This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

problems with system after virus [Closed] [Solved]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

http://www.microsoft.com/security/portal/t…2#symptoms_link

the above virus is one of 2 viruses i had on my system yesterday. windows defender found this and then avg found 2 more. all were removed, i then downloaded avg pc tune up and it removed over 700 items from the registry as well as broken links and lots of other things to speed my system up.

as soon as the virus hit, i had avira on my system, it blocked it initially then the virus killed avira. also at the same time an update to windows defender failed.

now windows defender wont open at all, it gives an error of 0x800106ba but none of the fixes on microsofts site will repair it.

ive tried to do a system restore, but since i was last on this site, my memory for restore points is very small and the oldest restore point was this morning, i tried to restore to that, but it failed with an unknown error.

im worried ive really messed up my system with all the cleaning ive done to it today, i think lots of 'whatever was removed' shouldnt have been removed and shouldve been repaired instead. hope someone can help me get it all sorted.

please talk me thru the processes step by step.

many thanks
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-
thanks for your reply, but im more concerned with what the avg tune up may have removed from my system and any other damage the virus might have caused. when the virus came on board, it not only wiped out avira, it switched my webcam on and diverted me to a bogus website. i now cant open defender, i cant use the restore point and there are possibly other issues caused too. all scans that i run now are clear. ive used superantispyware, kaspersky, microsoft essentials and avg.
I understand your concerns…I have been in your shoes believe me. :) Let's take a look and be sure that all of the viruses are actually removed before we continue with trying to fix damage. It would not be helpful to fix parts of your system when there is still an active infection that could break it again. When you get done with the scans I asked for you to run, be sure to post the logs.
think ive worked out how! halfway thru running the 2nd scan my whole system siezed up again. so im having to redo it. will post results when done. btw thats another problem ive been having since!
oh dear, after rebooting and trying to do the 2nd scan again, it didnt give me the scan button option, so not sure if it has all the results u need or not. here is the file anyway

Attachments:

i uninstalled this after running it, hope that was the right thing to do? # AdwCleaner v2.300 - Logfile created 05/01/2013 at 21:33:57 # Updated 28/04/2013 by Xplode # Operating system : Windows Vista ™ Home Premium Service Pack 2 (32 bits) # User : Lisa - LISA-PC # Boot Mode : Normal # Running from : C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2BVIASL\AdwCleaner[1].exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Program Files\1ClickDownload Folder Found : C:\Program Files\Common Files\AVG Secure Search Folder Found : C:\Program Files\Conduit Folder Found : C:\Users\Lisa\AppData\Local\Conduit Folder Found : C:\Users\Lisa\AppData\Local\PackageAware Folder Found : C:\Users\Lisa\AppData\LocalLow\AVG Security Toolbar Folder Found : C:\Users\Lisa\AppData\LocalLow\Conduit ***** [Registry] ***** Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\DataMngr Key Found : HKCU\Software\IGearSettings Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\Software\AVG Security Toolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\Iminent Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : HKU\S-1-5-21-3225807831-2202106886-1861927024-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKU\S-1-5-21-3225807831-2202106886-1861927024-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.19412 [OK] Registry is clean. -\\ Google Chrome v26.0.1410.64 File : C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Preferences Found [l.24] : icon_url = "hxxp://isearch.avg.com/favicon.ico", Found [l.27] : keyword = "isearch.avg.com", Found [l.30] : search_url = "hxxp://isearch.avg.com/search?cid={D7CBDAF9-8C02-4B7F-9530-FB963A5B6E56}&mid=ff1163bbf3c0a3c9556f6d05d6797b02-76e4b41c324e193ca0c1614c9d7450ff03b13002&lang=en&ds=AVG&pr=fr&d=2012-05-26 21:39:08&v=11.0.0.9&sap=dsp&q={searchTerms}", ************************* AdwCleaner[R1].txt - [6697 octets] - [01/05/2013 21:33:57] ########## EOF - C:\AdwCleaner[R1].txt - [6757 octets] ##########
Since it seems that you had problems with aswMBR let's try this instead…

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Good…

ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
the first link above wouldnt download, it came up with an error. not sure if thats my system or a faulty link? dayam, my system stopped responding again during the scan with the 2nd link. i will try again …. ok having problems with this too, it runs half way then says theres a newer version so i agree to the newer version, it goes back to the scan then disappears. this has happened 3 times now, doesnt seem much point in trying again. what should i do? thanks combofix has just popped up again and said it cant rename combofix as combofix [1] so i clicked ok but again nothing, really bizarre. will try again to open it…im giving up on this, its now creating a restore point, is this planning on changing something on my system if it continues?
Hi, Are you still having problems with the link? It worked just fine for me. If need be, boot to Safe Mode with Networking and download the file and run it from there. Post the log if one is made or let me know what happens if ComboFix won't run.
here is a copy of the log, no idea where its been saved to as it didnt give me an option or any prompts. i must point out though that half way thru the PEV.exe stopped working.

ComboFix 13-05-01.03 - Lisa 03/05/2013 12:12:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2939.1828 [GMT 1:00]
Running from: c:\users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R25G1BRV\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lisa\AppData\Local\temp\ppcrlui_4632_2
c:\windows\system32\pt
c:\windows\system32\pt\smartfacevcp.dll.mui
c:\windows\system32\pt\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Created from 2013-04-03 to 2013-05-03 )))))))))))))))))))))))))))))))
.
.
2013-05-03 11:25 . 2013-05-03 11:35 ——– d—–w- c:\users\Lisa\AppData\Local\temp
2013-05-03 11:25 . 2013-05-03 11:25 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-05-03 11:25 . 2013-05-03 11:25 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-05-03 11:09 . 2013-05-03 11:09 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB27CD8F-819C-40F9-ABC4-28D83ABE0251}\MpKslb2579036.sys
2013-05-02 20:30 . 2013-04-17 05:31 6906960 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB27CD8F-819C-40F9-ABC4-28D83ABE0251}\mpengine.dll
2013-05-01 20:40 . 2013-04-17 05:31 6906960 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-30 12:26 . 2013-04-30 12:26 ——– d—–w- c:\users\Lisa\AppData\Local\ElevatedDiagnostics
2013-04-29 07:54 . 2013-04-29 07:54 ——– d—–w- c:\programdata\WindowsSearch
2013-04-29 07:49 . 2013-04-29 07:49 ——– d—–w- c:\users\Lisa\AppData\Roaming\AVG
2013-04-29 07:46 . 2013-04-29 07:51 ——– d—–w- c:\programdata\AVG
2013-04-29 07:46 . 2013-04-29 07:46 ——– d-sh–w- c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-04-29 07:44 . 2013-04-12 14:49 706640 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A48308B0-33C9-409B-8FB0-189FF59E395F}\gapaengine.dll
2013-04-29 07:40 . 2013-04-29 22:10 ——– d—–w- c:\program files\Microsoft Security Client
2013-04-28 21:48 . 2013-04-10 03:08 6906960 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC7DF4D1-C904-491A-91B4-BFC26F82D36D}\mpengine.dll
2013-04-28 21:34 . 2013-04-28 21:34 ——– d—–w- c:\programdata\Kaspersky Lab
2013-04-28 21:10 . 2013-04-28 21:10 ——– d—–w- c:\programdata\AVG SafeGuard toolbar
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\users\Lisa\AppData\Local\AVG SafeGuard toolbar
2013-04-28 21:09 . 2013-04-28 21:09 34592 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\program files\AVG SafeGuard toolbar
2013-04-28 21:06 . 2013-04-28 21:06 ——– d—–w- C:\$AVG
2013-04-28 20:58 . 2013-04-28 21:15 ——– d—–w- c:\users\Lisa\AppData\Local\Avg2013
2013-04-28 20:58 . 2013-04-28 20:58 ——– d—–w- c:\users\Lisa\AppData\Local\MFAData
2013-04-28 20:36 . 2013-04-28 20:36 ——– d—–w- c:\programdata\rwcrf
2013-04-21 14:13 . 2013-04-21 14:13 ——– d—–w- C:\found.000
2013-04-10 09:57 . 2013-03-03 19:07 1082232 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 09:55 . 2013-03-11 13:25 3603816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 09:55 . 2013-03-11 13:25 3551080 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 09:55 . 2013-03-09 03:45 49152 —-a-w- c:\windows\system32\csrsrv.dll
2013-04-10 09:55 . 2013-03-09 01:28 64000 —-a-w- c:\windows\system32\smss.exe
2013-04-10 09:52 . 2013-03-08 03:52 2067968 —-a-w- c:\windows\system32\mstscax.dll
2013-04-10 09:51 . 2013-03-08 03:53 376320 —-a-w- c:\windows\system32\winsrv.dll
2013-04-10 09:49 . 2013-03-05 01:40 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-04-09 22:09 . 2013-04-09 22:09 ——– d—–w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 10:54 . 2012-08-13 15:33 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-13 10:54 . 2011-06-04 07:44 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-12 00:10 . 2009-10-03 09:47 237088 ——w- c:\windows\system32\MpSigStub.exe
2013-03-06 23:32 . 2013-03-27 14:46 228600 —-a-w- c:\windows\system32\aswBoot.exe
2013-03-01 09:32 . 2013-03-01 09:32 22328 —-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-02-26 22:40 . 2013-02-26 22:40 208184 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-02-14 02:52 . 2013-02-14 02:52 182072 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-02-12 01:57 . 2013-03-21 18:53 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-08 03:37 . 2013-02-08 03:37 96568 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2013-02-08 03:37 . 2013-02-08 03:37 245048 —-a-w- c:\windows\system32\drivers\avglogx.sys
2013-02-08 03:37 . 2013-02-08 03:37 60216 —-a-w- c:\windows\system32\drivers\avgidshx.sys
2013-02-08 03:37 . 2013-02-08 03:37 170808 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2013-02-08 03:37 . 2013-02-08 03:37 39224 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-04-28 21:09 1966768 —-a-w- c:\program files\AVG SafeGuard toolbar\15.1.0.2\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.1.0.2\AVG SafeGuard toolbar_toolbar.dll" [2013-04-28 1966768]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-19 138096]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-03-01 18643560]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-20 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-03-13 4394032]
"vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2013-04-28 1223344]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-12-06 16:12 1029416 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - FSUSBEXDISK
*NewlyCreated* - MPKSLB2579036
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-09 20:28 1642448 —-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-13 10:54]
.
2013-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3225807831-2202106886-1861927024-1000Core.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-06 11:00]
.
2013-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3225807831-2202106886-1861927024-1000UA.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-06 11:00]
.
2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:06]
.
2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://uk.msn.com
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1 0.0.0.0
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.1.0\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-03 12:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-05-03 12:38:03
ComboFix-quarantined-files.txt 2013-05-03 11:38
.
Pre-Run: 94,218,997,760 bytes free
Post-Run: 94,481,317,888 bytes free
.
- - End Of File - - 0F05BADD8DF302FD847247C8AB2660CD
Hi,

Good job and thanks for letting me know about PEV.exe stopping. :)

I notice that you have both AVG and Microsoft Security Essentials (MSE) running at the same time. Having more than one antivirus program running at the same time can seriously degrade the performance of your system. Please uninstall either AVG or MSE (which ever you prefer) using either the provided uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel). As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.
—————

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-

Post the newly made log and let me know how your system is running. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI