012-08-30 08:17 6980552 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-23 17:33 . 2012-04-13 16:30 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-23 17:33 . 2011-08-14 19:53 73136 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-30 21:03 . 2012-03-20 19:44 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2004-08-04 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2004-08-04 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2004-08-04 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 12:00 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{193d7001-bd9f-48c2-b5c7-69775aa2201d}"= "c:\program files\Plusmedia_uk\prxtbPlu1.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{193d7001-bd9f-48c2-b5c7-69775aa2201d}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{193d7001-bd9f-48c2-b5c7-69775aa2201d}]
2011-05-09 09:49 176936 —-a-w- c:\program files\Plusmedia_uk\prxtbPlu1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{193d7001-bd9f-48c2-b5c7-69775aa2201d}"= "c:\program files\Plusmedia_uk\prxtbPlu1.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{193d7001-bd9f-48c2-b5c7-69775aa2201d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{193D7001-BD9F-48C2-B5C7-69775AA2201D}"= "c:\program files\Plusmedia_uk\prxtbPlu1.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{193d7001-bd9f-48c2-b5c7-69775aa2201d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-04 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"Openwares LiveUpdate"="c:\program files\LiveUpdate\LiveUpdate.exe" [2003-12-13 61440]
"Aqua Dock"="c:\program files\Aqua Dock\Aqua Dock.exe" [2003-11-01 386560]
"EPSON Stylus D68 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE" [2005-01-25 98304]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"TalkTalk"="c:\program files\TalkTalk\bin\sprtcmd.exe" [2007-10-12 202016]
"Epson 68"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE" [2005-01-25 98304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless Networking Utility.lnk - c:\program files\Belkin\F6D4050\v1\Belkinwcui.exe [2011-7-27 1077248]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-2 180224]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\TalkTalk\\agent\\bin\\bcont.exe"=
"c:\\Program Files\\TalkTalk\\agent\\bin\\bcont_nm.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\TalkTalk\\bin\\sprtcmd.exe"=
"c:\\Program Files\\Common Files\\SupportSoft\\bin\\tgsrvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
.
R2 sprtsvc_TalkTalk;SupportSoft Sprocket Service (TalkTalk);c:\program files\TalkTalk\bin\sprtsvc.exe [12/10/2007 08:33 202016]
R2 tgsrvc_TalkTalk;SupportSoft Repair Service (TalkTalk);c:\program files\Common Files\SupportSoft\bin\tgsrvc.exe [02/08/2007 13:42 148768]
S1 MpKsld0342547;MpKsld0342547;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{710F7AAF-FAF2-4B83-8030-343E23C65AEB}\MpKsld0342547.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{710F7AAF-FAF2-4B83-8030-343E23C65AEB}\MpKsld0342547.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/07/2010 18:04 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [13/04/2012 17:30 250288]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [10/10/2006 22:51 131072]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\drivers\CnxEtU.sys [10/10/2006 22:51 614272]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver;c:\windows\system32\drivers\CnxTgNW.sys [10/10/2006 22:52 53248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/07/2010 18:04 136176]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [31/03/2012 12:27 20464]
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 17:33]
.
2012-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 17:57]
.
2012-10-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-13 17:03]
.
2012-10-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-13 17:03]
.
2012-10-05 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 16:25]
.
2012-10-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1343024091-682003330-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
.
2012-08-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-1343024091-682003330-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
.
2012-10-05 c:\windows\Tasks\User_Feed_Synchronization-{AF56A27E-A45B-4D4C-92AD-42D49FBF1C27}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.talktalk.co.uk/
uInternet Settings,ProxyOverride = ;*.local
IE: &AOL Toolbar Search - c:\program files\aol\aol talktalk toolbar 5.0\resources\en-GB\local\search.html
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{00cbb66b-1d3b-46d3-9577-323a336acb50} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
AddRemove-BrowserCompanion - c:\program files\BrowserCompanion\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-05 21:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3768)
c:\windows\system32\WININET.dll
c:\docume~1\lisa\LOCALS~1\Temp\IadHide5.dll
c:\program files\Aqua Dock\Aqua Dock.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2012-10-05 21:16:11 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-05 20:16
.
Pre-Run: 15,436,554,240 bytes free
Post-Run: 16,046,456,832 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 7296217C3E1E13F677CE37AB7D6B1198

——————————————————————————————————————————————————————————-
COMBOFIX/QOOBOX LOG


2012-10-05 20:14:18 . 2012-10-05 20:14:18 480 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-BrowserCompanion.reg.dat
2012-10-05 20:13:34 . 2012-10-05 20:13:34 150 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\HKU-Default-Run-ALUAlert.reg.dat
2012-10-05 20:13:27 . 2012-10-05 20:13:28 171 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2012-10-05 20:13:26 . 2012-10-05 20:13:26 208 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-{30F9B915-B755-4826-820B-08FBA6BD249D}.reg.dat
2012-10-05 20:13:26 . 2012-10-05 20:13:26 213 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2012-10-05 20:13:24 . 2012-10-05 20:13:24 157 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{00cbb66b-1d3b-46d3-9577-323a336acb50}.reg.dat
2012-10-05 20:07:17 . 2012-10-05 20:07:17 374 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\etc\hosts.ics.vir
2012-10-05 19:59:39 . 2012-10-05 19:59:39 2,886 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Service_EPSONStatusAgent2.reg.dat
2012-10-05 19:59:39 . 2012-10-05 19:59:39 1,166 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_EPSONSTATUSAGENT2.reg.dat
2012-10-05 19:59:22 . 2012-10-05 19:59:22 9,558 -c–a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2012-10-05 19:43:30 . 2012-10-05 19:43:30 51 -c–a-w- C:\Qoobox\Quarantine\catchme.log
2012-04-13 16:43:57 . 2012-10-05 19:17:48 3,472 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\mru.xml.vir
2012-03-29 03:41:24 . 2012-03-29 03:41:24 322,776 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\d.xml.vir
2012-03-29 03:41:06 . 2012-03-29 03:41:06 469,152 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\c.xml.vir
2012-03-29 03:40:42 . 2012-03-29 03:40:42 550,072 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\b.xml.vir
2012-03-29 03:40:14 . 2012-03-29 03:40:14 449,744 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\a.xml.vir
2012-03-29 03:39:50 . 2012-03-29 03:39:50 93,624 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\1.xml.vir
2012-03-28 19:35:18 . 2012-03-28 19:35:18 765 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\result.db.vir
2012-01-09 07:39:10 . 2012-01-09 07:39:10 38,776 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\z.xml.vir
2012-01-09 07:39:08 . 2012-01-09 07:39:08 38,216 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\y.xml.vir
2012-01-09 07:39:06 . 2012-01-09 07:39:06 150,648 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\w.xml.vir
2012-01-09 07:39:06 . 2012-01-09 07:39:06 10,784 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\x.xml.vir
2012-01-09 07:39:00 . 2012-01-09 07:39:00 99,192 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\v.xml.vir
2012-01-09 07:38:56 . 2012-01-09 07:38:56 79,200 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\u.xml.vir
2012-01-09 07:38:52 . 2012-01-09 07:38:52 337,624 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\t.xml.vir
2012-01-09 07:38:36 . 2012-01-09 07:38:36 628,328 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\s.xml.vir
2012-01-09 07:38:08 . 2012-01-09 07:38:08 145,056 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\r.xml.vir
2012-01-09 07:38:00 . 2012-01-09 07:38:00 313,784 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\p.xml.vir
2012-01-09 07:38:00 . 2012-01-09 07:38:00 15,368 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\q.xml.vir
2012-01-09 07:37:46 . 2012-01-09 07:37:46 134,752 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\o.xml.vir
2012-01-09 07:37:40 . 2012-01-09 07:37:40 131,392 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\n.xml.vir
2012-01-09 07:37:34 . 2012-01-09 07:37:34 348,960 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\m.xml.vir
2012-01-09 07:37:18 . 2012-01-09 07:37:18 213,224 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\l.xml.vir
2012-01-09 07:37:08 . 2012-01-09 07:37:08 113,160 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\k.xml.vir
2012-01-09 07:37:04 . 2012-01-09 07:37:04 91,208 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\J.xml.vir
2012-01-09 07:37:00 . 2012-01-09 07:37:00 124,200 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\i.xml.vir
2012-01-09 07:36:54 . 2012-01-09 07:36:54 179,016 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\h.xml.vir
2012-01-09 07:36:46 . 2012-01-09 07:36:46 227,792 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\g.xml.vir
2012-01-09 07:36:36 . 2012-01-09 07:36:36 209,904 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\f.xml.vir
2012-01-09 07:36:28 . 2012-01-09 07:36:28 268,912 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\lisa\Application Data\PriceGong\Data\e.xml.vir
2011-07-23 17:47:51 . 2011-07-23 17:47:51 51,725 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\uninstall.exe.vir
2011-07-21 10:23:04 . 2011-07-21 10:23:04 65,523 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\blabbers-ff-full.xpi.vir
2011-07-21 10:11:10 . 2011-07-21 10:11:10 127,792 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\toolbar.dll.vir
2011-07-21 10:10:56 . 2011-07-21 10:10:56 158,512 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\tdataprotocol.dll.vir
2011-07-21 10:10:54 . 2011-07-21 10:10:54 141,104 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\updatebhoWin32.dll.vir
2011-07-21 10:10:40 . 2011-07-21 10:10:40 225,584 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\jsloader.dll.vir
2011-07-21 10:10:40 . 2011-07-21 10:10:40 219,440 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\widgetserv.exe.vir
2011-07-21 10:10:24 . 2011-07-21 10:10:24 177,456 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\BCHelper.exe.vir
2010-03-10 09:30:54 . 2010-03-10 09:30:54 122 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\updater.ini.vir
2010-02-15 08:11:14 . 2010-02-15 08:11:14 5,430 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\logo.ico.vir
2009-03-28 09:23:09 . 2009-03-27 20:30:50 38,164,992 -c–a-w- C:\Qoobox\Quarantine\C\Program Files\Downloaded Installers\{9CAD26F9-54E3-4CBD-A8CA-C7C0E80F65E3}\setup.msi.vir
2008-09-30 05:57:19 . 2008-04-14 00:12:17 294,912 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\dlimport.exe.vir
2008-04-27 19:14:43 . 2004-02-11 16:58:16 24,613 —-a-w- C:\Qoobox\Quarantine\C\DOCUME~1\lisa\LOCALS~1\Temp\IadHide5.dll.vir
2006-05-19 12:59:41 . 2006-05-19 12:59:41 94,720 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\SETD.tmp.vir
2006-05-19 12:59:41 . 2006-05-19 12:59:41 148,480 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\SETE.tmp.vir
2005-07-14 17:28:02 . 2005-07-14 17:28:02 365 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf.vir
2004-08-04 12:00:00 . 2004-08-04 12:00:00 111,104 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000008_.tmp.dll.vir

——————————————————————————————————————————————————————————-
MALWARE LOG

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.10.10.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
lisa :: BARBARA-C65FA82 [administrator]

10/10/2012 16:59:20
mbam-log-2012-10-10 (18-48-10).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 331367
Time elapsed: 1 hour(s), 31 minute(s), 59 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 8
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> No action taken.
HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> No action taken.
HKCR\PROTOCOLS\HANDLER\CHROME (PUP.Blabbers) -> No action taken.
HKCR\PROTOCOLS\HANDLER\PROX (PUP.Blabbers) -> No action taken.

Registry Values Detected: 3
HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> No action taken.
HKCR\protocols\Handler\chrome|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> No action taken.
HKCR\protocols\Handler\prox|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\Program Files\MP3 Player Utilities\RDiskUpdate\DelDrv.exe (Risktool.KillFiles) -> No action taken.
C:\Qoobox\Quarantine\C\Program Files\BrowserCompanion\BCHelper.exe.vir (PUP.Blabbers) -> No action taken.
C:\System Volume Information\_restore{E3790B0D-08B3-425E-9B65-B3B07579DC25}\RP669\A0316705.exe (PUP.Blabbers) -> No action taken.

(end)

——————————————————————————————————————————————————————————-
DDS ATTACH LOG

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 07/10/2005 21:39:41
System Uptime: 10/10/2012 16:42:54 (3 hours ago)
.
Motherboard: TriGem Computer, Inc. | | Imperial
Processor: Intel® Celeron® CPU 1.70GHz | WMT478/NWD | 1694/mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 15.628 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&36B16CB7&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&36B16CB7&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP651: 15/08/2012 22:17:20 - Software Distribution Service 3.0
RP652: 16/08/2012 22:58:37 - Software Distribution Service 3.0
RP653: 19/08/2012 19:09:11 - Software Distribution Service 3.0
RP654: 21/08/2012 21:27:46 - Software Distribution Service 3.0
RP655: 24/08/2012 23:37:24 - Software Distribution Service 3.0
RP656: 27/08/2012 21:56:51 - Software Distribution Service 3.0
RP657: 29/08/2012 19:17:17 - Software Distribution Service 3.0
RP658: 30/08/2012 20:39:41 - Software Distribution Service 3.0
RP659: 02/09/2012 02:16:59 - System Checkpoint
RP660: 12/09/2012 11:57:07 - System Checkpoint
RP661: 13/09/2012 09:58:06 - Software Distribution Service 3.0
RP662: 15/09/2012 09:22:38 - Software Distribution Service 3.0
RP663: 23/09/2012 18:20:50 - Software Distribution Service 3.0
RP664: 23/09/2012 19:19:27 - Software Distribution Service 3.0
RP665: 30/09/2012 13:44:55 - Software Distribution Service 3.0
RP666: 30/09/2012 23:06:48 - Software Distribution Service 3.0
RP667: 05/10/2012 16:28:28 - System Checkpoint
RP668: 05/10/2012 20:11:37 - Software Distribution Service 3.0
RP669: 05/10/2012 20:33:28 - Software Distribution Service 3.0
RP670: 05/10/2012 21:19:23 - Removed Ad-Aware
RP671: 05/10/2012 21:19:47 - Software Distribution Service 3.0
RP672: 05/10/2012 21:29:55 - Installed AVG 2013
RP673: 05/10/2012 21:31:09 - Installed AVG 2013
RP674: 07/10/2012 18:46:10 - System Checkpoint
RP675: 08/10/2012 00:09:03 - Software Distribution Service 3.0
RP676: 10/10/2012 12:37:51 - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
.
101 Dalmatians Print Studio
ABBYY FineReader 4.0 Sprint
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9.5.2
Advanced WindowsCare Personal
AOL TalkTalk Toolbar 5.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Aqua Dock
Auslogics Disk Defrag
AVG 2013
Belkin Wireless USB Adapter Setup
BluBox
Bonjour
CCleaner
CCScore
Crush'Em 2.0
Digital Camera Driver
Download Updater (AOL LLC)
EPSON Attach To Email
EPSON Easy Photo Print
EPSON File Manager
EPSON PhotoQuicker3.2
EPSON Printer Software
EPSON Scan
EPSON Scan Assistant
EPSON Stylus SX100_TX100 Manual
EPSON SX100 Series Printer Uninstall
EPSON Web-To-Page
ErrorFix
ESD68 User's Guide
ESET Online Scanner
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
essvcpt
Google Chrome
Google Earth
Google Update Helper
HLPPDOCK
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
iTunes
Java Auto Updater
Java™ 6 Update 31
Junk Mail filter update
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
LRC Editor 4.0 (remove only)
Malwarebytes Anti-Malware version 1.65.0.1400
McAfee Security Scan
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.5
Microsoft Office XP Professional with FrontPage
Microsoft Publisher 2002
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MP3 Player Utilities
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Notifier
OfotoXMI
OTtBP
OTtBPSDK
Packard Bell Diamond 1200Plus v1.0
Pinnacle Express
Puzzl'Em 1.0 Beta2
QuickTime
RealPlayer
RealUpgrade 1.0
Samsung Master
Samsung USB Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
Segoe UI
SFR
SHASTA
SKIN0001
SKINXSDK
Sky Broadband
SmartSound Quicktracks Plugin
Spybot - Search & Destroy
staticcr
TalkTalk Assist & Go
TalkTalk Mail Toolbar
Tesco Photobook Creator
Ulead Photo Explorer 8.5 SE Basic
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VoiceOver Kit
VPRINTOL
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows XP Service Pack 3
WinZip
WIRELESS
Xvid 1.1.2 final uninstall
XviD MPEG-4 Codec
ZyXEL USB ADSL
.
==== Event Viewer Messages From Past Week ========
.
10/10/2012 16:45:40, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
10/10/2012 13:14:51, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706be: Office XP Service Pack 3.
07/10/2012 22:47:15, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\windows\system32\dnsrslvr.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 5.1.2600.5797, the version of the system file is 5.1.2600.5797.
07/10/2012 14:13:48, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
05/10/2012 21:53:21, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.
05/10/2012 20:17:12, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8024002d: Office XP Service Pack 3.
05/10/2012 20:14:03, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
05/10/2012 20:09:00, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
05/10/2012 14:49:07, error: Microsoft Antimalware [2001] -
05/10/2012 14:39:16, error: Service Control Manager [7000] - The MBAMService service failed to start due to the following error: The system cannot find the path specified.
.
==== End Of File ===========================
Thanks for those logs.

Most of PriceGong and other rubbish has been dealt with but please let me have the AdwCleaner log.

==============================================

Run Malwarebytes’ Anti-Malware

Although you ran it, you didn't choose to remove the baddies.
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Please include both logs

Thanks

Satchfan
Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.10.10.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 lisa :: BARBARA-C65FA82 [administrator] 11/10/2012 15:47:32 mbam-log-2012-10-11 (15-47-32).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 260799 Time elapsed: 13 minute(s), 19 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 4 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ——————————————————————————————————————————————————————————- # AdwCleaner v2.004 - Logfile created 10/11/2012 at 10:28:07 # Updated 06/10/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : lisa - BARBARA-C65FA82 # Boot Mode : Normal # Running from : C:\Documents and Settings\lisa\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search File Deleted : C:\WINDOWS\system32\conduitEngine.tmp Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Secure Search Folder Deleted : C:\Documents and Settings\lisa\AppData\LocalLow\bbrs_002.tb Folder Deleted : C:\Documents and Settings\lisa\Application Data\AVG Secure Search Folder Deleted : C:\Documents and Settings\lisa\Application Data\PriceGong Folder Deleted : C:\Documents and Settings\lisa\Local Settings\Application Data\AVG Secure Search Folder Deleted : C:\Documents and Settings\lisa\Local Settings\Application Data\Conduit Folder Deleted : C:\Program Files\AVG Secure Search Folder Deleted : C:\Program Files\Common Files\Software Update Utility Folder Deleted : C:\Program Files\Conduit ***** [Registry] ***** Key Deleted : HKCU\Software\AskSearchAsst Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\BrowserCompanion Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com Key Deleted : HKCU\Software\PriceGong Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\Software\BrowserCompanion Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511} Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2567697 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\updatebho.TimerBHO Key Deleted : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\ImInstaller Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowserCompanion Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxps://isearch.avg.com/tab?cid={C1BD8AA3-81CC-45A5-AABF-9CB9C6F74076}&mid=9746eb06013647d099d6d1096da20854-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=AVG&pr=pr&d=2012-10-05 21:54:30&v=12.2.5.34&sap=nt –> hxxp://www.google.com -\\ Mozilla Firefox v [Unable to get version] Profile name : default File : C:\Documents and Settings\lisa\Application Data\Mozilla\Firefox\Profiles\12we8o5l.default\prefs.js C:\Documents and Settings\lisa\Application Data\Mozilla\Firefox\Profiles\12we8o5l.default\user.js … Deleted ! Deleted : /* Do not edit this file. * * If you make changes to this file while the application is running, * t[…] -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\lisa\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.40] : icon_url = "hxxps://isearch.avg.com/favicon.ico", Deleted [l.43] : keyword = "isearch.avg.com", Deleted [l.46] : search_url = "hxxps://isearch.avg.com/search?cid={C1BD8AA3-81CC-45A5-AABF-9CB9C6F74076}&mid=&lang=&ds=&pr=&d=&v=&sap=dsp&q={searchTerms}", File : C:\Documents and Settings\kids\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [10925 octets] - [11/10/2012 10:28:07] ########## EOF - C:\AdwCleaner[S1].txt - [10986 octets] ##########
the pc is really slow but i assume its age can have an impact on its performance, its running alot better than previously. if you see no malware then i should assume its clear. I have to give the pc back tonight however. thx for you time x
I would say that it is pretty-much OK. I’d rather we’d done another online scan but if you have to get the PC back we can tidy up the tools that we used and the ones you previously used.

As long as your computer seems to be running well, please follow these steps:

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.

===================================================

Uninstall AdwCleaner
  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with yes.
You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update installed programs

There are old versions of Java & Adobe Reader on the computer which are vulnerable to infections.
  • click Start, Settings, Control Panel.
  • double-click Add or remove programs.
  • select any versions of Java, and Adobe Reader then click Uninstall.
Install the latest versions:

Java
http://www.java.com/en/download/manual.jsp

Adobe Reader
http://www.adobe.com/products/acrobat/read…llversions.html

===================================================

Spybot - Search and Destroy’ – Re-enable TeaTimer and remember to scan your computer with the program on a regular basis as you would with your anti-virus software.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes


If you or your mother feels that the slowness is still a concern, please let me know and we'll look further: otherwise, you can start a new topic as and when you are ready.

If I hear nothing for 24 hours I shall assume all is well and close the topic.

Safe computing

Satchfan
i can get to the pc to run a scan on it but it will take a litlte extra time to reply to you, if you dont mind. it generally works fine but it takes a long time to initially get started. f you think its ok then we can close the thread. thanks for everything :thumbup:
I'll close this now but when you have time to access the computer for a few days, try the Eset scan and if any infections show up or if you have any concerns, start a new thread and we'll look again. Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI