This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus: White Smoke Toolbar (aka WhiteSmoke) [Solved]

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last eve I was shown a message from this site:
http://www.mplayertotal.com/flashplayer/up…p?uid=107404113

. . . telling that I had to update my flashplayer in order to view the site. Although the site seemed less than legit, [i.e. not a flashplayer site] much of the "update process" did appear legit. Turns out it this had NOTHING to do with updating ANYTHING! :angry:

The result was that my machine had "VAFPlayer" installed as well as the "White Smoke Toolbar"
I can no longer do a System Restore to any previous date before this virus May 5, 2013

1- I cannot do System Restore
2- I can no longer run picture manager [see attachment] πŸ“ŽPic_Manager.PNG
3- The "Always use selected program" check box will not stay checked [see attachment] πŸ“ŽNot_checked.PNG

4- Q: Is sweetpacks valid or is it garbage?
SweetPacks (i.e. start.sweetpacks.com : Line O23 - Service: Updater By SweetPacks in HijackThis Log)


OS = XP

Here is my "hijack This"
==============================================================
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:41:07 AM, on 5/5/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\SearchProtect\bin\CltMngSvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Documents and Settings\pete\Application Data\SearchProtect\bin\cltmng.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
E:\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&…;ctid=CT3289847
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st…D-001D92B44399}
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Javaβ„’ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Updater By SweetPacks Helper - {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD} - C:\Program Files\Updater By SweetPacks\Extension32.dll
O2 - BHO: Javaβ„’ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [EaseUS EPM tray] C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WordWeb] "C:\Program Files\WordWeb\wweb32.exe" -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /1
O4 - HKCU\..\Run: [SearchProtect] C:\Documents and Settings\pete\Application Data\SearchProtect\bin\cltmng.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Updater By SweetPacks - Unknown owner - C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe (file missing)

–
End of file - 7919 bytes
Hello peteinmaine. Posted Image

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
  • Please be patient. Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed all clear.
  • Please reply within 3 days of each post to avoid closing this topic.
Hello fbfbfb,
Thank you. I await your reply with patience.
Cheers :)
peteinmaine
Hello, peteinmaine.

Thank you for the HJT log. I would like to take a closer look at your system.

Please run the following scans

1. DDS

Please download DDS from HERE and save it to your desktop.Please copy and paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]

3. Security Check

Please download Security Check from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt. This may take a few minutes.
Please copy and paste the contents of that document into your next reply.
Hello fbfbfb,

After running DDS, please note:
Your instructions appear to need updating, as they do not appear to coincide with the current prompts.

β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”-

Per your request, please find C/P to follow:
1. dds.txt
3. checkup.txt


Attachment:
2.attach.txt


=============================================================================
πŸ“Žattach.txt

=============================================================================
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.21.2
Run by [removed] at 21:16:09 on 2013-05-07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.808 [GMT -4:00]
.
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\pete\Application Data\SearchProtect\bin\cltmng.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\SearchProtect\bin\CltMngSvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Java\jre7\bin\javaw.exe
C:\Program Files\Java\jre7\bin\java.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN11054928771329222&UM=2&ctid=CT3289847
mStart Page = hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={9B779BA9-97F5-11E2-96BD-001D92B44399}
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Javaβ„’ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Updater By SweetPacks: {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD} - c:\program files\updater by sweetpacks\Extension32.dll
BHO: Javaβ„’ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SweetPacks Browser Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: SweetPacks Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: SweetPacks Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Washer] c:\program files\washer\washer.exe /1
uRun: [SearchProtect] c:\documents and settings\pete\application data\searchprotect\bin\cltmng.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [EaseUS EPM tray] c:\program files\easeus\easeus partition master 9.2.1 home edition\bin\EpmNews.exe
mRun: [KONICA MINOLTA magicolor 2400W STD] c:\windows\system32\MSTMON_S.EXE STARTUP
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WordWeb] "c:\program files\wordweb\wweb32.exe" -startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SearchProtectAll] c:\program files\searchprotect\bin\cltmng.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1358997859234
TCP: NameServer = 192.168.1.1 209.18.47.61 209.18.47.62
TCP: Interfaces\{AB62BAA6-55AC-4A79-AEAB-B2300EAE6EFA} : DHCPNameServer = 192.168.1.1 [removed] [removed]
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\pete\application data\mozilla\firefox\profiles\noiovjdh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN42265594992454012&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/|https://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN42265594992454012&UM=2&q=
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_169.dll
FF - ExtSQL: 2013-03-28 18:20; {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}; c:\program files\updater by sweetpacks\Firefox
.
β€”- FIREFOX POLICIES β€”-
FF - user.js: extensions.searchya.hmpg - true
FF - user.js: extensions.searchya.hmpgUrl - hxxp://www.searchya.com/?f=1&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=
FF - user.js: extensions.searchya.dfltSrch - true
FF - user.js: extensions.searchya.srchPrvdr - SearchYa!
FF - user.js: extensions.searchya.dnsErr - true
FF - user.js: extensions.searchya_i.newTab - false
FF - user.js: extensions.searchya.newTabUrl - hxxp://www.searchya.com/?f=2&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=
FF - user.js: extensions.searchya.tlbrSrchUrl - hxxp://www.searchya.com/?f=3&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=&q=
FF - user.js: extensions.searchya.id - 001D92B443995232
FF - user.js: extensions.searchya.instlDay - 15752
FF - user.js: extensions.searchya.vrsn - [removed]
FF - user.js: extensions.searchya.vrsni - [removed]
FF - user.js: extensions.searchya_i.vrsnTs - 1.8.8.013:9:49
FF - user.js: extensions.searchya.prtnrId - searchya
FF - user.js: extensions.searchya.prdct - searchya
FF - user.js: extensions.searchya.aflt - dnldyho
FF - user.js: extensions.searchya_i.smplGrp - none
FF - user.js: extensions.searchya.tlbrId - base
FF - user.js: extensions.searchya.instlRef -
FF - user.js: extensions.searchya.dfltLng -
FF - user.js: extensions.searchya.appId - {1973277F-87B0-4EA3-9ED2-470A91D284CF}
FF - user.js: extensions.searchya.excTlbr - false
FF - user.js: extensions.searchya_i.hmpg - true
FF - user.js: extensions.irspeeddial.aflt - dnldyho
FF - user.js: extensions.irspeeddial.instlRef -
FF - user.js: extensions.irspeeddial.cr - 2135847891
FF - user.js: extensions.irspeeddial.cd - 2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2XzutBtFtBtF
tCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 60216]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 245048]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-16 96568]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 39224]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 208184]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 22328]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 170808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 182072]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2013-2-27 4937264]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2013-2-19 282624]
R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\searchprotect\bin\CltMngSvc.exe [2013-4-11 93984]
R2 Updater By SweetPacks;Updater By SweetPacks;c:\program files\updater by sweetpacks\ExtensionUpdaterService.exe [2013-3-28 188760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2013-1-23 103040]
S1 avgtp;avgtp;\??\c:\windows\system32\drivers\avgtpx86.sys –> c:\windows\system32\drivers\avgtpx86.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 MLPTDR_Q;MLPTDR_Q;c:\windows\system32\MLPTDR_Q.SYS [2004-11-18 18848]
S2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\14.2.0\toolbarupdater.exe –> c:\program files\common files\avg secure search\vtoolbarupdater\14.2.0\ToolbarUpdater.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2013-1-23 1691480]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2013-1-26 13896]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2013-1-26 9160]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
ShellExec: EasyShare.exe: Preview="c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe"
.
=============== Created Last 30 ================
.
2013-05-05 01:44:15 ——– d—–w- c:\program files\Tuguu SL
2013-05-05 01:44:15 ——– d—–w- c:\documents and settings\pete\application data\player
2013-05-05 01:40:53 ——– d—–w- c:\documents and settings\pete\application data\SwvUpdater
2013-05-05 01:40:11 ——– d—–w- c:\program files\Conduit
2013-05-05 01:40:04 ——– d—–w- c:\documents and settings\pete\local settings\application data\Conduit
2013-05-05 01:40:03 ——– d—–w- c:\documents and settings\pete\local settings\application data\Temp
2013-05-05 01:39:17 ——– d—–w- c:\documents and settings\pete\local settings\application data\CRE
2013-05-05 01:38:31 ——– d—–w- c:\program files\SearchProtect
2013-05-05 01:38:16 ——– d—–w- c:\documents and settings\pete\application data\SearchProtect
2013-04-20 14:23:32 275696 β€”-a-w- c:\windows\system32\mucltui.dll
2013-04-20 14:23:32 214256 β€”-a-w- c:\windows\system32\muweb.dll
2013-04-20 14:23:32 17136 β€”-a-w- c:\windows\system32\mucltui.dll.mui
2013-04-19 10:37:03 94112 β€”-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-15 20:07:26 ——– d—–w- c:\documents and settings\pete\.swt
.
==================== Find3M ====================
.
2013-04-19 09:58:07 71048 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-19 09:58:07 691592 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-24 11:24:31 1409 β€”-a-w- c:\windows\QTFont.for
2013-03-08 08:36:22 293376 β€”-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:32:25 2149888 β€”-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50:30 2028544 β€”-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-06 10:28:48 861088 β€”-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-06 10:28:48 782240 β€”-a-w- c:\windows\system32\deployJava1.dll
2013-03-02 02:06:31 916480 β€”-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:06:30 43520 β€”β€”w- c:\windows\system32\licmgr10.dll
2013-03-02 02:06:30 1469440 β€”β€”w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:25:02 1867264 β€”-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08:47 385024 β€”β€”w- c:\windows\system32\html.iec
2013-03-01 14:32:20 22328 β€”-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-02-27 07:56:51 2067456 β€”-a-w- c:\windows\system32\mstscax.dll
2013-02-27 03:40:46 208184 β€”-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-02-14 07:52:46 182072 β€”-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-02-12 00:32:23 12928 β€”-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-12 00:32:23 12928 β€”β€”w- c:\windows\system32\drivers\usb8023x.sys
2013-02-08 08:37:56 245048 β€”-a-w- c:\windows\system32\drivers\avglogx.sys
2013-02-08 08:37:52 60216 β€”-a-w- c:\windows\system32\drivers\avgidshx.sys
2013-02-08 08:37:44 170808 β€”-a-w- c:\windows\system32\drivers\avgldx86.sys
2013-02-08 08:37:40 39224 β€”-a-w- c:\windows\system32\drivers\avgrkx86.sys
.
============= FINISH: 21:16:33.81 ===============



=============================================================================
Results of screen317's Security Check version 0.99.63
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 21
Adobe Flash Player 11.7.700.169
Adobe Reader XI
Mozilla Firefox (20.0.1)
Google Chrome 26.0.1410.43
Google Chrome 26.0.1410.64
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 14% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Hello, peteinmaine.

Thank you for the DDS and Security Check reports. Your logs indicate there is a lot of garbage on your machine that needs to be removed. Let's begin with the following scan:

ComboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts. ComboFix will automatically check to see if the Microsoft Windows Recovery Console is installed.

Note:

  • If Combofix asks you to install the Microsoft Windows Recovery Console, please allow it.
  • If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • When prompted, agree to the End-User License Agreement to begin installation.
  • If ComboFix asks you to update the program, please do so.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.
Hello fbfbfb,

I did select "Temporarily disable AVG protection" followed by "Disable AVG till restart".
I then reviewed AVG to find that it actually displayed a disabled status.
However, apparently Combofix still saw Avg's status:
"AVG AntiVirus Free Edition 2013 *Enabled/Updated*


AVG has been re-enabled.

I question weather AVG was sufficiently disabled for this application. Please advise.

Combox log to follow:
=============================================================================

ComboFix 13-05-09.01 - pete 05/09/2013 19:43:11.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1443 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\pete\WINDOWS
c:\windows\system32\Cache
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\66841418b8d87230.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d0175e9022bb6d3.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\7ce169baee355d66.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
.
.
((((((((((((((((((((((((( Files Created from 2013-04-09 to 2013-05-09 )))))))))))))))))))))))))))))))
.
.
2013-05-05 01:44 . 2013-05-05 01:44 ——– d—–w- c:\program files\Tuguu SL
2013-05-05 01:44 . 2013-05-05 01:44 ——– d—–w- c:\documents and settings\pete\Application Data\player
2013-05-05 01:40 . 2013-05-05 01:40 ——– d—–w- c:\documents and settings\pete\Application Data\SwvUpdater
2013-05-05 01:40 . 2013-05-05 01:40 ——– d—–w- c:\program files\Conduit
2013-05-05 01:40 . 2013-05-05 03:32 ——– d—–w- c:\documents and settings\pete\Local Settings\Application Data\Conduit
2013-05-05 01:40 . 2013-05-05 01:40 ——– d—–w- c:\documents and settings\pete\Local Settings\Application Data\Temp
2013-05-05 01:39 . 2013-05-05 01:39 ——– d—–w- c:\documents and settings\pete\Local Settings\Application Data\CRE
2013-05-05 01:38 . 2013-05-05 01:38 ——– d—–w- c:\program files\SearchProtect
2013-05-05 01:38 . 2013-05-05 01:38 ——– d—–w- c:\documents and settings\pete\Application Data\SearchProtect
2013-04-20 14:23 . 2012-06-02 19:18 275696 β€”-a-w- c:\windows\system32\mucltui.dll
2013-04-20 14:23 . 2012-06-02 19:18 214256 β€”-a-w- c:\windows\system32\muweb.dll
2013-04-20 00:54 . 2013-04-20 00:54 ——– d—–w- c:\program files\Microsoft Silverlight
2013-04-19 10:37 . 2013-04-19 10:37 ——– d—–w- c:\program files\Common Files\Java
2013-04-19 10:37 . 2013-04-04 09:35 94112 β€”-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-15 20:07 . 2013-04-15 20:07 ——– d—–w- c:\documents and settings\pete\.swt
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-19 09:58 . 2013-01-27 03:30 71048 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-19 09:58 . 2013-01-27 03:30 691592 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-24 11:24 . 2013-03-24 11:24 1409 β€”-a-w- c:\windows\QTFont.for
2013-03-08 08:36 . 2001-08-23 12:00 293376 β€”-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:32 . 2001-08-23 12:00 2149888 β€”-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2001-08-17 13:48 2028544 β€”-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-06 10:28 . 2013-01-26 19:23 861088 β€”-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-06 10:28 . 2013-01-26 19:23 782240 β€”-a-w- c:\windows\system32\deployJava1.dll
2013-03-02 02:06 . 2013-01-24 02:51 916480 β€”-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:06 . 2013-01-24 02:52 1469440 β€”β€”w- c:\windows\system32\inetcpl.cpl
2013-03-02 02:06 . 2013-01-24 02:52 43520 β€”β€”w- c:\windows\system32\licmgr10.dll
2013-03-02 01:25 . 2001-08-23 12:00 1867264 β€”-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2013-01-24 03:06 385024 β€”β€”w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2013-01-24 02:51 2067456 β€”-a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2013-01-24 03:04 12928 β€”β€”w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2001-08-23 12:00 12928 β€”-a-w- c:\windows\system32\drivers\usb8023.sys
2013-04-11 22:03 . 2013-04-11 22:03 263064 β€”-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Washer"="c:\program files\Washer\washer.exe" [2003-01-13 818688]
"SearchProtect"="c:\documents and settings\pete\Application Data\SearchProtect\bin\cltmng.exe" [2013-04-11 2730784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2013-01-24 20117648]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-29 98304]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"EaseUS EPM tray"="c:\program files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe" [2012-11-29 2086984]
"KONICA MINOLTA magicolor 2400W STD"="c:\windows\system32\MSTMON_S.EXE" [2005-06-22 184320]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
"WordWeb"="c:\program files\WordWeb\wweb32.exe" [2012-04-21 77064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2013-02-03 77824]
"SearchProtectAll"="c:\program files\SearchProtect\bin\cltmng.exe" [2013-04-11 2730784]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-7-22 151552]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\FrostWire 5\\FrostWire.exe"=
"c:\\Program Files\\FVD Suite\\FVD Downloader\\FVD Downloader.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgemcx.exe"=
.
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/2/2012 4:30 AM 170808]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [2/19/2013 4:02 AM 282624]
R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\SearchProtect\bin\CltMngSvc.exe [4/11/2013 10:28 AM 93984]
R2 Updater By SweetPacks;Updater By SweetPacks;c:\program files\Updater By SweetPacks\ExtensionUpdaterService.exe [3/28/2013 6:20 PM 188760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [1/23/2013 11:21 PM 103040]
S1 avgtp;avgtp;\??\c:\windows\system32\drivers\avgtpx86.sys –> c:\windows\system32\drivers\avgtpx86.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [2/27/2013 11:42 PM 4937264]
S2 MLPTDR_Q;MLPTDR_Q;c:\windows\system32\MLPTDR_Q.SYS [11/18/2004 10:13 PM 18848]
S2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe –> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1/23/2013 11:12 PM 1691480]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [1/26/2013 1:15 PM 13896]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [1/26/2013 1:15 PM 9160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 04:52 1642448 β€”-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-27 09:58]
.
2013-05-09 c:\windows\Tasks\AmiUpdXp.job
- c:\documents and settings\pete\Application Data\SwvUpdater\Updater.exe [2013-05-05 01:37]
.
2013-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-26 16:41]
.
2013-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-26 16:41]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN11054928771329222&UM=2&ctid=CT3289847
mStart Page = hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={9B779BA9-97F5-11E2-96BD-001D92B44399}
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pete\Application Data\Mozilla\Firefox\Profiles\noiovjdh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN42265594992454012&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/|https://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN42265594992454012&UM=2&q=
FF - ExtSQL: 2013-03-28 18:20; {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}; c:\program files\Updater By SweetPacks\Firefox
FF - user.js: extensions.searchya.hmpg - true
FF - user.js: extensions.searchya.hmpgUrl - hxxp://www.searchya.com/?f=1&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=
FF - user.js: extensions.searchya.dfltSrch - true
FF - user.js: extensions.searchya.srchPrvdr - SearchYa!
FF - user.js: extensions.searchya.dnsErr - true
FF - user.js: extensions.searchya_i.newTab - false
FF - user.js: extensions.searchya.newTabUrl - hxxp://www.searchya.com/?f=2&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=
FF - user.js: extensions.searchya.tlbrSrchUrl - hxxp://www.searchya.com/?f=3&a=dnldyho&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F&cr=2135847891&ir=&q=
FF - user.js: extensions.searchya.id - 001D92B443995232
FF - user.js: extensions.searchya.instlDay - 15752
FF - user.js: extensions.searchya.vrsn - [removed]
FF - user.js: extensions.searchya.vrsni - [removed]
FF - user.js: extensions.searchya_i.vrsnTs - 1.8.8.013:9:49
FF - user.js: extensions.searchya.prtnrId - searchya
FF - user.js: extensions.searchya.prdct - searchya
FF - user.js: extensions.searchya.aflt - dnldyho
FF - user.js: extensions.searchya_i.smplGrp - none
FF - user.js: extensions.searchya.tlbrId - base
FF - user.js: extensions.searchya.instlRef -
FF - user.js: extensions.searchya.dfltLng -
FF - user.js: extensions.searchya.appId - {1973277F-87B0-4EA3-9ED2-470A91D284CF}
FF - user.js: extensions.searchya.excTlbr - false
FF - user.js: extensions.searchya_i.hmpg - true
FF - user.js: extensions.irspeeddial.aflt - dnldyho
FF - user.js: extensions.irspeeddial.instlRef -
FF - user.js: extensions.irspeeddial.cr - 2135847891
FF - user.js: extensions.irspeeddial.cd - 2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2XzutBtFtBtF
tCtFyEyBzztN1L1Czu1Q1G1I1Q2U1M1F
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-09 19:45
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€”
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”
.
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2013-05-09 19:46:49
ComboFix-quarantined-files.txt 2013-05-09 23:46
.
Pre-Run: 45,094,494,208 bytes free
Post-Run: 45,177,384,960 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - B6FA56EC44C432147EE4B5C6FE3DA47A
Hello, peteinmaine.

We ask that you disable any security programs to avoid potential interference when running a scan. ComboFix seems to have run well, and the log looks complete, so we won't worry about your AVG not disabling. Let's begin to clean up the garbage on your system.

Please run the following scans

1. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

2. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

In your next reply, please let me know how your computer is running after the scans.
Hello fbfbfb,

Re: "In your next reply, please let me know how your computer is running after the scans."

A- Upon restarting my browser, I have encountered this error. :huh: However, it appears that the only setting affected was my startup pages which I have now reset.
πŸ“ŽGoogle_error.PNG



B- Picture manager continues to be a problem.
πŸ“ŽPic_Manager.PNG


C- The "Always use selected program" check box continues to not stay checked
πŸ“ŽNot_checked.PNG



Please find to follow:
1- JRT.txt
2- AdwCleaner[S1].txt

=============================================================================
JRT.txt
=============================================================================


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Microsoft Windows XP x86
Ran by [removed] on Sat 05/11/2013 at 19:02:24.75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] cltmngsvc
Successfully deleted: [Service] cltmngsvc
Successfully stopped: [Service] updater by sweetpacks
Successfully deleted: [Service] updater by sweetpacks



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotect
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-789336058-115176313-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\esrv.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\extension.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.searchyaesrvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.searchyaesrvc.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3289847
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E51F5A47-76D4-4D18-8083-9755F883C823}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_local_machine\software\pip"



~~~ Files

Successfully deleted: [File] "C:\end"



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\strongvault online backup"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\sweetim"
Successfully deleted: [Folder] "C:\Documents and Settings\pete\Application Data\searchprotect"
Successfully deleted: [Folder] "C:\Documents and Settings\pete\Application Data\swvupdater"
Successfully deleted: [Folder] "C:\Documents and Settings\pete\Local Settings\Application Data\conduit"
Successfully deleted: [Folder] "C:\Documents and Settings\pete\Local Settings\Application Data\updater21804"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\coupon companion plugin"
Successfully deleted: [Folder] "C:\Program Files\searchprotect"
Successfully deleted: [Folder] "C:\Program Files\sweetim"
Successfully deleted: [Folder] "C:\Program Files\updater by sweetpacks"
Successfully deleted: [Folder] "C:\WINDOWS\system32\ai_recyclebin"
Successfully deleted: [Folder] "C:\ai_recyclebin"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\ask"



~~~ FireFox

Successfully deleted: [File] C:\Documents and Settings\pete\Application Data\mozilla\firefox\profiles\noiovjdh.default\user.js
Successfully deleted: [Folder] C:\Documents and Settings\pete\Application Data\mozilla\firefox\profiles\noiovjdh.default\smartbar
Successfully deleted: [Folder] C:\Documents and Settings\pete\Application Data\mozilla\firefox\profiles\noiovjdh.default\extensions\[removed]
Successfully deleted: [Folder] C:\Documents and Settings\pete\Application Data\mozilla\firefox\profiles\noiovjdh.default\extensions\staged
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}
Successfully deleted the following from C:\Documents and Settings\pete\Application Data\mozilla\firefox\profiles\noiovjdh.default\prefs.js

user_pref("CT3289847.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN42265594992454012&UM;=2&q;=");
user_pref("CT3289847.embeddedsData", "[{\"appId\":\"130068661007799818\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT3289847.installType", "conduitnsisintegration");
user_pref("CT3289847.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3289847&octid;=CT3289847&SearchSource;=15&CUI;=UN4226559499245401
user_pref("CT3289847.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHV
pdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnN
user_pref("CT3289847.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fsearch.conduit.com%2F%3Fctid%3DCT3289847%26octid%3DCT3289847%26SearchSource%3D15%26CUI%3DUN
user_pref("CT3289847.search.searchAppId", "130068661007799818");
user_pref("CT3289847.search.searchCount", "0");
user_pref("CT3289847.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://WhiteSmokeNew.OurToolbar.com//xpi\"}");
user_pref("CT3289847.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"WhiteSmoke New\"}");
user_pref("CT3289847.smartbar.CTID", "CT3289847");
user_pref("CT3289847.smartbar.Uninstall", "0");
user_pref("CT3289847.smartbar.homepage", "true");
user_pref("CT3289847.smartbar.toolbarName", "WhiteSmoke New ");
user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN42265594992454012&UM;=2&SearchSource;=13");
user_pref("Smartbar.ConduitSearchEngineList", "WhiteSmoke New Customized Web Search");
user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN42265594992454012&UM;=2&q;=");
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
user_pref("Smartbar.keywordURLSelectedCTID", "CT3289847");
user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search");
user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN42265594992454012&UM;=2&SearchSource;=3&q;={searchTerms}");
user_pref("browser.search.selectedEngine", "WhiteSmoke New Customized Web Search");
user_pref("extensions.crossrider.bic", "13c81e1381c1a387daad6be32efc5d3c");
user_pref("extensions.crossriderapp21804.21804.InstallationTime", 1359388686);
user_pref("extensions.crossriderapp21804.21804.active", true);
user_pref("extensions.crossriderapp21804.21804.addressbar", "");
user_pref("extensions.crossriderapp21804.21804.addressbarenhanced", "");
user_pref("extensions.crossriderapp21804.21804.backgroundjs", "\n\n//\n");
user_pref("extensions.crossriderapp21804.21804.backgroundver", 32);
user_pref("extensions.crossriderapp21804.21804.can_run_bg_code", true);
user_pref("extensions.crossriderapp21804.21804.certdomaininstaller", "");
user_pref("extensions.crossriderapp21804.21804.changeprevious", false);
user_pref("extensions.crossriderapp21804.21804.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie.InstallationTime.value", "1359388686");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_aoi.value", "1359388686");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_arbitrary_code.expiration", "Fri Mar 08 2013 08:03:21 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_arbitrary_code.value", "%22%28function%28%29%7B_GPL_PLUGIN.st%3D%7B%5C%22141539%26pid%3D1382%5C%22%3A%7Bs%3A%5B%5C%2
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_blocklist.expiration", "Fri Mar 08 2013 08:03:21 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_blocklist.value", "%22nonexistantdomain.com%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_cf_bu1.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_cf_bu1.value", "1361280238");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_country_code.expiration", "Wed Mar 13 2013 03:55:27 GMT-0400 (Eastern Daylight Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_country_code.value", "%22US%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_crr.value", "1362747533");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_currenttime.value", "%221362693789%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_hotfix20111102645.expiratio
n", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_hotfix20111102645.value", "%221%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%22100086%22%2C%22sub_id%22%3A%22default%22%2C%22uzid%22%3A%22100086%
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_installtime.value", "%221359242007%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_parent_zoneid.value", "%2214019%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_pc_20120828.value", "1359388702219");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_product_id.value", "%221175%22");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_sr[hrblock.com].expiration", "Sat Mar 09 2013 07:18:02 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_sr[hrblock.com].value", "1362745082");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_sr[xdating.com].expiration", "Fri Mar 08 2013 16:15:39 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_sr[xdating.com].value", "1362690939");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_zoneid.value", "%22136821%22");
user_pref("extensions.crossriderapp21804.21804.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie.dbtest.value", "1359388692903");
user_pref("extensions.crossriderapp21804.21804.description", "Coupon Companion");
user_pref("extensions.crossriderapp21804.21804.domain", "");
user_pref("extensions.crossriderapp21804.21804.enablesearch", false);
user_pref("extensions.crossriderapp21804.21804.fbremoteurl", "");
user_pref("extensions.crossriderapp21804.21804.group", 0);
user_pref("extensions.crossriderapp21804.21804.homepage", "");
user_pref("extensions.crossriderapp21804.21804.iframe", false);
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_appVer.value", "46");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_lastVersion.expira
tion", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_nextCheck.expirati
on", "Fri Mar 08 2013 13:17:49 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_remote_resources.e
xpiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_remote_resources.v
alue", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.crossriderapp21804.21804.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.started||_GPL_PLUGIN.prepare({pid:1175,baseCDN:
user_pref("extensions.crossriderapp21804.21804.manifesturl", "");
user_pref("extensions.crossriderapp21804.21804.name", "Coupon Companion Plugin");
user_pref("extensions.crossriderapp21804.21804.newtab", "");
user_pref("extensions.crossriderapp21804.21804.opensearch", "");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return ap
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.name", "base");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.ver", 4);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=function(B){if(void 0===this||null===this)throw
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.ver", 15);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{},rules:{},started:!1,allowed:!1,log:function(
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.name", "GPL Background (BG)");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.ver", 34);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelect
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.name", "CrossriderAppUtils");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==\"undefined
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.name", "CrossriderUtils");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!=true)&&(typeof _firefoxVersion!==\"undefined\"&
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.name", "FFAppAPIWrapper");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.ver", 5);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1.4.2\n * hxxp://jquery.com/\n
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.name", "jQuery");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.d
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.name", "debug");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(B){this.queue.push(B);}};appAPI.ready=fun
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.name", "resources");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferre
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.name", "initializer");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document && typeof document.getElementById !== \"unde
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.name", "jquery_1_7_1");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.name", "resources_background");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function(j){return(typeof j===\"object\"&&j;!==null);}
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.name", "appApiMessage");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(function(){var k={};var f=appAPI.appInfo.name;var l=
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.name", "appApiValidation");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof; navigator!==\"undefined\"&&typeof; navigator.userAge
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.name", "CrossriderInfo");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_0", "4,14,78,16,64,47,72,1000015");
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,1000014,28");
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
user_pref("extensions.crossriderapp21804.21804.pluginsurl", "hxxp://app-static.crossrider.com/plugin/apps/21804/plugins/088/ff/plugins.json");
user_pref("extensions.crossriderapp21804.21804.pluginsversion", 43);
user_pref("extensions.crossriderapp21804.21804.publisher", "215 Apps");
user_pref("extensions.crossriderapp21804.21804.searchstatus", 0);
user_pref("extensions.crossriderapp21804.21804.setnewtab", false);
user_pref("extensions.crossriderapp21804.21804.settingsurl", "");
user_pref("extensions.crossriderapp21804.21804.thankyou", "");
user_pref("extensions.crossriderapp21804.21804.updateinterval", 360);
user_pref("extensions.crossriderapp21804.21804.ver", 46);
user_pref("extensions.crossriderapp21804.adsOldValue", -1);
user_pref("extensions.crossriderapp21804.apps", "21804");
user_pref("extensions.crossriderapp21804.bic", "13c81e1381c1a387daad6be32efc5d3c");
user_pref("extensions.crossriderapp21804.cid", 21804);
user_pref("extensions.crossriderapp21804.firstrun", false);
user_pref("extensions.crossriderapp21804.hadappinstalled", true);
user_pref("extensions.crossriderapp21804.installationdate", 1359388686);
user_pref("extensions.crossriderapp21804.lastcheck", 22712418);
user_pref("extensions.crossriderapp21804.lastcheckitem", 22712514);
user_pref("extensions.crossriderapp21804.modetype", "production");
user_pref("extensions.crossriderapp21804.reportInstall", true);
user_pref("extensions.searchya.aflt", "dnldyho");
user_pref("extensions.searchya.appId", "{1973277F-87B0-4EA3-9ED2-470A91D284CF}");
user_pref("extensions.searchya.dfltLng", "");
user_pref("extensions.searchya.dfltSrch", true);
user_pref("extensions.searchya.dnsErr", true);
user_pref("extensions.searchya.excTlbr", false);
user_pref("extensions.searchya.hmpg", true);
user_pref("extensions.searchya.hmpgUrl", "hxxp://www.searchya.com/?f=1&a;=dnldyho&cd;=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBzzt
user_pref("extensions.searchya.id", "001D92B443995232");
user_pref("extensions.searchya.instlDay", "15752");
user_pref("extensions.searchya.instlRef", "");
user_pref("extensions.searchya.newTabUrl", "hxxp://www.searchya.com/?f=2&a;=dnldyho&cd;=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEyBz
user_pref("extensions.searchya.prdct", "searchya");
user_pref("extensions.searchya.prtnrId", "searchya");
user_pref("extensions.searchya.srchPrvdr", "SearchYa!");
user_pref("extensions.searchya.tlbrId", "base");
user_pref("extensions.searchya.tlbrSrchUrl", "hxxp://www.searchya.com/?f=3&a;=dnldyho&cd;=2XzuyEtN2Y1L1QzutDtDtC0DzytB0ByEyEtAzyzyyDtBtAtBtN0D0Tzu0CyEtCtAtN1L2Xzut
BtFtBtFtCtFyEy
user_pref("extensions.searchya.vrsn", "[removed]");
user_pref("extensions.searchya.vrsni", "[removed]");
user_pref("extensions.searchya_i.hmpg", true);
user_pref("extensions.searchya_i.newTab", false);
user_pref("extensions.searchya_i.smplGrp", "none");
user_pref("extensions.searchya_i.vrsnTs", "1.8.8.013:9:49");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN42265594992454012&UM;=2&q;=");
user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN42265594992454012&UM;=2&SearchSource;=13");
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN42265594992454012&UM;=2&q;=");
user_pref("smartbar.machineId", "K9W5UT4JDNHN+IOPV4CY2PSA2IAJEZGCACZPA33QIGW31/OSUH3H0EJGFSNBKLVEEXSWXKSAIOWCWYSOROMKBW");
user_pref("smartbar.originalHomepage", "hxxp://www.yahoo.com/|hxxp://www.facebook.com/home.php");
user_pref("smartbar.originalSearchAddressUrl", "");
user_pref("smartbar.originalSearchEngine", "Bing");
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocatio
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_referrer", "hxxp://search.conduit.com/?ctid=CT3289847&octid;=CT3289847&SearchSource;=15&CUI;=UN42265594992454012&
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_temp_referer", "hxxp://search.conduit.com/?ctid=CT3289847&octid;=CT3289847&SearchSource;=15&CUI;=UN42265594992454
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_product_name", "Updater By SweetPacks");



~~~ Chrome

Successfully deleted: [Folder] C:\Documents and Settings\pete\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 05/11/2013 at 19:04:11.89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~






=============================================================================
AdwCleaner[S1].txt
=============================================================================


# AdwCleaner v2.300 - Logfile created 05/11/2013 at 19:06:35
# Updated 28/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : pete - NPH
# Boot Mode : Normal
# Running from : C:\Documents and Settings\pete\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : vToolbarUpdater14.2.0

***** [Files / Folders] *****

Deleted on reboot : C:\Documents and Settings\pete\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
File Deleted : C:\WINDOWS\Tasks\AmiUpdXp.job
Folder Deleted : C:\Documents and Settings\pete\Application Data\SearchYa
Folder Deleted : C:\Documents and Settings\pete\Local Settings\Application Data\APN
Folder Deleted : C:\Program Files\DomaIQ Uninstaller

***** [Registry] *****

Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\searchya
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6801410E-CC88-42D6-A93B-909E95645407}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\Software\DomaIQ
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Deleted : HKLM\Software\InstallCore
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\Supreme Savings
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0.1 (en-US)

File : C:\Documents and Settings\pete\Application Data\Mozilla\Firefox\Profiles\noiovjdh.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v26.0.1410.64

File : C:\Documents and Settings\pete\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

Deleted [l.39] : icon_url = "hxxp://search.conduit.com/fav.ico",
Deleted [l.42] : keyword = "search.conduit.com",
Deleted [l.46] : search_url = "hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource;=49&CUI;=UN37[…]
Deleted [l.47] : suggest_url = "hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}&CUI;=U[…]
Deleted [l.2396] : homepage = "hxxp://search.conduit.com/?ctid=CT3289847&SearchSource;=48&CUI;=UN37201980881456924&UM;[…]

*************************

AdwCleaner[S1].txt - [4930 octets] - [11/05/2013 19:06:35]

########## EOF - C:\AdwCleaner[S1].txt - [4990 octets] ##########
Hello, peteinmaine.

Thank you for your JRT and adwCleaner reports. They have removed quite a bit of garbage from your system. When toolbars are removed, they often change your browser settings, but you have reset your homepage.

Let's take a look at your Picture Manager issue. You have already tried setting an association to open your picture with Picture Manager and that did not work. There are several other options we can try. To begin with, work through the following to see if any of these will fix the problem.

1. Run Microsoft Diagnostic in Office
  • Click Start > Programs > Microsoft Office > Microsoft Office Tools > Microsoft Office Diagnostic
  • At the next screen, click Continue. The diagnostic will take about 15 minutes to complete.
  • If no problems have been detected, No cause found will appear at the top of the screen.
  • If problems have been diagnosed, click Continue to connect to Microsoft's servers and view the results and recommendations.
Let me know if anything has been found.

2. Repair Office
  • Click on Start > Control Panel > Add or Remove Programs .
  • Click on the Office Suite that you are using to highlight it > Click Change.
  • Wait for Windows Installer to load the Microsoft Office 2003 Setup page. Once there, click Reinstall or Repair > Next.
  • Select Detect and Repair errors in my Office installation.
When finished, try Picture Manager. If the problem still persists, proceed to the next option.

3. Reinstall Office

To reinstall a fresh copy of Micrososft Office, follow the steps above, but choose Reinstall Office instead of Detect and Repair errors in my Office installation. When finished, try Picture Manager again.

Let me know if any of these options have resolved your issue.
Hello fbfbfb,

Re: "1. Run Microsoft Diagnostic in Office"
Click Start > Programs > Microsoft Office > Microsoft Office Tools > Microsoft Office Diagnostic
Unfortunately, I have no "Microsoft Office Diagnostic"
πŸ“ŽOffice.PNG
However, I did move on to #2 and find success with Picture manager


2. Repair Office
Click on Start > Control Panel > Add or Remove Programs.
Microsoft Office Small Business Edition 2003
Change > Repair > Repair errors in my Office installation


This solved my Picture Manager problem. I can now use Picture manager with no errors. :thumbup:


Next, I went back & attempted:
3. Reinstall Office

Problem corrected!
As I ran the Re-installation, here is what I got.
πŸ“ŽWhite_Smoke.PNG
Apparently the WhiteSmoke toolbar was still in residence.
Solution: Chrome > Settings > Extensions > Delete toolbar
Reran Re-installation to find: this result
πŸ“ŽSuccess.PNG
SUCCESS! Toolbar removed! :thumbup:



<>
This was a problem which originated at the start, yet I failed to mention. This problem continues.
The preview for Windows Media Player is not visible. Instead, I only see the Microsoft emblem for files which are usually associated with Windows Media Player rather than the expected preview from the file itself. [i.e. WMV, MPG]
πŸ“ŽWin_Media_Video_File.PNG

Please advise.
Hello, peteinmaine.

Very glad to hear that your Picture Manager is working properly, and good job deleting the WhiteSmoke Toolbar from your Chrome extensions. Let's try to resolve your issue with Windows Media Player thumbnails using the following options.

1. Set WMP as Default Player

Check to see if WMP is presently set to be your default player:
  • Click Start > Control Panel > Add and Remove Programs.
  • Click Set Program Access and Defaults located in the bottom left column.
  • Click the small arrows next to Custom on the right hand side.
  • Under the Choose a default Media Player section, select Windows Media Player.
  • Click OK.
2. Re-enable Media Types Preview in Explorer
  • Click Start > Run.
  • In the open field type cmd.
  • At the cursor, copy and paste the following:

regsvr32 shmedia.dll
regsvr32 shimgvw.dll

  • The following message should appear: DllRegisterServer in (name of file) succeeded.
  • Exit all dialogue boxes.
The thumbnail previews should now appear. If not, try the next solution.

3. Microsoft Fixit Tool
  • Download Microsoft's Fixit HERE.
  • Click the green Run Now button and follow the prompts.
4. Uninstall and Reinstall Windows Media Player

Uninstall
  • Click Start > Control Panel.
  • Double-click Add or Remove Programs.
  • Locate Windows Media Player in the list of programs, click to highlight it > Click Remove.
  • Follow the onscreen instructions to uninstall Windows Media Player from your computer.
Reinstall
  • Visit Microsoft's Windows Media Player download site HERE.
  • Click Continue to navigate to the Genuine Windows Validation page.
  • Click Continue to begin the genuine Windows validation. > Click Save File. GenuineCheck.exe will save to your download folder.
  • Double click GenuineCheck to open the file, then click Run.
  • The Windows Genuine Advantage dialogue box will open showing a code. Copy and paste this code into the open field and click Validate.
  • In the next window, click the red Download button.
  • Click Save File to begin installing Windows Media Player 11 for XP.
  • Wait for Windows Media Player to install. Do not use your computer during this process.
  • When the installation is complete, either select Express Settings (default configuration settings), or select Custom Settings to manually configure Windows Media Player settings.
  • Click Finish and Windows Media Player will open on your screen and automatically import media files stored on your computer.
Hello fbfbfb,

Re:
1. Set WMP as Default Player
2. Re-enable Media Types Preview in Explorer


Success using steps 1 & 2. The dialog boxes to follow, along with screen capture example of same video as originally presented. [i.e. now functioning correctly] :thumbup:
πŸ“ŽRegSvr32.PNG

Last Question:
AVG continues to run. However, it will frequently display a message that tells me in order to complete an update, the machine must be rebooted. I have rebooted on many occasions, yet continue to receive this message. This behavior I had not seen previous to this virus.
Tonight, after I had already selected to postpone for 1 hour, I then opened AVG & selected: Options > Update.
Since I had never seen this behavior prior to the WhiteSmoke Virus, I question if this is related.

I will post a screen capture of the message as soon as it is available again.
Hello, peteinmaine.

Good job working through the WMP issue. Your AVG's request for repeated reboots is most likely caused by an unfinished update process. For some reason, during the reboot, AVG is unable to replace files with their updated version. The easiest and recommended solution is to completely uninstall and reinstall AVG.

Uninstall AVG using AVG Remover:
  • Download the AVG Remover tool from HERE.
  • If you are asked whether to run or save the file, select Save or Save as, and save the file to your Desktop.

Note: Save all your work and documents! Your computer will be restarted automatically during the procedure.

  • Double-click the downloaded AVG Remover tool to run it.
  • Your computer will be restarted. After the restart, allow the tool to remove the remaining AVG files.
Install New Copy of AVG
  • Follow this LINK to download the free AVG Anti-Virus 2013.
  • Double-click AVG for Windows (32 bit) > Click Save File.
  • Double-click the downloaded AVG installation file, and follow the displayed instructions.
  • When prompted, copy and paste the AVG license number.
  • When the installation has finished, restart your computer.
AVG will now work correctly.

Peteinmaine, are there any other issues that I can assist you with? If all is good, we can move ahead with some important housekeeping.
Hello fbfbfb,

Completed:
1- Uninstall AVG using AVG Remover:
2- Install New Copy of AVG


Question:
1- Re: "When prompted, copy and paste the AVG license number."
I have never received any prompt. Therefore, I have no licence number. Please advise.


Problem:
When I shut my machine down, I am prompted for this.
πŸ“ŽUpdates_not.PNG

However, although I complete the update, this is repetitive with each shut-down, apparently never actually happening. The update process is consistently 2 items. This was happening before our last exchange. I was hopeful that the R&R of AVG would correct the problem. However, this continues to persist. Please advise

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI