This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Machine running badly [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi MARTY1946,

Chkdsk in Vista/7

You must run the command prompt as an administrator or in an "elevated mode".
  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "chkdsk /r" (make note of the space between chkdsk and /)
- - - - - Next - - - - -

Reboot

- - - - - Next - - - - -

To view results log:
  • Open the Start Menu, and type eventvwr.msc in the search box and press enter.
  • If prompted by UAC, then click on Yes (Windows 7) or Continue (Vista).
  • In the left pane of Event Viewer, double click on Windows Logs to expand it, then right click on Application and click on Find.
  • Copy and paste Chkdsk into the line, and click on Find Next.
  • You will now see the system log for the scan results of Check Disk (chkdsk).
  • In the right had menu select copy, open notepad and paste the chkdsk results into notepad
  • Post in your next reply.
In your next post please provide the following:
  • chkdsk results
  • Any change in performance?
HI MARTY1946,

No luck with the chkdsk

When the chkdsk screen you provided appears your need to press the letter "Y" on your keyboard to have the step run on computer next start up.

Also when I try to restart computer I am getting a loud beeping noise

How many beeps do you hear? What is the make and model of your computer?

What the beeps mean:

The BIOS performs a power-on self-test (POST) (a built-in diagnostic program that checks system hardware to ensure that everything is present and functioning properly, before the BIOS begins the actual boot), a test which is used to ensure a system is functioning properly. When a problem is identified, the BIOS will normally produce an error message. In some cases, since a problem may be detected so early that the BIOS cannot even access the video card to print the message, a series of beeping pattern will be produced on the speaker to tell a user what the problem is. The exact meaning of the beep codes depends on the type and version of BIOS.
Hi My computer is Toshiba Satellite L505D Laptop I get a BEEP BEEP BEEP continuous BEEP usually on Restart Could not do the chkdsk /f because of the malfunction on Restart it aborts chkdsk Thanks Marty :(
Hi MARTY1946,

Start with a "hard reset", here's the procedure for resetting a laptop:
  • Unplug the AC power, then remove the battery.
  • Hold down the power button for ten seconds.
  • Reinstall the battery, then plug the AC back in.
- - - - - Next - - - - -

I get a BEEP BEEP BEEP continuous BEEP usually on Restart

Would you translate this into 3 short beeps, followed by a long beep?

Could not do the chkdsk /f because of the malfunction on Restart it aborts chkdsk

Your reply shows chkdsk /f. Is that just a typo?
The correct command is chkdsk /r (as displayed in your screen shot)
Hello; I did the hard start as you requested. Removed battery etc. It didn't change anything, i still can't boot normally. The beeps are continuous one after another. I can get the computer to boot by pressing F12. The chkdsk /f was a typo. Thanks Marty
Hi MARTY1946,

Let's try this approach …

Reboot Your System using Last Known good Configuration
  • Restart your computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
  • Use the arrow keys to select the Last known good configuration menu item.
  • Press Enter.
- - - - - Next - - - - -

Re-try Chkdsk in Vista/7

You must run the command prompt as an administrator or in an "elevated mode".
  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "chkdsk /r" (make note of the space between chkdsk and /)
To view results log:
  • Open the Start Menu, and type eventvwr.msc in the search box and press enter.
  • If prompted by UAC, then click on Yes (Windows 7) or Continue (Vista).
  • In the left pane of Event Viewer, double click on Windows Logs to expand it, then right click on Application and click on Find.
  • Copy and paste Chkdsk into the line, and click on Find Next.
  • You will now see the system log for the scan results of Check Disk (chkdsk).
  • In the right had menu select copy, open notepad and paste the chkdsk results into notepad
  • Post in your next reply.

In your next post please provide the following:
  • Update on computer's performance
  • chksdk results log
Hi; I did as you asked. The last known good config did not work. Still have the beeping. Can't get the chkdsk log. Sorry, this is not going well. One other thing, the period key stopped working sometime I don;t know when. I'm using a Virtual Keyboard to insert periods. Marty :(
Hi MARTY1946,

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

In your next post please provide the following:
  • ComboFix.txt
  • Any change in performance?
Hello; Here is the Combofix Log ComboFix 13-05-12.01 - User 05/12/2013 8:45.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1662 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\MyOwnSuperhero\bar\2.bin\v3BAr.dll c:\program files\Webfetti\bar\2.bin\7dBAr.dll . . ((((((((((((((((((((((((( Files Created from 2013-04-12 to 2013-05-12 ))))))))))))))))))))))))))))))) . . 2013-05-12 12:54 . 2013-05-12 12:54 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\program files\FGIcon 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\programdata\Wincert 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\program files\Settings Alerter 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\programdata\Tarma Installer 2013-05-11 12:54 . 2013-05-11 15:03 ——– d—–w- c:\users\User\AppData\Roaming\Strongvault 2013-05-11 12:52 . 2013-05-11 15:02 ——– d—–w- c:\users\User\AppData\Local\SwvUpdater 2013-05-11 12:51 . 2013-05-11 15:03 ——– d-sh–w- c:\windows\system32\AI_RecycleBin 2013-05-11 12:49 . 2013-05-11 15:03 ——– d—–w- C:\AI_RecycleBin 2013-05-11 12:49 . 2013-05-11 12:49 ——– d—–w- c:\program files\LyricsTube 2013-05-10 22:56 . 2013-05-10 22:56 ——– d—–w- c:\program files\KeyBar_1.8 2013-05-10 22:54 . 2013-05-10 22:55 ——– d—–w- c:\program files\OtShot 2013-05-10 22:05 . 2013-05-10 22:05 ——– d—–w- c:\users\User\AppData\Roaming\Iminent 2013-05-10 22:05 . 2013-05-10 22:05 ——– d—–w- c:\programdata\Iminent 2013-05-10 21:58 . 2013-05-10 21:58 ——– d—–w- c:\program files\Conduit 2013-05-10 21:58 . 2013-05-11 22:14 ——– d—–w- c:\users\User\AppData\Local\Conduit 2013-05-10 21:58 . 2013-05-11 12:51 ——– d—–w- c:\users\User\AppData\Local\CRE 2013-05-10 21:40 . 2013-05-10 21:40 ——– d—–w- c:\program files\LessTabs 2013-05-10 21:40 . 2013-05-10 21:40 ——– d—–w- c:\program files\IMinent Toolbar 2013-05-10 21:39 . 2013-05-10 21:39 ——– d—–w- c:\program files\Common Files\Umbrella 2013-05-10 21:39 . 2013-05-10 22:04 ——– d—–w- c:\program files\Iminent 2013-05-10 17:02 . 2013-05-10 17:02 13024 β€”-a-w- c:\windows\system32\drivers\SWDUMon.sys 2013-05-10 17:02 . 2013-05-10 17:02 ——– d—–w- c:\users\User\AppData\Local\SlimWare Utilities Inc 2013-05-10 12:04 . 2013-05-10 12:20 ——– d—–w- C:\temp 2013-05-10 01:17 . 2013-05-10 01:17 ——– d—–w- C:\_OTL 2013-05-09 19:53 . 2013-05-09 19:53 ——– d—–w- c:\windows\ERUNT 2013-05-09 19:53 . 2013-05-09 22:41 ——– d—–w- C:\JRT 2013-05-09 15:00 . 2013-05-09 22:27 690 β€”-a-w- c:\windows\DeleteOnReboot.bat 2013-05-09 12:50 . 2013-05-09 12:50 ——– d—–w- c:\users\User\AppData\Roaming\Foresight Software 2013-05-09 12:50 . 2013-05-10 17:42 ——– d—–w- c:\programdata\Foresight Software 2013-05-08 18:56 . 2013-05-08 19:47 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2013-05-08 18:55 . 2009-01-25 16:14 15224 β€”-a-w- c:\windows\system32\sdnclean.exe 2013-05-08 18:55 . 2013-05-08 18:56 ——– d—–w- c:\program files\Spybot - Search & Destroy 2 2013-05-08 18:55 . 2013-05-08 18:55 ——– d—–w- c:\users\User\AppData\Local\Programs 2013-05-01 12:29 . 2013-04-04 09:35 94112 β€”-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-04-30 01:33 . 2013-04-30 01:33 9728 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-24 12:04 . 2013-04-12 13:45 1211752 β€”-a-w- c:\windows\system32\drivers\ntfs.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-01 12:30 . 2012-07-04 12:34 861088 β€”-a-w- c:\windows\system32\npdeployJava1.dll 2013-04-01 12:30 . 2010-12-05 10:25 782240 β€”-a-w- c:\windows\system32\deployJava1.dll 2013-03-31 12:49 . 2012-12-26 11:40 499712 β€”-a-w- c:\windows\system32\msvcp71.dll 2013-03-31 12:49 . 2012-12-26 11:40 348160 β€”-a-w- c:\windows\system32\msvcr71.dll 2013-03-29 06:53 . 2013-03-29 06:53 208184 β€”-a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2013-03-21 07:08 . 2013-03-21 07:08 182072 β€”-a-w- c:\windows\system32\drivers\avgtdix.sys 2013-03-19 12:19 . 2012-08-30 18:43 33624 β€”-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-03-19 05:04 . 2013-04-10 15:05 3968856 β€”-a-w- c:\windows\system32\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 15:05 3913560 β€”-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 04:48 . 2013-04-10 15:05 38912 β€”-a-w- c:\windows\system32\csrsrv.dll 2013-03-19 02:49 . 2013-04-10 15:05 69632 β€”-a-w- c:\windows\system32\smss.exe 2013-03-13 14:35 . 2012-04-08 15:38 693976 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-03-13 14:35 . 2011-05-15 20:27 73432 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-01 14:32 . 2013-03-01 14:32 22328 β€”-a-w- c:\windows\system32\drivers\avgidsshimx.sys 2013-03-01 03:09 . 2013-04-10 15:05 2347008 β€”-a-w- c:\windows\system32\win32k.sys 2013-02-15 04:37 . 2013-04-10 15:05 3217408 β€”-a-w- c:\windows\system32\mstscax.dll 2013-02-15 04:34 . 2013-04-10 15:05 131584 β€”-a-w- c:\windows\system32\aaclient.dll 2013-02-15 03:25 . 2013-04-10 15:05 36864 β€”-a-w- c:\windows\system32\tsgqec.dll 2013-02-12 03:32 . 2013-03-26 12:27 15872 β€”-a-w- c:\windows\system32\drivers\usb8023.sys 2012-09-06 01:27 . 2013-04-12 20:50 266720 β€”-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{9ed31f84-c8b3-4926-b950-dff74047ff79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712] . [HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}] . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}] 2012-12-19 15:22 2609864 β€”-a-w- c:\program files\IMinent Toolbar\tbcore3.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{9ed31f84-c8b3-4926-b950-dff74047ff79}] 2013-04-10 10:19 231712 β€”-a-w- c:\program files\KeyBar_1.8\prxtbKeyB.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864] "{9ed31f84-c8b3-4926-b950-dff74047ff79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712] . [HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620] . [HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864] "{9ED31F84-C8B3-4926-B950-DFF74047FF79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712] . [HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620] . [HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare] @="{72bcb80d-7778-eb4a-ec51-22340ad33e07}" [HKEY_CLASSES_ROOT\CLSID\{72bcb80d-7778-eb4a-ec51-22340ad33e07}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare2] @="{b723586e-9ca0-5b27-341a-4990a8c342cf}" [HKEY_CLASSES_ROOT\CLSID\{b723586e-9ca0-5b27-341a-4990a8c342cf}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare3] @="{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}" [HKEY_CLASSES_ROOT\CLSID\{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616] "TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672] "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-11 1324384] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296] "Toshiba Online Backup"="c:\program files\Toshiba Online Backup\ToshibaOnlineBackup.exe" [2010-01-15 965976] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2013-03-31 295512] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176] "Iminent"="c:\program files\Iminent\Iminent.exe" [2013-04-30 1074736] "IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2013-04-30 884784] "OtShot"="c:\program files\OtShot\otshot.exe" [2012-10-18 4386816] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Secure Backup and Share Status.lnk - c:\program files\SecureBackupShare\ComcastSecureBackupSharestat.exe [2010-12-14 3539688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R3 cpuz134;cpuz134;c:\users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x] R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x] R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x] S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x] S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x] S1 ComcastSecureBackupShareFilter;ComcastSecureBackupShareFilter;c:\windows\system32\DRIVERS\ComcastSecureBackupShare.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x] S2 ComcastSecureBackupSharebackup;Comcast Secure Backup & Share Backup Service;c:\program files\SecureBackupShare\ComcastSecureBackupSharebackup.exe [x] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [x] S2 SDScannerService;Spybot-S&D; 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D; 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D; 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [x] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [x] S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}] 2009-08-06 16:15 264048 β€”-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-10 12:20 1642448 β€”-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-05-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 14:35] . 2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47] . 2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47] . . β€”β€”- Supplementary Scan β€”β€”- . uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI;=UN35564223172798513&UM;=2&ctid;=CT3289847 uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 75.75.76.76 75.75.75.75 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN35092422866735130&UM;=2&q;= FF - ExtSQL: 2013-03-31 08:50; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed] FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed] FF - ExtSQL: 2013-05-10 17:58; {6c3bc03f-d7b9-43ac-8931-c242e3cae971}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{6c3bc03f-d7b9-43ac-8931-c242e3cae971} FF - ExtSQL: 2013-05-10 18:55; {9ed31f84-c8b3-4926-b950-dff74047ff79}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79} FF - ExtSQL: 2013-05-11 08:50; {739df940-c5ee-4bab-9d7e-270894ae687a}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a} FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed] FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed] FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true FF - user.js: extentions.y2layers.installId - e803e1ea-1a21-4412-8f75-cb13afdc7f45 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . . β€”β€”- File Associations β€”β€”- . .scr=AutoCADScriptFile . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file) BHO-{1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - (no file) Toolbar-Locked - (no file) Toolbar-10 - (no file) Notify-SDWinLogon - SDWinLogon.dll AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files\Coupons\uninstall.exe AddRemove-IMBoosterARP - c:\program files\Iminent\inst\Bootstrapper\Bootstrapper.exe AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe . . . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"=hex:51,66,7a,6c,4c,1d,38,12,28,b9,b1, 5e,21,d7,a9,08,e9,36,2a,eb,0a,ff,3e,f3 "{7B13EC3E-999A-4B70-B9CB-2617B8323822}"=hex:51,66,7a,6c,4c,1d,38,12,50,ef,00, 7f,a8,d7,1e,0e,c6,dd,65,57,bd,6c,7c,36 "{A8C7C2CA-6DFD-4E16-8458-592361564D38}"=hex:51,66,7a,6c,4c,1d,38,12,a4,c1,d4, ac,cf,23,78,0b,fb,4e,1a,63,64,08,09,2c "{9D425283-D487-4337-BAB6-AB8354A81457}"=hex:51,66,7a,6c,4c,1d,38,12,ed,51,51, 99,b5,9a,59,06,c5,a0,e8,c3,51,f6,50,43 "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4, 91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{0095C290-A428-4BDD-B98C-E0A116F1C702}"=hex:51,66,7a,6c,4c,1d,38,12,fe,c1,86, 04,1a,ea,b3,0e,c6,9a,a3,e1,13,af,83,16 "{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}"=hex:51,66,7a,6c,4c,1d,38,12,91,e9,dd, 10,ef,d8,6f,04,d1,21,96,ac,d9,7d,87,e2 "{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22, 12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a, 34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1, 38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4 "{435EAA86-D32B-484F-869C-53745FCB1642}"=hex:51,66,7a,6c,4c,1d,38,12,e8,a9,4d, 47,19,9d,21,0d,f9,8a,10,34,5a,95,52,56 "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}"=hex:51,66,7a,6c,4c,1d,38,12,92,9a,85, b0,57,58,7a,01,de,dd,87,e2,a1,ff,7a,f8 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:c4,ad,76,d6,22,26,cd,01 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€” . - - - - - - - > 'lsass.exe'(800) c:\windows\system32\ARstore.dll . Completion time: 2013-05-12 08:58:17 ComboFix-quarantined-files.txt 2013-05-12 12:58 . Pre-Run: 249,772,179,456 bytes free Post-Run: 249,468,657,664 bytes free . - - End Of File - - 3F7D02E29DA500FBDFCAEC1B90297314
Hi MARTY1946,

1. Be aware that many download screens have pre-checked boxes. If allowed, they add other processes to the ownload, some and some not- having to do with the program being downloaded.
If/When you go to run the download that you have saved to the desktop and get a choice of Standard or Custom Download, always choose Custom. Doing so will allow you to NOT choose any additional features the program is offering.

=========================
2. Set Default Download Location in Browsers:

You can choose a location on your computer where downloads should be saved by default. This means that whenever you using Save As in the File> Save As or when you choose to Save a download, it will automatically default to the location you have set. You may find that setting the Default Download Location to your Desktop the most convenient.If you want to move the file later, you can. If you want to delete the file, it will be most handy on the Desktop. For the cleaning and scanning programs we use, almost all are directed to be saved to the desktop.

Chrome:
Open Chrome > Customize and control > Options > Under the Hood > Downloads > Change > Select Desktop > OK
(Don't check 'ask where to save each time….')

Firefox:
Open Firefox > Tools > Options > Main/General > Downloads Section > Save Files to > Browse > Navigate to and select Desktop > OK

Internet Explorer
Open IE > Gear icon > View Downloads > Options > Browse to and select Desktop > OK

There may be a slight difference in the path dependent on the browser version. There may also be a box to check to "Ask me the location each time". I do not advise checking that box.

=========================
3. ComboFix Running Location

You are not running ComboFix from the correct location.

Please drag the copy of Combofix to the recycle bin and download a fresh copy and save it to your Desktop.

=========================
4. ComboFix Script

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

Folder::
c:\users\User\AppData\Roaming\Strongvault
c:\program files\KeyBar_1.8
c:\program files\OtShot
c:\users\User\AppData\Roaming\Iminent
c:\programdata\Iminent
c:\program files\Conduit
c:\users\User\AppData\Local\Conduit
c:\program files\IMinent Toolbar
c:\program files\Iminent

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9ed31f84-c8b3-4926-b950-dff74047ff79}"=-

[-HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}]
[-HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[-HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[-HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
[-HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{9ed31f84-c8b3-4926-b950-dff74047ff79}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"=-
"{9ed31f84-c8b3-4926-b950-dff74047ff79}"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"=-
"{9ED31F84-C8B3-4926-B950-DFF74047FF79}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Iminent"=-
"IminentMessenger"=-
"OtShot"=-

FireFox::
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN35092422866735130&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3289847&CUI=UN35092422866735130&UM=2&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN35092422866735130&UM=2&q=
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:58; {6c3bc03f-d7b9-43ac-8931-c242e3cae971}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{6c3bc03f-d7b9-43ac-8931-c242e3cae971}
FF - ExtSQL: 2013-05-11 08:50; {739df940-c5ee-4bab-9d7e-270894ae687a}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.


=========================
5.

I get a BEEP BEEP BEEP continuous BEEP usually on Restart

Are the beeps the same length and volume? How many beeps in total?

The BIOS name is also important ( ie Award, Phonix etc). This can usually be found on one of the first screen shown during boot-up.

=========================

In your next post please provide the following:
  • ComboFix.txt
  • BIOS information, if available.
  • Any change in performance?
Hello; I couldn't get combofix log right after reboot, the machine did not reboot correctly, I ran combofix again, there was no reboot so i was able to get the log so I will add it below. The computer seems to be running better, but still have the reboot issue. The script file in combo fix seemed to run ok the first time. I will get the Bios properties on my next boot. ComboFix 13-05-12.01 - User 05/12/2013 11:32:43.4.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1548 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-04-12 to 2013-05-12 ))))))))))))))))))))))))))))))) . . 2013-05-12 15:43 . 2013-05-12 15:43 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-05-12 15:13 . 2013-05-12 15:43 ——– d—–w- c:\users\User\AppData\Local\temp 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\program files\FGIcon 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\programdata\Wincert 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\program files\Settings Alerter 2013-05-11 13:28 . 2013-05-11 13:28 ——– d—–w- c:\programdata\Tarma Installer 2013-05-11 12:52 . 2013-05-11 15:02 ——– d—–w- c:\users\User\AppData\Local\SwvUpdater 2013-05-11 12:51 . 2013-05-11 15:03 ——– d-sh–w- c:\windows\system32\AI_RecycleBin 2013-05-11 12:49 . 2013-05-11 15:03 ——– d—–w- C:\AI_RecycleBin 2013-05-11 12:49 . 2013-05-11 12:49 ——– d—–w- c:\program files\LyricsTube 2013-05-10 21:58 . 2013-05-11 12:51 ——– d—–w- c:\users\User\AppData\Local\CRE 2013-05-10 21:40 . 2013-05-10 21:40 ——– d—–w- c:\program files\LessTabs 2013-05-10 21:39 . 2013-05-10 21:39 ——– d—–w- c:\program files\Common Files\Umbrella 2013-05-10 17:02 . 2013-05-10 17:02 13024 β€”-a-w- c:\windows\system32\drivers\SWDUMon.sys 2013-05-10 17:02 . 2013-05-10 17:02 ——– d—–w- c:\users\User\AppData\Local\SlimWare Utilities Inc 2013-05-10 12:04 . 2013-05-10 12:20 ——– d—–w- C:\temp 2013-05-10 01:17 . 2013-05-10 01:17 ——– d—–w- C:\_OTL 2013-05-09 19:53 . 2013-05-09 19:53 ——– d—–w- c:\windows\ERUNT 2013-05-09 19:53 . 2013-05-09 22:41 ——– d—–w- C:\JRT 2013-05-09 15:00 . 2013-05-09 22:27 690 β€”-a-w- c:\windows\DeleteOnReboot.bat 2013-05-09 12:50 . 2013-05-09 12:50 ——– d—–w- c:\users\User\AppData\Roaming\Foresight Software 2013-05-09 12:50 . 2013-05-10 17:42 ——– d—–w- c:\programdata\Foresight Software 2013-05-08 18:56 . 2013-05-08 19:47 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2013-05-08 18:55 . 2009-01-25 16:14 15224 β€”-a-w- c:\windows\system32\sdnclean.exe 2013-05-08 18:55 . 2013-05-08 18:56 ——– d—–w- c:\program files\Spybot - Search & Destroy 2 2013-05-08 18:55 . 2013-05-08 18:55 ——– d—–w- c:\users\User\AppData\Local\Programs 2013-05-01 12:29 . 2013-04-04 09:35 94112 β€”-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-04-30 01:33 . 2013-04-30 01:33 9728 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-24 12:04 . 2013-04-12 13:45 1211752 β€”-a-w- c:\windows\system32\drivers\ntfs.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-01 12:30 . 2012-07-04 12:34 861088 β€”-a-w- c:\windows\system32\npdeployJava1.dll 2013-04-01 12:30 . 2010-12-05 10:25 782240 β€”-a-w- c:\windows\system32\deployJava1.dll 2013-03-31 12:49 . 2012-12-26 11:40 499712 β€”-a-w- c:\windows\system32\msvcp71.dll 2013-03-31 12:49 . 2012-12-26 11:40 348160 β€”-a-w- c:\windows\system32\msvcr71.dll 2013-03-29 06:53 . 2013-03-29 06:53 208184 β€”-a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2013-03-21 07:08 . 2013-03-21 07:08 182072 β€”-a-w- c:\windows\system32\drivers\avgtdix.sys 2013-03-19 12:19 . 2012-08-30 18:43 33624 β€”-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-03-19 05:04 . 2013-04-10 15:05 3968856 β€”-a-w- c:\windows\system32\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 15:05 3913560 β€”-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 04:48 . 2013-04-10 15:05 38912 β€”-a-w- c:\windows\system32\csrsrv.dll 2013-03-19 02:49 . 2013-04-10 15:05 69632 β€”-a-w- c:\windows\system32\smss.exe 2013-03-13 14:35 . 2012-04-08 15:38 693976 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-03-13 14:35 . 2011-05-15 20:27 73432 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-01 14:32 . 2013-03-01 14:32 22328 β€”-a-w- c:\windows\system32\drivers\avgidsshimx.sys 2013-03-01 03:09 . 2013-04-10 15:05 2347008 β€”-a-w- c:\windows\system32\win32k.sys 2013-02-15 04:37 . 2013-04-10 15:05 3217408 β€”-a-w- c:\windows\system32\mstscax.dll 2013-02-15 04:34 . 2013-04-10 15:05 131584 β€”-a-w- c:\windows\system32\aaclient.dll 2013-02-15 03:25 . 2013-04-10 15:05 36864 β€”-a-w- c:\windows\system32\tsgqec.dll 2013-02-12 03:32 . 2013-03-26 12:27 15872 β€”-a-w- c:\windows\system32\drivers\usb8023.sys 2012-09-06 01:27 . 2013-04-12 20:50 266720 β€”-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare] @="{72bcb80d-7778-eb4a-ec51-22340ad33e07}" [HKEY_CLASSES_ROOT\CLSID\{72bcb80d-7778-eb4a-ec51-22340ad33e07}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare2] @="{b723586e-9ca0-5b27-341a-4990a8c342cf}" [HKEY_CLASSES_ROOT\CLSID\{b723586e-9ca0-5b27-341a-4990a8c342cf}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare3] @="{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}" [HKEY_CLASSES_ROOT\CLSID\{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}] 2010-12-14 17:06 3424488 β€”-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616] "TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672] "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-11 1324384] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296] "Toshiba Online Backup"="c:\program files\Toshiba Online Backup\ToshibaOnlineBackup.exe" [2010-01-15 965976] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2013-03-31 295512] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Secure Backup and Share Status.lnk - c:\program files\SecureBackupShare\ComcastSecureBackupSharestat.exe [2010-12-14 3539688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R3 cpuz134;cpuz134;c:\users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x] R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x] R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x] R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x] S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x] S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x] S1 ComcastSecureBackupShareFilter;ComcastSecureBackupShareFilter;c:\windows\system32\DRIVERS\ComcastSecureBackupShare.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x] S2 ComcastSecureBackupSharebackup;Comcast Secure Backup & Share Backup Service;c:\program files\SecureBackupShare\ComcastSecureBackupSharebackup.exe [x] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [x] S2 SDScannerService;Spybot-S&D; 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D; 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D; 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [x] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [x] S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}] 2009-08-06 16:15 264048 β€”-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-10 12:20 1642448 β€”-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-05-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 14:35] . 2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47] . 2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47] . . β€”β€”- Supplementary Scan β€”β€”- . uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI;=UN35564223172798513&UM;=2&ctid;=CT3289847 uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 75.75.76.76 75.75.75.75 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN35092422866735130&UM;=2&q;= FF - ExtSQL: 2013-03-31 08:50; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed] FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed] FF - ExtSQL: 2013-05-10 17:58; {6c3bc03f-d7b9-43ac-8931-c242e3cae971}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{6c3bc03f-d7b9-43ac-8931-c242e3cae971} FF - ExtSQL: 2013-05-10 18:55; {9ed31f84-c8b3-4926-b950-dff74047ff79}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79} FF - ExtSQL: 2013-05-11 08:50; {739df940-c5ee-4bab-9d7e-270894ae687a}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a} FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed] FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed] FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true FF - user.js: extentions.y2layers.installId - e803e1ea-1a21-4412-8f75-cb13afdc7f45 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . . β€”β€”- File Associations β€”β€”- . .scr=AutoCADScriptFile . . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"=hex:51,66,7a,6c,4c,1d,38,12,28,b9,b1, 5e,21,d7,a9,08,e9,36,2a,eb,0a,ff,3e,f3 "{7B13EC3E-999A-4B70-B9CB-2617B8323822}"=hex:51,66,7a,6c,4c,1d,38,12,50,ef,00, 7f,a8,d7,1e,0e,c6,dd,65,57,bd,6c,7c,36 "{A8C7C2CA-6DFD-4E16-8458-592361564D38}"=hex:51,66,7a,6c,4c,1d,38,12,a4,c1,d4, ac,cf,23,78,0b,fb,4e,1a,63,64,08,09,2c "{9D425283-D487-4337-BAB6-AB8354A81457}"=hex:51,66,7a,6c,4c,1d,38,12,ed,51,51, 99,b5,9a,59,06,c5,a0,e8,c3,51,f6,50,43 "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4, 91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{0095C290-A428-4BDD-B98C-E0A116F1C702}"=hex:51,66,7a,6c,4c,1d,38,12,fe,c1,86, 04,1a,ea,b3,0e,c6,9a,a3,e1,13,af,83,16 "{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}"=hex:51,66,7a,6c,4c,1d,38,12,91,e9,dd, 10,ef,d8,6f,04,d1,21,96,ac,d9,7d,87,e2 "{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22, 12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a, 34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1, 38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4 "{435EAA86-D32B-484F-869C-53745FCB1642}"=hex:51,66,7a,6c,4c,1d,38,12,e8,a9,4d, 47,19,9d,21,0d,f9,8a,10,34,5a,95,52,56 "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}"=hex:51,66,7a,6c,4c,1d,38,12,92,9a,85, b0,57,58,7a,01,de,dd,87,e2,a1,ff,7a,f8 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:c4,ad,76,d6,22,26,cd,01 . [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€” . - - - - - - - > 'lsass.exe'(796) c:\windows\system32\ARstore.dll . - - - - - - - > 'Explorer.exe'(4508) c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll c:\program files\SecureBackupShare\LIBEAY32.dll . Completion time: 2013-05-12 11:46:33 ComboFix-quarantined-files.txt 2013-05-12 15:46 ComboFix2.txt 2013-05-12 15:21 ComboFix3.txt 2013-05-12 13:43 ComboFix4.txt 2013-05-12 12:58 . Pre-Run: 249,462,284,288 bytes free Post-Run: 249,160,941,568 bytes free . - - End Of File - - 1303AFCF2BEBDCEDC60FFBB6595E595B
Hello Again; I did a screenshot of what's happening in the start menu, Take notice of the series of periods or dots, if you don;t type something it keeps inserting periods by itself. I'm not sure what bios i have?
Hi MARTY1946,

1. First we need to make all files and folders VISIBLE:

To enable the viewing of hidden and protected system files in Windows please follow these steps:
  • Close all programs so that you are at your desktop.
  • Click on the Start button. (This is the small round button with the Windows flag in the lower left corner.)
  • Click on the Control Panel menu option.
  • When the control panel opens you can either be in Classic View or Control Panel Home view:

    If you are in the Classic View do the following:
    • Double-click on the Folder Options icon.
    • Click on the View tab.
    • Go to step 5
    If you are in the Control Panel Home view do the following:
    • Click on the Appearance and Personalization link.
    • Click on Show Hidden Files or Folders.
    • Go to step 5.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the check mark from the check box labeled Hide extensions for known file types.
  • Remove the check mark from the check box labeled Hide protected operating system files.
  • Press the Apply button and then the OK button.
=========================

2. Uninstall Firefox & Chrome completely

Remove Mozilla Firefox Completely:
  • Exit Firefox completely
  • Go to the Control Panel > > Programs and Features
  • Select Mozilla Firefox (all versions, one at a time) and click Uninstall
    • You may be prompted with and option to "Remove my Firefox personal data and customization". This will also remove your Firefox user profile data (bookmarks, passwords, cookies, extensions, preferences, etc.)
      DO NOT select this option if you want to keep your Firefox profile data and settings.
  • Delete the Firefox installation directory located here: C:\Program Files\Mozilla Firefox
  • Delete the Firefox folder that contains temporary data located here:
    • C:\Users\\AppData\Local\Mozilla\Firefox
    • C:\Users\\AppData\Local\VirtualStore\Program Files\Mozilla Firefox (if it exists)
  • Remove the Mozilla Firefox desktop icon if it still is present.

- - - - - Next - - - - -

Uninstall Google Chrome

Windows Vista/ Windows 7/ Windows 8
  • Close all Chrome windows and tabs.
  • Go to the Start menu > Control Panel.
  • Click Programs and Features.
  • Double-click Google Chrome.
  • Click Uninstall from the confirmation dialog.
  • To delete your user profile information, like your browser preferences, bookmarks, and history, select the "Also delete your browsing data" check-box.

Re-Hide Files and Folders

Reboot your computer to ensure changes have taken effect.

=========================

3. Disable Spybot - Search & Destroy's Tea Timer

Please follow the instruction below.
  • Locate your copy of Spybot - Search & Destroy's and open it.
  • In the menu bar at the top select "Mode", then select "Advanced".
  • In the left hand menu expand the "Tools" menu.
  • Select "Resident", then remove the check mark for "Resident Tea Timer"
  • Then exit the program by clicking "File" then select "Exit"
=========================

4. Disable the proxy settings in Internet Explorer

  • Under β€œTools” in the browser tool bar select β€œInternet Options”.
  • In the β€œInternet Options” window that pops up, click the β€œConnections” tab at the top.
  • Click β€œLAN Settings” near the bottom of the β€œConnections” section.
  • If the β€œProxy server” check-box is marked with a check, click it to deselect/uncheck it.
  • Click β€œOK” to close the β€œLocal Area Network (LAN) Settings” window.
  • Click β€œOK” to close the β€œInternet Options” window.
Reboot

=========================

5. Make sure "Proxy server" is still disabled under LAN Settings

Click the Start menu button > Control Panel
Internet Options > Connections tab
LAN Settings, be sure the check-box in the Proxy Server section is unchecked
Click OK to confirm and close.

=========================

6. AdwCleaner

Delete the copy of AdwCleaner you downloaded previously, and download a fresh copy.

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

In your next post please provide the following:
  • AdwCleaner.txt
  • Any change in performance?
Hi; I got another problem to fix before I remove FIREFOX. Internet Explorer stopped working. I says it encountered a problem a needs to close. I am afraid to remove the working browser before I can get on the net with Internet Explorer. Got any suggestions on how to get Internet Explorer working again? I'm sorry about all the problems. Thanks Marty

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI