This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

very very slow computer [Closed] [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I'm trying to help my uncle make his computer faster. His computer is running very slowly. It takes a long time for the computer to boot and for programs to run and load.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:48:45 PM, on 20/01/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\TeamViewer\Version7\TeamViewer.exe
c:\program files\teamviewer\version7\TeamViewer_Desktop.exe
C:\Users\Dorwang\Documents\sunshinegirl_canoe_ca – Today's SUNshine Girl_files\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca/ig/dell?hl=en&cli…amp;ibd=4071215
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

–
End of file - 10690 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi Jeff, thank you for helping me and I'm sorry for the slow reply. I was waiting to hear from my uncle so that I could use his computer again but he had not contacted me. I'm waiting for aswMBR to finish updating and will copy the logfile here when it is finished. My uncle has very slow internet so it is taking a long time. I tried to right-click and Run as Administrator dds to run dds but that option wasn't available so I double clicked the icon. Here are the results: DDS.txt DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2 Run by [removed] at 16:59:48 on 2013-01-24 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.1012.216 [GMT -5:00] . AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} AV: AVG Anti-Virus Free *Disabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82} SP: AVG Anti-Virus Free *Disabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\Windows\system32\SLsvc.exe C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe C:\Windows\System32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Windows\system32\AERTSrv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe C:\Windows\system32\DllHost.exe C:\Windows\RtHDVCpl.exe C:\Windows\WindowsMobile\wmdc.exe C:\Windows\System32\igfxpers.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Logitech\Vid HD\Vid.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Xfire\xfire.exe C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\AVG Secure Search\ROC_JAN2013_TB.exe C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\14.0.1\ScriptHelper.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\taskeng.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Windows\system32\wuauclt.exe C:\Program Files\TeamViewer\Version7\TeamViewer.exe C:\Program Files\TeamViewer\Version7\tv_w32.exe c:\program files\teamviewer\version7\TeamViewer_Desktop.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uWindow Title = Internet Explorer provided by Dell mStart Page = hxxp://ca.yahoo.com mDefault_Page_URL = hxxp://ca.yahoo.com uURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: FGCatchUrl: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - c:\program files\flashget\jccatch.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg8\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\14.0.2.14\AVG Secure Search_toolbar.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\dell\bae\BAE.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: FlashGet GetFlash Class: {F156768E-81EF-470C-9057-481BA8380DBA} - c:\program files\flashget\getflash.dll BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\14.0.2.14\AVG Secure Search_toolbar.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Logitech Vid] "c:\program files\logitech\vid hd\Vid.exe" -bootmode uRun: [Facebook Update] "c:\users\dorwang\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [ROC_JAN2013_TB] "c:\program files\avg secure search\ROC_JAN2013_TB.exe" /PROMPT /CMPID=JAN2013_TB mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Windows Mobile Device Center] c:\windows\windowsmobile\wmdc.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [hpqSRMon] StartupFolder: c:\users\dorwang\appdata\roaming\micros~1\windows\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\xfire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: &Download; All with FlashGet - c:\program files\flashget\jc_all.htm IE: &Download; with FlashGet - c:\program files\flashget\jc_link.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab TCP: NameServer = 192.168.0.1 TCP: Interfaces\{5B3B49B8-8799-4F8B-B772-562D3C1386A2} : DHCPNameServer = 192.168.0.1 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\14.0.1\ViProtocol.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs= avgrsstx.dll SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg . ================= FIREFOX =================== . FF - ProfilePath - c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\ FF - prefs.js: browser.search.defaulturl - hxxp://ca.search.yahoo.com/search?fr=ffsp1&p;= FF - prefs.js: browser.startup.homepage - hxxp://home.mywebsearch.com/index.jhtml?ptb=AB4AD811-7D70-4A3E-A4C0-0D08082F48A5&n;=77edeb10&p2;=^XP^xdm255^LENCA^ca FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B33bfe08b-bd8b-4f25-a2c3-558e4761ca17%7D∣=69cb538dd4d794d5fad5cde773cc8862-611c63547164efb827e16df3587e4ce68912e632&ds;=AVG&v;=10.2.0.3⟨=us≺=fr&d;=2011-12-05%2008%3A55%3A58&sap;=ku&q;= FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko10.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko11.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko19.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko5.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko6.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko7.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko8.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\components\RadioWMPCoreGecko9.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko10.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko11.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko19.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko5.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko6.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko7.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko8.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\components\RadioWMPCoreGecko9.dll FF - component: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll FF - plugin: c:\progra~1\meadco~1\npmeadax.dll FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\14.0.1\npsitesafety.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\vlc\npvlc.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\dorwang\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll FF - plugin: c:\users\dorwang\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}\plugins\np-mswmp.dll FF - plugin: c:\users\dorwang\appdata\roaming\mozilla\firefox\profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}\plugins\np-mswmp.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_146.dll FF - ExtSQL: !HIDDEN! 2009-07-16 11:13; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . . =============== Created Last 30 ================ . 2013-01-24 21:34:55 ——– d—–w- c:\users\dorwang\appdata\local\AVG Secure Search 2013-01-24 21:30:40 31576 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-01-23 15:35:21 60872 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{97df53c6-cca8-4ca3-b527-2a42312a7133}\offreg.dll 2013-01-22 20:04:50 15712 —-a-w- c:\program files\common files\windows live\.cache\bb8d82831cdf8db1f\MeshBetaRemover.exe 2013-01-22 20:03:53 94040 —-a-w- c:\program files\common files\windows live\.cache\995b8ae31cdf8db17\DSETUP.dll 2013-01-22 20:03:53 525656 —-a-w- c:\program files\common files\windows live\.cache\995b8ae31cdf8db17\DXSETUP.exe 2013-01-22 20:03:53 1691480 —-a-w- c:\program files\common files\windows live\.cache\995b8ae31cdf8db17\dsetup32.dll 2013-01-22 20:03:45 94040 —-a-w- c:\program files\common files\windows live\.cache\8daa12c31cdf8db16\DSETUP.dll 2013-01-22 20:03:45 525656 —-a-w- c:\program files\common files\windows live\.cache\8daa12c31cdf8db16\DXSETUP.exe 2013-01-22 20:03:45 1691480 —-a-w- c:\program files\common files\windows live\.cache\8daa12c31cdf8db16\dsetup32.dll 2013-01-22 19:54:11 ——– d—–w- c:\users\dorwang\appdata\local\Windows Live 2013-01-22 19:51:09 754688 —-a-w- c:\windows\system32\webservices.dll 2013-01-19 15:14:59 55808 —-a-w- c:\program files\mozilla firefox\vlc\plugins\video_filter\libaudiobargraph_v_plugin.dll 2013-01-18 18:40:19 6991832 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{97df53c6-cca8-4ca3-b527-2a42312a7133}\mpengine.dll 2013-01-10 14:50:17 16369160 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe 2013-01-09 15:49:55 2048000 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 15:49:23 204288 —-a-w- c:\windows\system32\ncrypt.dll 2013-01-09 15:48:30 1400832 —-a-w- c:\windows\system32\msxml6.dll 2013-01-08 19:31:49 ——– d—–w- c:\users\dorwang\Tracing 2013-01-08 19:23:37 54632 —-a-w- c:\windows\system32\drivers\fssfltr.sys 2013-01-08 19:20:23 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2013-01-08 19:18:31 ——– d—–w- c:\program files\Windows Live SkyDrive 2013-01-08 19:17:07 83249512 —-a-w- c:\program files\common files\windows live\.cache\wlc5F20.tmp 2012-12-26 17:47:16 34304 —-a-w- c:\windows\system32\atmlib.dll 2012-12-26 17:47:16 293376 —-a-w- c:\windows\system32\atmfd.dll . ==================== Find3M ==================== . 2013-01-10 14:51:51 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-01-10 14:51:51 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-12-08 04:30:48 0 —-a-w- c:\windows\system32\dlumd9.dll 2012-12-08 04:30:48 0 —-a-w- c:\windows\system32\dlumd11.dll 2012-12-08 04:30:48 0 —-a-w- c:\windows\system32\dlumd10.dll 2012-12-08 04:30:39 1996288 —-a-w- c:\windows\system32\DisplayLinkUsbCo2_7.0.41409.0.dll 2012-12-08 04:30:38 21888 —-a-w- c:\windows\system32\drivers\DisplayLinkUsbPort_7.0.41409.0.sys 2012-12-08 04:12:59 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-12-08 04:12:58 746984 —-a-w- c:\windows\system32\deployJava1.dll 2012-12-08 00:07:43 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-11-20 08:32:39 336248 —-a-w- c:\windows\system32\drivers\dlkmd.sys 2012-11-20 08:32:39 15224 —-a-w- c:\windows\system32\drivers\dlkmdldr.sys 2012-11-20 08:31:12 1156568 —-a-w- c:\windows\system32\dlumd64.dll 2012-11-20 08:31:07 964056 —-a-w- c:\windows\system32\dlumd32.dll 2012-11-20 08:31:02 93144 —-a-w- c:\windows\system32\DLTmmB.dll 2012-11-20 08:31:01 90584 —-a-w- c:\windows\system32\ManageTMMLifeTime.dll 2012-11-14 02:09:22 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-13 01:29:51 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-02 10:18:17 376320 —-a-w- c:\windows\system32\dpnet.dll 2012-11-02 08:26:06 23040 —-a-w- c:\windows\system32\dpnsvr.exe . ============= FINISH: 17:03:37.28 =============== Attach.txt DDS (Ver_2012-11-20.01) . Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume3 Install Date: 15/12/2007 9:06:33 AM System Uptime: 24/01/2013 4:25:55 PM (1 hours ago) . Motherboard: Dell Inc. | | 0RY007 Processor: Intel® Pentium® Dual CPU E2140 @ 1.60GHz | Socket 775 | 1200/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 223 GiB total, 133.204 GiB free. D: is FIXED (NTFS) - 10 GiB total, 6.592 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . . ==== Installed Programs ====================== . 32 Bit HP CIO Components Installer Ad-Aware Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.1 µTorrent AVG Free 8.5 AVG Security Toolbar Bing Bar Browser Address Error Redirector BufferChm CameraHelperMsi CCleaner CustomerResearchQFolder D2500 D2500_Help Dell DataSafe Online Dell Getting Started Guide Dell Support Center (Support Software) DeviceDiscovery DeviceManagementQFolder DisplayLink Core Software DisplayLink Graphics DJ_SF_03_D2500_ProductContext DJ_SF_03_D2500_Software DJ_SF_03_D2500_Software_Min Entropia Universe erLT eSupportQFolder Facebook Video Calling 1.2.0.287 FlashGet 1.9.6.1073 FrostWire 4.13.5 Google Updater GPBaseService Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Customer Participation Program 10.0 HP Deskjet D2500 Printer Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update HPDiagnosticAlert HPProductAssistant HPSSupply Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections 12.1.11.0 Java 7 Update 9 Java Auto Updater Java™ 6 Update 37 Java™ SE Runtime Environment 6 Junk Mail filter update K-Meleon 1.5.4 en-US (remove only) Logitech Vid HD Logitech Webcam Software LWS Facebook LWS Gallery LWS Help_main LWS Launcher LWS Motion Detection LWS Pictures And Video LWS Twitter LWS Video Mask Maker LWS VideoEffects LWS Webcam Software LWS WLM Plugin LWS YouTube Plugin Malwarebytes Anti-Malware version 1.65.1.1000 MarketResearch McAfee Security Scan Plus Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Picture It! Photo 7.0 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Word 2002 Microsoft Works Microsoft Works 2003 Setup Launcher Microsoft Works 7.0 Microsoft Works Suite Add-in for Microsoft Word Monlam Bod-yig 1 Mozilla Firefox 18.0.1 (x86 en-GB) Mozilla Maintenance Service MSVCRT MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Pando Media Booster PowerDVD PSSWCORE Quick Screen Recorder 1.5 Realtek High Definition Audio Driver Revo Uninstaller 1.94 Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler Roxio MyDVD DE Roxio Update Manager Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Shop for HP Supplies Skype Click to Call Skype™ 5.10 SmartWebPrintingOC Soft Voice SoftRing Modem with SmartSP SolutionCenter Sonic Activation Module Status SUPERAntiSpyware TeamViewer 7 Toolbox TrayApp UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) User's Guides VideoToolkit01 VLC media player 2.0.4 WebReg Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Mobile Device Center Windows Mobile Device Center Driver Update Works Suite OS Pack Xfire (remove only) Yahoo! BrowserPlus 2.9.8 Yahoo! Detect Yahoo! Messenger Yahoo! Search Protection Yahoo! Software Update . ==== End Of File ===========================
Here is the aswMBR log file: aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-24 17:12:25 —————————– 17:12:25.971 OS Version: Windows 6.0.6002 Service Pack 2 17:12:25.971 Number of processors: 2 586 0xF0D 17:12:25.973 ComputerName: DORWANG-PC UserName: Dorwang 17:12:28.720 Initialize success 17:32:55.499 AVAST engine defs: 13012401 17:34:06.467 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 17:34:06.471 Disk 0 Vendor: ST3250310AS 3.ADA Size: 238418MB BusType: 3 17:34:06.495 Disk 0 MBR read successfully 17:34:06.518 Disk 0 MBR scan 17:34:06.626 Disk 0 Windows VISTA default MBR code 17:34:06.632 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 17:34:06.656 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 98304 17:34:06.672 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 228129 MB offset 21069824 17:34:06.703 Disk 0 scanning sectors +488278016 17:34:06.895 Disk 0 scanning C:\Windows\system32\drivers 17:34:56.295 Service scanning 17:35:43.359 Modules scanning 17:35:54.548 Disk 0 trace - called modules: 17:35:54.655 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 17:35:54.665 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84e4f170] 17:35:54.675 3 CLASSPNP.SYS[863b08b3] -> nt!IofCallDriver -> [0x846ef918] 17:35:54.684 5 acpi.sys[806a26bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x846d3b98] 17:35:57.199 AVAST engine scan C:\Windows 17:36:03.697 AVAST engine scan C:\Windows\system32 17:51:27.196 AVAST engine scan C:\Windows\system32\drivers 17:52:11.710 AVAST engine scan C:\Users\Dorwang 18:13:32.928 AVAST engine scan C:\ProgramData 18:17:58.834 Scan finished successfully 18:45:23.350 Disk 0 MBR has been saved successfully to "C:\Users\Dorwang\Desktop\MBR.dat" 18:45:23.427 The log file has been saved successfully to "C:\Users\Dorwang\Desktop\aswMBR.txt"
Hi,

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-

ComboFix

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Here are the log files. Thanks Jeffce

# AdwCleaner v2.108 - Logfile created 01/25/2013 at 16:48:59
# Updated 24/01/2013 by Xplode
# Operating system : Windows Vista ™ Home Basic Service Pack 2 (32 bits)
# User : Dorwang - DORWANG-PC
# Boot Mode : Normal
# Running from : C:\Users\Dorwang\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\searchplugins\my-web-search.xml
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Users\Dorwang\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Dorwang\AppData\Local\AVG Security Toolbar
Folder Deleted : C:\Users\Dorwang\AppData\LocalLow\AVG Security Toolbar
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\Conduit
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\ConduitEngine
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\CT2354614
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\CT2415802
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\CT2436590
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\{54d0da58-64e7-4408-be1f-72659f70fcbe}
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\{9dbb9aeb-5a16-4989-a66f-c0f1c909d647}
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\{eec7cc31-73f4-4f7f-ac41-80994c84711b}
Folder Deleted : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v18.0.1 (en-GB)

File : C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\prefs.js

C:\Users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\user.js … Deleted !

Deleted : user_pref("CT2354614..clientLogIsEnabled", false);
Deleted : user_pref("CT2354614..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…]
Deleted : user_pref("CT2354614..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…]
Deleted : user_pref("CT2354614.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2354614.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2354614.BrowserCompStateIsOpen_129683254438197986", true);
Deleted : user_pref("CT2354614.CTID", "CT2354614");
Deleted : user_pref("CT2354614.CurrentServerDate", "25-1-2013");
Deleted : user_pref("CT2354614.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2354614.DialogsGetterLastCheckTime", "Thu Jan 24 2013 12:57:44 GMT-0500 (Eastern Standa[…]
Deleted : user_pref("CT2354614.DownloadReferralCookieData", "");
Deleted : user_pref("CT2354614.EMailNotifierPollDate", "Sun Jul 11 2010 11:32:14 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("CT2354614.ExternalComponentPollDate128950121095832148", "Sun Feb 21 2010 12:27:07 GMT-050[…]
Deleted : user_pref("CT2354614.ExternalComponentPollDate129034476366350537", "Sun Jul 11 2010 11:27:08 GMT-040[…]
Deleted : user_pref("CT2354614.ExternalComponentPollDate129039750747456367", "Sun Jul 11 2010 11:27:08 GMT-040[…]
Deleted : user_pref("CT2354614.ExternalComponentPollDate1670445323984375361", "Sun Mar 28 2010 10:31:29 GMT-04[…]
Deleted : user_pref("CT2354614.FirstServerDate", "29-12-2009");
Deleted : user_pref("CT2354614.FirstTime", true);
Deleted : user_pref("CT2354614.FirstTimeFF3", true);
Deleted : user_pref("CT2354614.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2354614.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2354614.HasUserGlobalKeys", true);
Deleted : user_pref("CT2354614.Initialize", true);
Deleted : user_pref("CT2354614.InitializeCommonPrefs", true);
Deleted : user_pref("CT2354614.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2354614.InstallationType", "Unknown");
Deleted : user_pref("CT2354614.InstalledDate", "Tue Dec 29 2009 13:07:07 GMT-0500 (Eastern Standard Time)");
Deleted : user_pref("CT2354614.InvalidateCache", false);
Deleted : user_pref("CT2354614.IsGrouping", false);
Deleted : user_pref("CT2354614.IsMulticommunity", false);
Deleted : user_pref("CT2354614.IsOpenThankYouPage", true);
Deleted : user_pref("CT2354614.IsOpenUninstallPage", true);
Deleted : user_pref("CT2354614.LanguagePackLastCheckTime", "Thu Jan 24 2013 16:37:55 GMT-0500 (Eastern Standar[…]
Deleted : user_pref("CT2354614.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2354614.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT2354614.LastLogin_2.5.2.14", "Sun Feb 28 2010 16:52:32 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2354614.LastLogin_2.5.6.0", "Sun Jul 11 2010 11:27:05 GMT-0400 (Eastern Daylight Time)"[…]
Deleted : user_pref("CT2354614.LastLogin_3.12.2.3", "Sun Jul 01 2012 20:37:33 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2354614.LastLogin_3.13.0.6", "Tue Jul 17 2012 10:48:32 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2354614.LastLogin_3.14.1.0", "Sun Aug 26 2012 12:55:47 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2354614.LastLogin_3.15.1.0", "Mon Nov 12 2012 16:18:00 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2354614.LastLogin_3.16.0.3", "Fri Jan 25 2013 14:17:30 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2354614.LatestVersion", "3.16.0.3");
Deleted : user_pref("CT2354614.Locale", "en");
Deleted : user_pref("CT2354614.LoginCache", 4);
Deleted : user_pref("CT2354614.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2354614.MCDetectTooltipShow", false);
Deleted : user_pref("CT2354614.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2354614.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2354614.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2354614.RadioIsPodcast", false);
Deleted : user_pref("CT2354614.RadioLastCheckTime", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2354614.RadioLastUpdateIPServer", "4");
Deleted : user_pref("CT2354614.RadioLastUpdateServer", "4");
Deleted : user_pref("CT2354614.RadioMediaID", "9962");
Deleted : user_pref("CT2354614.RadioMediaType", "Media Player");
Deleted : user_pref("CT2354614.RadioMenuSelectedID", "EBRadioMenu_CT23546149962");
Deleted : user_pref("CT2354614.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2354614.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2354614.RadioVolume", "0");
Deleted : user_pref("CT2354614.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2354614.SavedHomepage", "hxxp://search.conduit.com/?ctid=CT2436590&SearchSource;=13");
Deleted : user_pref("CT2354614.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[…]
Deleted : user_pref("CT2354614.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2354614.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT235[…]
Deleted : user_pref("CT2354614.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2354614.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2354614.SearchInNewTabLastCheckTime", "Thu Jan 24 2013 16:37:19 GMT-0500 (Eastern Stand[…]
Deleted : user_pref("CT2354614.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT2354614.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[…]
Deleted : user_pref("CT2354614.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2354614.ServiceMapLastCheckTime", "Thu Jan 24 2013 16:37:24 GMT-0500 (Eastern Standard […]
Deleted : user_pref("CT2354614.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2354614.SettingsLastCheckTime", "Fri Jan 25 2013 14:17:19 GMT-0500 (Eastern Standard Ti[…]
Deleted : user_pref("CT2354614.SettingsLastUpdate", "1359101652");
Deleted : user_pref("CT2354614.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2354614.ThirdPartyComponentsLastCheck", "Sat Jun 26 2010 13:15:08 GMT-0400 (Eastern Day[…]
Deleted : user_pref("CT2354614.ThirdPartyComponentsLastUpdate", "1276854000");
Deleted : user_pref("CT2354614.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2354614");
Deleted : user_pref("CT2354614.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[…]
Deleted : user_pref("CT2354614.UserID", "UN94299550565776323");
Deleted : user_pref("CT2354614.ValidationData_Search", 2);
Deleted : user_pref("CT2354614.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2354614.WeatherNetwork", "");
Deleted : user_pref("CT2354614.WeatherPollDate", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Daylight Time)");
Deleted : user_pref("CT2354614.WeatherUnit", "C");
Deleted : user_pref("CT2354614.alertChannelId", "749848");
Deleted : user_pref("CT2354614.clientLogIsEnabled", true);
Deleted : user_pref("CT2354614.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[…]
Deleted : user_pref("CT2354614.components.1000034", true);
Deleted : user_pref("CT2354614.components.1000234", true);
Deleted : user_pref("CT2354614.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[…]
Deleted : user_pref("CT2354614.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2354614.initDone", true);
Deleted : user_pref("CT2354614.myStuffEnabled", true);
Deleted : user_pref("CT2354614.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2354614.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT2354614.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2354614.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT2354614.revertSettingsEnabled", false);
Deleted : user_pref("CT2354614.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2354614.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2354614.testingCtid", "");
Deleted : user_pref("CT2354614.toolbarAppMetaDataLastCheckTime", "Thu Jan 24 2013 16:37:55 GMT-0500 (Eastern S[…]
Deleted : user_pref("CT2354614.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[…]
Deleted : user_pref("CT2415802..clientLogIsEnabled", false);
Deleted : user_pref("CT2415802..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…]
Deleted : user_pref("CT2415802..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…]
Deleted : user_pref("CT2415802.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2415802.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2415802.BrowserCompStateIsOpen_129462016196700409", true);
Deleted : user_pref("CT2415802.BrowserCompStateIsOpen_129683267180122832", true);
Deleted : user_pref("CT2415802.CTID", "CT2415802");
Deleted : user_pref("CT2415802.CurrentServerDate", "25-1-2013");
Deleted : user_pref("CT2415802.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2415802.DialogsGetterLastCheckTime", "Thu Jan 24 2013 12:57:41 GMT-0500 (Eastern Standa[…]
Deleted : user_pref("CT2415802.DownloadReferralCookieData", "");
Deleted : user_pref("CT2415802.EMailNotifierPollDate", "Sun Jul 11 2010 11:32:11 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("CT2415802.ExternalComponentPollDate128950121095832148", "Sun Jul 11 2010 11:26:28 GMT-040[…]
Deleted : user_pref("CT2415802.ExternalComponentPollDate129034474183537558", "Sun Jul 11 2010 11:26:28 GMT-040[…]
Deleted : user_pref("CT2415802.ExternalComponentPollDate1670445323984375361", "Tue Mar 23 2010 07:37:29 GMT-04[…]
Deleted : user_pref("CT2415802.FirstServerDate", "31-12-2009");
Deleted : user_pref("CT2415802.FirstTime", true);
Deleted : user_pref("CT2415802.FirstTimeFF3", true);
Deleted : user_pref("CT2415802.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2415802.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2415802.HasUserGlobalKeys", true);
Deleted : user_pref("CT2415802.Initialize", true);
Deleted : user_pref("CT2415802.InitializeCommonPrefs", true);
Deleted : user_pref("CT2415802.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2415802.InstallationType", "Unknown");
Deleted : user_pref("CT2415802.InstalledDate", "Thu Dec 31 2009 10:26:07 GMT-0500 (Eastern Standard Time)");
Deleted : user_pref("CT2415802.InvalidateCache", false);
Deleted : user_pref("CT2415802.IsGrouping", false);
Deleted : user_pref("CT2415802.IsMulticommunity", false);
Deleted : user_pref("CT2415802.IsOpenThankYouPage", true);
Deleted : user_pref("CT2415802.IsOpenUninstallPage", true);
Deleted : user_pref("CT2415802.LanguagePackLastCheckTime", "Thu Jan 24 2013 16:37:16 GMT-0500 (Eastern Standar[…]
Deleted : user_pref("CT2415802.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2415802.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT2415802.LastLogin_2.5.2.14", "Sun Feb 28 2010 16:52:32 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2415802.LastLogin_2.5.6.0", "Sun Jul 11 2010 11:26:35 GMT-0400 (Eastern Daylight Time)"[…]
Deleted : user_pref("CT2415802.LastLogin_3.12.2.3", "Sun Jul 01 2012 20:37:27 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2415802.LastLogin_3.13.0.6", "Mon Jul 16 2012 08:30:45 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2415802.LastLogin_3.14.1.0", "Sun Aug 26 2012 12:57:05 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2415802.LastLogin_3.15.1.0", "Mon Nov 12 2012 16:16:36 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2415802.LastLogin_3.16.0.3", "Fri Jan 25 2013 14:16:55 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2415802.LatestVersion", "3.16.0.3");
Deleted : user_pref("CT2415802.Locale", "en");
Deleted : user_pref("CT2415802.LoginCache", 4);
Deleted : user_pref("CT2415802.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2415802.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2415802.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2415802.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2415802.RadioIsPodcast", false);
Deleted : user_pref("CT2415802.RadioLastCheckTime", "Sun Jul 11 2010 11:27:11 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2415802.RadioLastUpdateIPServer", "4");
Deleted : user_pref("CT2415802.RadioLastUpdateServer", "4");
Deleted : user_pref("CT2415802.RadioMediaID", "9962");
Deleted : user_pref("CT2415802.RadioMediaType", "Media Player");
Deleted : user_pref("CT2415802.RadioMenuSelectedID", "EBRadioMenu_CT24158029962");
Deleted : user_pref("CT2415802.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2415802.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2415802.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2415802.SavedHomepage", "hxxp://search.conduit.com/?ctid=CT2354614&SearchSource;=13");
Deleted : user_pref("CT2415802.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[…]
Deleted : user_pref("CT2415802.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2415802.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT241[…]
Deleted : user_pref("CT2415802.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2415802.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2415802.SearchInNewTabLastCheckTime", "Thu Jan 24 2013 16:35:36 GMT-0500 (Eastern Stand[…]
Deleted : user_pref("CT2415802.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT2415802.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[…]
Deleted : user_pref("CT2415802.ServiceMapLastCheckTime", "Thu Jan 24 2013 16:35:43 GMT-0500 (Eastern Standard […]
Deleted : user_pref("CT2415802.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2415802.SettingsLastCheckTime", "Fri Jan 25 2013 14:13:13 GMT-0500 (Eastern Standard Ti[…]
Deleted : user_pref("CT2415802.SettingsLastUpdate", "1358755255");
Deleted : user_pref("CT2415802.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2415802.ThirdPartyComponentsLastCheck", "Sat Jun 26 2010 13:15:10 GMT-0400 (Eastern Day[…]
Deleted : user_pref("CT2415802.ThirdPartyComponentsLastUpdate", "1275739938");
Deleted : user_pref("CT2415802.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2415802");
Deleted : user_pref("CT2415802.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[…]
Deleted : user_pref("CT2415802.UserID", "UN08911334859186871");
Deleted : user_pref("CT2415802.ValidationData_Search", 2);
Deleted : user_pref("CT2415802.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2415802.WeatherNetwork", "");
Deleted : user_pref("CT2415802.WeatherPollDate", "Sun Jul 11 2010 11:27:11 GMT-0400 (Eastern Daylight Time)");
Deleted : user_pref("CT2415802.WeatherUnit", "C");
Deleted : user_pref("CT2415802.alertChannelId", "810195");
Deleted : user_pref("CT2415802.clientLogIsEnabled", true);
Deleted : user_pref("CT2415802.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[…]
Deleted : user_pref("CT2415802.components.1000034", true);
Deleted : user_pref("CT2415802.components.1000234", true);
Deleted : user_pref("CT2415802.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[…]
Deleted : user_pref("CT2415802.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2415802.initDone", true);
Deleted : user_pref("CT2415802.myStuffEnabled", true);
Deleted : user_pref("CT2415802.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2415802.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT2415802.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2415802.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT2415802.revertSettingsEnabled", false);
Deleted : user_pref("CT2415802.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2415802.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2415802.testingCtid", "");
Deleted : user_pref("CT2415802.toolbarAppMetaDataLastCheckTime", "Thu Jan 24 2013 16:37:16 GMT-0500 (Eastern S[…]
Deleted : user_pref("CT2415802.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[…]
Deleted : user_pref("CT2436590.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2436590.CTID", "CT2436590");
Deleted : user_pref("CT2436590.CurrentServerDate", "11-7-2010");
Deleted : user_pref("CT2436590.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2436590.EMailNotifierPollDate", "Sun Jul 11 2010 11:32:14 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("CT2436590.ExternalComponentPollDate129015373189907028", "Sun Mar 28 2010 10:31:32 GMT-040[…]
Deleted : user_pref("CT2436590.ExternalComponentPollDate129015373190063280", "Fri Jan 29 2010 11:21:03 GMT-050[…]
Deleted : user_pref("CT2436590.ExternalComponentPollDate129038056302832188", "Sun Jul 11 2010 11:27:10 GMT-040[…]
Deleted : user_pref("CT2436590.FirstServerDate", "20-12-2009");
Deleted : user_pref("CT2436590.FirstTime", true);
Deleted : user_pref("CT2436590.FirstTimeFF3", true);
Deleted : user_pref("CT2436590.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2436590.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2436590.Initialize", true);
Deleted : user_pref("CT2436590.InitializeCommonPrefs", true);
Deleted : user_pref("CT2436590.InstalledDate", "Sun Dec 20 2009 12:03:44 GMT-0500 (Eastern Standard Time)");
Deleted : user_pref("CT2436590.InvalidateCache", false);
Deleted : user_pref("CT2436590.IsGrouping", false);
Deleted : user_pref("CT2436590.IsMulticommunity", false);
Deleted : user_pref("CT2436590.IsOpenThankYouPage", true);
Deleted : user_pref("CT2436590.IsOpenUninstallPage", true);
Deleted : user_pref("CT2436590.LanguagePackLastCheckTime", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Dayligh[…]
Deleted : user_pref("CT2436590.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2436590.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT2436590.LastLogin_2.5.2.13", "Mon Dec 28 2009 13:31:51 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2436590.LastLogin_2.5.2.14", "Sun Feb 28 2010 16:52:35 GMT-0500 (Eastern Standard Time)[…]
Deleted : user_pref("CT2436590.LastLogin_2.5.6.0", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Daylight Time)"[…]
Deleted : user_pref("CT2436590.LatestVersion", "2.1.0.18");
Deleted : user_pref("CT2436590.Locale", "en");
Deleted : user_pref("CT2436590.LoginCache", 4);
Deleted : user_pref("CT2436590.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2436590.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2436590.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2436590.RadioIsPodcast", false);
Deleted : user_pref("CT2436590.RadioLastCheckTime", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Daylight Time)[…]
Deleted : user_pref("CT2436590.RadioLastUpdateIPServer", "4");
Deleted : user_pref("CT2436590.RadioLastUpdateServer", "4");
Deleted : user_pref("CT2436590.RadioMediaID", "9962");
Deleted : user_pref("CT2436590.RadioMediaType", "Media Player");
Deleted : user_pref("CT2436590.RadioMenuSelectedID", "EBRadioMenu_CT24365909962");
Deleted : user_pref("CT2436590.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2436590.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2436590.RadioVolume", "16");
Deleted : user_pref("CT2436590.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2436590.SavedHomepage", "hxxp://www.tibetsites.com");
Deleted : user_pref("CT2436590.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[…]
Deleted : user_pref("CT2436590.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2436590.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[…]
Deleted : user_pref("CT2436590.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2436590.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2436590.SearchInNewTabLastCheckTime", "Sun Jul 11 2010 11:27:10 GMT-0400 (Eastern Dayli[…]
Deleted : user_pref("CT2436590.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT2436590.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[…]
Deleted : user_pref("CT2436590.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2436590.SettingsLastCheckTime", "Sun Jul 11 2010 11:27:10 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("CT2436590.SettingsLastUpdate", "1277824125");
Deleted : user_pref("CT2436590.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2436590.ThirdPartyComponentsLastCheck", "Sat Jun 26 2010 13:15:11 GMT-0400 (Eastern Day[…]
Deleted : user_pref("CT2436590.ThirdPartyComponentsLastUpdate", "1276756621");
Deleted : user_pref("CT2436590.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId;=[…]
Deleted : user_pref("CT2436590.UserID", "UN49564811184688627");
Deleted : user_pref("CT2436590.ValidationData_Search", 2);
Deleted : user_pref("CT2436590.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2436590.WeatherNetwork", "");
Deleted : user_pref("CT2436590.WeatherPollDate", "Sun Jul 11 2010 11:27:14 GMT-0400 (Eastern Daylight Time)");
Deleted : user_pref("CT2436590.WeatherUnit", "C");
Deleted : user_pref("CT2436590.alertChannelId", "830740");
Deleted : user_pref("CT2436590.clientLogIsEnabled", true);
Deleted : user_pref("CT2436590.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[…]
Deleted : user_pref("CT2436590.myStuffEnabled", true);
Deleted : user_pref("CT2436590.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2436590.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT2436590.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2436590.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT2436590.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2354614/CT2354614[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2415802/CT2415802[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alert.services.conduit.com/Alerts/AlertServices.asmx/GetHost[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alert.services.conduit.com/Alerts/AlertServices.asmx/GetHost[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alert.services.conduit.com/Alerts/AlertServices.asmx/GetHost[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/749848/745684/CA", "\"0\"")[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/810195/806007/CA", "\"0\"")[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/830740/826544/CA", "\"0\"")[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CA", "\"0\"")[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2354614", […]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2415802", […]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.2[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2354614",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2415802",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut;=0", "63[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut;=3/13/20[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"57d[…]
Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "[removed]");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "[removed]");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://us.yhs.search.yahoo.com/avg/searc[…]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2436590,CT2354614,CT2415802,ConduitEngine");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2436590,CT2354614,CT2415802");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Tue Mar 22 2011 08:58:47 GMT-04[…]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Mar 29 2012 11:11:35 GMT-0400 (Easte[…]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Mar 29 2012 11:11:28 GMT-0400 (Eastern D[…]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "{4e3896a6-a78d-464d-b62f-cd595fff58c1}");
Deleted : user_pref("CommunityToolbar.globalUserId", "af4d9e14-548a-4d1a-b937-bb86814601f8");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2415802");
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Thu Mar 22 2012 17:17:45 GMT-0400 (Eastern Dayl[…]
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Thu Mar 29 2012 11:11:32 GMT-0400 (Eastern Da[…]
Deleted : user_pref("ConduitEngine.FirstServerDate", "03/23/2011 19");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Tue Mar 22 2011 08:58:52 GMT-0400 (Eastern Daylight Time)"[…]
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Thu Mar 29 2012 11:11:32 GMT-0400 (Eastern Day[…]
Deleted : user_pref("ConduitEngine.LastLogin_3.3.2.1", "Sun May 01 2011 08:44:59 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Thu Mar 29 2012 17:52:55 GMT-0400 (Eastern Daylight Ti[…]
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Thu Mar 29 2012 17:52:55 GMT-0400 (Eastern Dayligh[…]
Deleted : user_pref("ConduitEngine.UserID", "UN77916018006028086");
Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Deleted : user_pref("ConduitEngine.engineLocale", "en-GB");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Thu Mar 29 2012 11:11:31 GMT-0400 (Easte[…]
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Thu Mar 29 2012 17:52:55 GMT-0400 (East[…]
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("ConduitEngine.usagesFlag", 2);
Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\FireFoxExt\\14.0.2.14")[…]
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.defaultthis.engineName", "24MusicBar Customized Web Search");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=AB4AD811-7D70-4A3[…]
Deleted : user_pref("[removed]-event-fired", true);
Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "AVG Secure Search");
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://isearch.avg.com/search?cid=%7B33bfe08b-bd8b-4[…]
Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
Deleted : user_pref("extensions.toolbar.mindspark._64Members_.homepage", "hxxp://home.mywebsearch.com/index.jh[…]
Deleted : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb;=AB4AD811[…]

*************************

AdwCleaner[S1].txt - [38525 octets] - [25/01/2013 16:48:59]

########## EOF - C:\AdwCleaner[S1].txt - [38586 octets] ##########











ComboFix 13-01-24.02 - Dorwang 25/01/2013 17:20:07.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.1012.166 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: AVG Anti-Virus Free *Disabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\TelevisionFanatic
c:\program files\TelevisionFanatic\bar\gen1\COMMON.T8S
c:\program files\TelevisionFanatic\bar\IE9Mesg\COMMON.T8S
c:\program files\TelevisionFanatic\bar\Message\COMMON.T8S
c:\program files\TelevisionFanatic\bar\Settings\s_pid.dat
c:\users\Dorwang\AppData\Roaming\Microsoft\Windows\Recent\0707tychungerstrike.url
c:\users\Dorwang\AppData\Roaming\Microsoft\Windows\Recent\Online Phayul Radio - www.phayul.com.url
c:\users\Dorwang\AppData\Roaming\Microsoft\Windows\Recent\Radio Free Asia.url
c:\users\Dorwang\AppData\Roaming\Microsoft\Windows\Recent\You tube.url
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\bootstrap.js
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\chrome.manifest
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\chrome\64ffxtbr.jar
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\install.rdf
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\META-INF\manifest.mf
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\META-INF\zigbert.rsa
c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\extensions\[removed]\META-INF\zigbert.sf
c:\users\Dorwang\KBD32.EXE
c:\users\Dorwang\MS_SCR32.EXE
c:\windows\system32\dlumd10.dll
c:\windows\system32\dlumd11.dll
c:\windows\system32\dlumd9.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-12-25 to 2013-01-25 )))))))))))))))))))))))))))))))
.
.
2013-01-25 22:33 . 2013-01-25 22:35 ——– d—–w- c:\users\Dorwang\AppData\Local\temp
2013-01-25 22:33 . 2013-01-25 22:33 ——– d—–w- c:\users\TEMP\AppData\Local\temp
2013-01-25 22:33 . 2013-01-25 22:33 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-01-25 20:11 . 2013-01-08 04:57 6991832 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BEF8A255-7AAB-472D-B6D9-0B116BF8A4D8}\mpengine.dll
2013-01-24 21:30 . 2013-01-24 21:30 31576 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-01-22 20:04 . 2013-01-22 20:04 15712 —-a-w- c:\program files\Common Files\Windows Live\.cache\bb8d82831cdf8db1f\MeshBetaRemover.exe
2013-01-22 20:03 . 2013-01-22 20:03 94040 —-a-w- c:\program files\Common Files\Windows Live\.cache\995b8ae31cdf8db17\DSETUP.dll
2013-01-22 20:03 . 2013-01-22 20:03 525656 —-a-w- c:\program files\Common Files\Windows Live\.cache\995b8ae31cdf8db17\DXSETUP.exe
2013-01-22 20:03 . 2013-01-22 20:03 1691480 —-a-w- c:\program files\Common Files\Windows Live\.cache\995b8ae31cdf8db17\dsetup32.dll
2013-01-22 20:03 . 2013-01-22 20:03 94040 —-a-w- c:\program files\Common Files\Windows Live\.cache\8daa12c31cdf8db16\DSETUP.dll
2013-01-22 20:03 . 2013-01-22 20:03 525656 —-a-w- c:\program files\Common Files\Windows Live\.cache\8daa12c31cdf8db16\DXSETUP.exe
2013-01-22 20:03 . 2013-01-22 20:03 1691480 —-a-w- c:\program files\Common Files\Windows Live\.cache\8daa12c31cdf8db16\dsetup32.dll
2013-01-22 19:54 . 2013-01-22 19:54 ——– d—–w- c:\users\Dorwang\AppData\Local\Windows Live
2013-01-22 19:51 . 2009-08-04 08:02 754688 —-a-w- c:\windows\system32\webservices.dll
2013-01-10 14:50 . 2013-01-10 14:50 16369160 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-01-09 15:49 . 2012-11-23 01:35 2048000 —-a-w- c:\windows\system32\win32k.sys
2013-01-09 15:49 . 2012-11-20 04:22 204288 —-a-w- c:\windows\system32\ncrypt.dll
2013-01-09 15:48 . 2012-11-02 10:19 1400832 —-a-w- c:\windows\system32\msxml6.dll
2013-01-08 19:31 . 2013-01-25 22:06 ——– d—–w- c:\users\Dorwang\Tracing
2013-01-08 19:23 . 2010-04-28 12:44 54632 —-a-w- c:\windows\system32\drivers\fssfltr.sys
2013-01-08 19:22 . 2013-01-08 19:22 ——– d—–w- c:\program files\Microsoft Sync Framework
2013-01-08 19:20 . 2013-01-08 19:20 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2013-01-08 19:18 . 2013-01-08 19:18 ——– d—–w- c:\program files\Windows Live SkyDrive
2013-01-08 19:17 . 2013-01-08 19:17 83249512 —-a-w- c:\program files\Common Files\Windows Live\.cache\wlc5F20.tmp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-10 14:51 . 2012-04-22 19:48 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 14:51 . 2012-04-22 19:48 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-16 13:12 . 2012-12-26 17:47 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50 . 2012-12-26 17:47 293376 —-a-w- c:\windows\system32\atmfd.dll
2012-12-08 04:30 . 2012-12-08 04:30 1996288 —-a-w- c:\windows\system32\DisplayLinkUsbCo2_7.0.41409.0.dll
2012-12-08 04:30 . 2012-12-08 04:30 21888 —-a-w- c:\windows\system32\drivers\DisplayLinkUsbPort_7.0.41409.0.sys
2012-12-08 04:12 . 2012-12-08 04:13 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-12-08 04:12 . 2010-07-09 16:51 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-12-08 00:07 . 2012-12-07 23:44 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-11-20 08:32 . 2012-12-08 04:39 336248 —-a-w- c:\windows\system32\drivers\dlkmd.sys
2012-11-20 08:32 . 2012-12-08 04:39 15224 —-a-w- c:\windows\system32\drivers\dlkmdldr.sys
2012-11-20 08:31 . 2012-11-20 08:31 1156568 —-a-w- c:\windows\system32\dlumd64.dll
2012-11-20 08:31 . 2012-11-20 08:31 964056 —-a-w- c:\windows\system32\dlumd32.dll
2012-11-20 08:31 . 2012-11-20 08:31 93144 —-a-w- c:\windows\system32\DLTmmB.dll
2012-11-20 08:31 . 2012-11-20 08:31 90584 —-a-w- c:\windows\system32\ManageTMMLifeTime.dll
2012-11-14 02:09 . 2012-12-12 18:56 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58 . 2012-12-12 18:56 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57 . 2012-12-12 18:56 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49 . 2012-12-12 18:56 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48 . 2012-12-12 18:56 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44 . 2012-12-12 18:56 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29 . 2012-12-12 00:43 2048 —-a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18 . 2012-12-12 00:34 376320 —-a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26 . 2012-12-12 00:34 23040 —-a-w- c:\windows\system32\dpnsvr.exe
2013-01-19 15:15 . 2013-01-19 15:14 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-11-05 6174008]
"Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]
"Facebook Update"="c:\users\Dorwang\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-16 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2011-10-17 2042208]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
.
c:\users\Dorwang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\xfire.exe [2008-4-4 2987856]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [x]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 14:52]
.
2013-01-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3889539913-3550952296-1423814129-1000Core.job
- c:\users\Dorwang\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-13 14:50]
.
2013-01-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3889539913-3550952296-1423814129-1000UA.job
- c:\users\Dorwang\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-13 14:50]
.
2013-01-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-03-06 12:08]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://ca.yahoo.com
IE: &Download; All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\program files\FlashGet\jc_link.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Dorwang\AppData\Roaming\Mozilla\Firefox\Profiles\03y78rau.default\
FF - prefs.js: browser.search.defaulturl - hxxp://ca.search.yahoo.com/search?fr=ffsp1&p;=
FF - ExtSQL: !HIDDEN! 2009-07-16 11:13; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-hpqSRMon - (no file)
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-25 17:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-01-25 17:39:48
ComboFix-quarantined-files.txt 2013-01-25 22:39
.
Pre-Run: 143,186,690,048 bytes free
Post-Run: 144,473,759,744 bytes free
.
- - End Of File - - 3265275109186CC0C9E443D8F41C2036
I see that you have both AVG Anti-Virus Free and Lavasoft Ad-Watch Live! Anti-Virus running on your system. You should remove one of them as having more than one antivirus programs running at once can cause serious system slow down and conflicts. You can remove one (whichever you choose) by going to Start >> Control Panel >> Programs and Features. Once one is removed, reboot your system and let me know how everything is running. :)
Hi and welcome back! :)

Once you get my last set of instructions completed in reference to removing one of the antivirus programs, please continue with this….

[external image: Posted Image] I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Thanks jeffce for being patient and understanding. The computer seems to be running quite a bit better. Here is the malwarebytes log Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.07.11 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Dorwang :: DORWANG-PC [administrator] 08/02/2013 10:45:33 PM mbam-log-2013-02-08 (22-45-33).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 236491 Time elapsed: 8 minute(s), 26 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) and the eset results C:\Users\Dorwang\Documents\sunshinegirl_canoe_ca – Today's SUNshine Girl_files\Downloads\Woeser.doc Win32/Exploit.CVE-2012-0158.AC trojan C:\Users\Dorwang\Incomplete\Preview-T-3545425-lungs that cant breathe.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI