This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

homepage hijacked [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

[attachment removed][attachment removed]Hello, I hope you can help me like you have kindly done so in the past. I think I inadvertantly downloaded a Trojan which has hijacked my Homepage. My Homepage will not display even if I try to load it using the options in the Internet Explorer tools dialog. I keep getting an "About Blank" as my homepage. Your help in fixing this will be much appreciated. I have attached the DDS logs below as instructed. Many thanks, Kevin
Hello, kayaref. Welcome to WTT Forums.

My name is fbfbfb.

I will gladly assist you with your malware concerns. Malware logs may require some time to analyze, and because there is no quick-fix solution, we may need to use various approaches to clean your system. Please be patient.

While working to resolve the issues with your machine, please note the following guidelines:
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • To avoid potential problems and setbacks, do not

  • install or uninstall any applications while your system is being cleaned.
  • use any tools other than those recommended.
  • run any other scans without being directed to do so.

  • Copy and Paste the log files inside your posts. Do not send them as attachments unless otherwise instructed.
  • Stay with this thread until your machine has been deemed all clear. Absence of symptoms does not mean your system is clear.
  • Please reply within 3 days of each posting to avoid closing this topic. If you need more time to complete tasks, or if you will be away, please let me know in advance.
Please run the following scans

1. OTL
  • Please download OTL to your desktop from HERE or HERE
  • Close all other applications and windows so that you have nothing open.
  • Double click on the [external image: Posted Image]icon on your desktop.

Note: Vista and Windows 7 users right-click and select Run As Administrator. If you receive a UAC prompt asking if you would like to continue running the program, you should press the Continue button.

  • Under Output, click Minimal Output to select it.
  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
  • Then click the Run Fix button at the top.
:OTL
uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
BHO: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - 
BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
TB: Vuze Remote Toolbar: {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
TB: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

:Commands
[emptytemp]
[resethosts]
[CLEARALLRESTOREPOINTS]
  • Let the program run unhindered; it will reboot when it is done. If it does not, please reboot your system.
  • Post the new log in your next reply.
2. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

3. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

P2P Software

I see you have P2P software (Vuze) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation.

Please note: Even if you are using a safe P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

Please see this topic for more information: Perils of P2P File Sharing.

I would strongly recommend that you uninstall this now. You can do so via Control Panel > Programs and Features.

CHECKLIST: In your next reply, please post the following:
  • OTL log
  • adwcleaner.txt
  • JRT.txt
  • Let me know how your computer is running now.
Hi fbfbfb, Many thanks for your reply and help on this. I have pasted the scan results below as instructed. My homepage now loads as normal and remains as selected via the options dialog. Computer seems to run ok, pages seem to load ok. Regards, Kevin All processes killed ========== OTL ========== ========== COMMANDS ========== [EMPTYTEMP] User: Aaron 1 ->Temp folder emptied: 8524998 bytes ->Temporary Internet Files folder emptied: 164996550 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 7090 bytes User: All Users User: Debbie 1 ->Temp folder emptied: 168879549 bytes ->Temporary Internet Files folder emptied: 300359259 bytes ->Java cache emptied: 254306 bytes ->FireFox cache emptied: 71679675 bytes ->Flash cache emptied: 43365 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Emma 1 ->Temp folder emptied: 45484838 bytes ->Temporary Internet Files folder emptied: 485068818 bytes ->Java cache emptied: 338893 bytes ->Flash cache emptied: 77803 bytes User: Guest ->Temp folder emptied: 50988 bytes ->Temporary Internet Files folder emptied: 5690924 bytes User: kevin ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 300041648 bytes ->Java cache emptied: 201319 bytes ->FireFox cache emptied: 80988453 bytes ->Google Chrome cache emptied: 6524111 bytes ->Flash cache emptied: 68047 bytes User: media User: Public User: TEMP ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56502 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 86821 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 268322678 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68298 bytes RecycleBin emptied: 6000132177 bytes Total Files Cleaned = 7,542.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 07262013_064813 Files\Folders moved on Reboot… C:\Users\Emma 1\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\kevin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BY0WFJPW\index[2].htm moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BY0WFJPW\index[3].htm moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9U89I81G\iframe[1].html moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9U89I81G\iframe[2].html moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4MDE8Z7R\iframe[1].html moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2QX2VQOK\iframe[1].html moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2QX2VQOK\iframe[2].html moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. File\Folder C:\Windows\temp\~bdFF35.tmp not found! PendingFileRenameOperations files… Registry entries deleted on Reboot… # AdwCleaner v2.306 - Logfile created 07/26/2013 at 07:02:24 # Updated 19/07/2013 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (64 bits) # User : kevin - KEV1 # Boot Mode : Normal # Running from : C:\Users\kevin\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : BCUService ***** [Files / Folders] ***** File Deleted : C:\END Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\ConduitEngine Folder Deleted : C:\Program Files (x86)\DeviceVM Folder Deleted : C:\Program Files (x86)\Vuze_Remote Folder Deleted : C:\Users\Aaron 1\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Aaron 1\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Aaron 1\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Aaron 1\AppData\LocalLow\Vuze_Remote Folder Deleted : C:\Users\Debbie 1\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Debbie 1\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Debbie 1\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Debbie 1\AppData\LocalLow\Vuze_Remote Folder Deleted : C:\Users\Emma 1\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Emma 1\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\Emma 1\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Emma 1\AppData\LocalLow\Vuze_Remote Folder Deleted : C:\Users\kevin\AppData\Local\Conduit Folder Deleted : C:\Users\kevin\AppData\Local\PackageAware Folder Deleted : C:\Users\kevin\AppData\LocalLow\Conduit Folder Deleted : C:\Users\kevin\AppData\LocalLow\ConduitEngine Folder Deleted : C:\Users\kevin\AppData\LocalLow\Vuze_Remote ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine Key Deleted : HKCU\Software\AppDataLow\Software\RewardsArcade Key Deleted : HKCU\Software\AppDataLow\Software\Vuze_Remote Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Cr_Installer Key Deleted : HKCU\Software\DeviceVM Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA14329E-9550-4989-B3F2-9732E92D17CC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{77AA6435-2488-4A94-9FE5-49519DD2ED9B} Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\conduitEngine Key Deleted : HKLM\Software\DeviceVM Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{67F95178-DD3C-41D3-A967-9733B76FD117} Key Deleted : HKLM\Software\Vuze_Remote Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{67F95178-DD3C-41D3-A967-9733B76FD117} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{04296F9C-AC1D-4B79-9276-8FB9D2BBF14A} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{285D3AE6-F714-47D4-A119-CC98DB8615FE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD3DC4D7-B9CE-4925-AB36-BC2B297A394D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA14329E-9550-4989-B3F2-9732E92D17CC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Vuze_Remote Toolbar Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BCU] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{BA14329E-9550-4989-B3F2-9732E92D17CC}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\wmysdnwa.default\prefs.js [OK] File is clean. File : C:\Users\Debbie 1\AppData\Roaming\Mozilla\Firefox\Profiles\ssxr0s02.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\kevin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [6069 octets] - [26/07/2013 07:02:24] ########## EOF - C:\AdwCleaner[S1].txt - [6129 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.2 (07.22.2013:2) OS: Windows 7 Professional x64 Ran by [removed] on Fri 26/07/2013 at 7:08:47.57 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\wmysdnwa.default\minidumps [1 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Fri 26/07/2013 at 7:12:21.79 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hello, Kevin.

Thank you for the logs. I'm glad to hear your computer is running much better. Sometimes, during the cleaning process, malware can resurface. Let's take another look to ensure your system is clean and up-to-date.

Please run the following scan

1. DDS

Please download DDS from HERE. Click Save File. The file will save to your default location.
  • Disable any script blocking protection. (How to Temporarily Disable Security Programs: Anti-virus/Anti-spyware/Firewall)
  • Double click dds.com > Click Run.
  • At the next prompt, ensure check marks appear next to dds.com and attach.txt > Click Start to begin the scan. When done, click OK to close the DDS window.
  • Two reports will automatically open: dds.txt and Attach.txt. These reports are also saved to your desktop.
Please copy and paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. Security Check

Please download Security Check from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt. This may take a few minutes.
Please copy and paste the contents of that document into your next reply.

CHECKLIST: In your next reply, please post the following:
  • dds.txt
  • attach.txt
  • checkup.txt
  • Let me know if there are any remaining issues we need to address.
Hi fbfbfb, Thanks, Here are the results as requested. I disabled my Antivirus as requested, but the Security Check result is not what I was expecting, it states that my operating system is unsupported. Regards, Kevin DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.25.2 Run by [removed] at 17:50:08 on 2013-07-26 Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8183.6305 [GMT 8:00] . AV: Bitdefender Antivirus *Disabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Bitdefender Antispyware *Disabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09} FW: Bitdefender Firewall *Enabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\SysWOW64\nlssrv32.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\explorer.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.iinet.net.au/home mStart Page = about:blank mWinlogon: Userinit = userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: FlashFXP Helper for Internet Explorer: {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files (x86)\FlashFXP\IEFlash.dll uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [AdobeBridge] mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" dRun: [20090604] C:\Program Files (x86)\Broderbund\Mavis Beacon Platinum - 25th Anniversary Edition\RegApp\encore_reg.exe /r "C:\Program Files (x86)\Broderbund\Mavis Beacon Platinum - 25th Anniversary Edition\RegApp\encore_reg.rpd" mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: Interfaces\{6910964C-D373-4ADB-83FB-0546BA7C3200} : NameServer = 192.168.1.254 SSODL: WebCheck - x64-mStart Page = about:blank x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Run: [Bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\wmysdnwa.default\ FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll . ============= SERVICES / DRIVERS =============== . R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2013-4-26 718840] R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2013-3-29 147232] R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys [2013-4-26 93600] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2012-9-8 103504] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-4-7 202752] R2 nlsX86cc;This service enables products that use the Nalpeiron Licensing System.;C:\Windows\SysWOW64\nlssrv32.exe [2011-9-23 66560] R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [2013-7-15 67320] R3 avchv;avchv Function Driver;C:\Windows\System32\drivers\avchv.sys [2012-9-8 261056] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-22 215040] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-6-22 1235968] R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2013-7-15 597776] S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2012-10-24 82384] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-2-16 99384] S3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2010-7-6 19544] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2012-5-11 203320] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-9-5 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-10 1255736] S4 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [2013-3-29 69392] . =============== Created Last 30 ================ . 2013-07-25 23:08:42 ——– d—–w- C:\Windows\ERUNT 2013-07-25 22:48:13 ——– d—–w- C:\_OTL 2013-07-15 11:58:54 597776 —-a-w- C:\Windows\System32\drivers\avckf.sys . ==================== Find3M ==================== . 2013-07-15 11:05:56 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-15 11:05:56 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-25 11:31:10 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-25 11:31:09 867240 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2013-06-25 11:31:09 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-05-29 15:06:25 382536 —-a-w- C:\Windows\System32\drivers\trufos.sys . ============= FINISH: 17:50:22.90 =============== UNSUPPORTED OPERATING SYSTEM! ABORTED!
Hello, Kevin.

Thank you for the DDS logs. Your system looks good – just a couple of leftover remnants to take care of.

Please run the following scan
  • Please download OTL to your desktop from HERE or HERE
  • Close all other applications and windows so that you have nothing open.
  • Double click on the [external image: Posted Image]icon on your desktop.

Note: Vista and Windows 7 users right-click and select Run As Administrator. If you receive a UAC prompt asking if you would like to continue running the program, you should press the Continue button.

  • Under Output, click Minimal Output to select it.
  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
  • Then click the Run Fix button at the top.
:OTL
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - 
uRun: [AdobeBridge] 

:Commands
[resethosts]
[CLEARALLRESTOREPOINTS]
  • Let the program run unhindered; it will reboot when it is done. If it does not, please reboot your system.
  • Post the new log in your next reply.
Unsupported Operating System Error

There could be several reasons for this error message, including applications that require updates. Let's first log into SafeMode, then try running Security Check again:

Using the F8 Method as an option:
  • Restart your computer.
  • Gently tap the F8 key repeatedly to enter the Advanced Boot Options menu.

Note: If Windows launches before you can choose Safe Mode, restart your computer and try again.

  • Select the Safe Mode option using the up and down arrow keys.
  • Then, press the enter key on your keyboard to boot into Safe Mode.
[external image: Posted Image]
  • Wait for the Windows 7 files to load, then log into your usual account.

Note: When tasks have been completed, reboot your computer to normal mode.

CHECKLIST: In your next reply, please post the following:
  • OTL log
  • checkup.txt
Hi fbfbfb,
Thanks again,
F8 would not work for booting up safe mode, so I chose the option in Msconfig.
Please see results of scans below.

Regards,
Kevin

========== OTL ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 07272013_093704


Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is enabled)
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Bitdefender Antivirus
Antivirus out of date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.70.0.1100
Out of date Malwarebytes Anti-Malware installed!
Java 7 Update 25
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 21.0 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
Hello, Kevin.

Your OTL log is clean. Good job starting Security Check. Let's take care of your outdated applications:

Windows Security Center (service is not running)

To check if Windows Security Center is running, do the following:
  • Click Start > Settings > Control Panel > Administrative Tools > Services
  • Scroll down the Services list, and locate Security Center.
  • Look under the Status column, and see if the service is Started. If not, click on Security Center to highlight it.
  • In the top left corner, under Security Center, look for and click Restart the service.
  • Exit the screen.
Antivirus out of date

Please visit the Bitdefender website HERE to update your antivirus software.

Multiple Anti-Spyware software

You presently have 2 anti-spyware applications installed on your system: Windows Defender and Bitdefender Anti-Spyware. Both these programs have real time monitoring abilities. Running more than one set of spyware monitoring components can cause conflicts and can sometimes lead to unexpected complications and system slowdowns. Please ensure that only one program is monitoring your system at any given time and the other is turned off. You can activate the other program when you need to take second look at your system.

Malwarebytes Anti-Malware

You can keep your Malwarebytes Anti-Malware database updated even when offline. Visit this LINK.

Adobe Reader

Updates to Adobe Reader safeguard your system against malicious attacks through PDF files.You are currently running Adobe Reader 9. Please update to Adobe Reader 11 (11.0.03) HERE to improve the functionaility and security of your software.

Firefox

Please check Mozilla Support HERE to update to the latest Firefox.

Please run the following scan

I would like to take one last look at your system to ensure everything is fine. Please send me a fresh DDS log.

Please let me know if there are any other issues we need to address. If not, I will walk you through a bit of housekeeping in my next post.
Thank you fbfbfb, Please find scan results below and attached. I am a bit confused about Bitdefender being out of date as I thought It was the current version(2013). As far as my outdated applications is concerned, please note the following: Windows Security Centre reads as started with Auto delay start. Bitdefender 2013 states that I have 49 days left before expiry, should I update now as you advise? Windows Defender is turned off. I have updated Malwarebytes application to latest version. I have just installed Adobe reader XI. Firefox is rarely used, but I will update as you advised. Best regards, Kevin DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.25.2 Run by [removed] at 13:55:31 on 2013-07-28 Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8183.6259 [GMT 8:00] . AV: Bitdefender Antivirus *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Bitdefender Antispyware *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09} FW: Bitdefender Firewall *Enabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\SysWOW64\nlssrv32.exe C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Windows\SysWOW64\NOTEPAD.EXE C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.iinet.net.au/home mStart Page = about:blank mWinlogon: Userinit = userinit.exe BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: FlashFXP Helper for Internet Explorer: {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files (x86)\FlashFXP \IEFlash.dll uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [AdobeBridge] mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" - launchedbylogin mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent dRun: [20090604] C:\Program Files (x86)\Broderbund\Mavis Beacon Platinum - 25th Anniversary Edition\RegApp\encore_reg.exe /r "C:\Program Files (x86)\Broderbund\Mavis Beacon Platinum - 25th Anniversary Edition\RegApp\encore_reg.rpd" mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: Interfaces\{6910964C-D373-4ADB-83FB-0546BA7C3200} : NameServer = 192.168.1.254 SSODL: WebCheck - x64-mStart Page = about:blank x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Run: [Bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\wmysdnwa.default\ FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll . ============= SERVICES / DRIVERS =============== . R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2013-4-26 718840] R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2013-3-29 147232] R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\BitDefender\BitDefender Firewall \bdfndisf6.sys [2013-4-26 93600] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2012-9-8 103504] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-4-7 202752] R2 nlsX86cc;This service enables products that use the Nalpeiron Licensing System.;C:\Windows\SysWOW64\nlssrv32.exe [2011-9- 23 66560] R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [2013-7-15 67320] R3 avchv;avchv Function Driver;C:\Windows\System32\drivers\avchv.sys [2012-9-8 261056] R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2013-7-15 597776] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-22 215040] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-6-22 1235968] R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework \v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET \Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2012-10-24 82384] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-2-16 99384] S3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2010-7-6 19544] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2012-5-11 203320] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-9-5 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-10 1255736] S4 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [2013-3-29 69392] . =============== Created Last 30 ================ . 2013-07-27 02:25:43 ——– d—–w- C:\Windows\pss 2013-07-25 23:08:42 ——– d—–w- C:\Windows\ERUNT 2013-07-25 22:48:13 ——– d—–w- C:\_OTL 2013-07-15 11:58:54 597776 —-a-w- C:\Windows\System32\drivers\avckf.sys . ==================== Find3M ==================== . 2013-07-15 11:05:56 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-15 11:05:56 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-25 11:31:10 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-25 11:31:09 867240 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2013-06-25 11:31:09 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-05-29 15:06:25 382536 —-a-w- C:\Windows\System32\drivers\trufos.sys . ============= FINISH: 13:55:43.06 =============== 📎Attach.txt
Hello, Kevin. Your DDS log looks very good. In answer to a few of your questions/concerns:

1. Confused about Bitdefender being out of date

With Bitdefender, you can choose to update virus definitions and/or update the product itself. In the last post, I gave you directions to update the latest virus definitions. This time, you may wish to update Bitdefender 2013 to a newer version, free of charge, by visiting this LINK. This should take care of any update messages you have received.

2. Windows Security Center reads as started with Auto delay start.

This is fine. This service is a delayed start-up and begins shortly after the system has finished starting up in order to reduce the strain of of the boot process.

3. Bitdefender 2013 expiry

If you are happy with Bitdefender and wish to renew your software, you can do so closer to the expiry date. You may want to review your purchase agreement to see if you were automatically signed up for auto-renewal. Many people who have purchased Bitdefender, and who have chosen not to renew, had their subscription renewed without their approval as they were not aware of the auto-renewal terms.

If you prefer to try a good, reputable, free antivirus program, please visit this LINK.

If you have no further questions or concerns, and your computer is working satisfactorily, please work through the following steps to ensure that unnecessary programs and files have been removed and your system is up-to-date.

CleanUp with OTL
  • Double-click OTL.exe to run it. (Vista/Win7 users, please right click on OTL.exe and select "Run as an Administrator.")
  • Close all other programs apart from OTL as this step will require a reboot.
  • On the OTL main screen, click on the CleanUp! button.
  • Click Yes to begin the Cleanup process, and then allow the program to reboot your computer.
  • After the reboot, delete any tools we used from your desktop.
Tool Removal

You no longer need the following tools. Please delete these and any logs from your machine: DDS, AdwCleaner, JRT, and Security Check.

Clean Up Temp Files

Please download TFC by OldTimer to your desktop.
  • Close any open windows.
  • Double click the TFC icon to run the program.
  • TFC will close all open programs itself in order to run.
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish.
  • Once complete, it should automatically reboot your machine.
  • If your computer does not automatically reboot, manually reboot to ensure a complete clean.
Update Internet Explorer

You are currently running IE 8. You can download the latest version of Internet Explorer HERE.

Turn On Automatic Updates

You can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
  • Click Start > click Control Panel > Click Windows Update.
  • In the left pane, click Change Settings.
  • Under Important Updates, click the down arrow and select Install updates automatically (recommended).
  • Under Recommended Updates, check Give me updates the same way I receive Important Updates.
  • Under Who can install updates, check Allow all users to install updates on this computer.
  • Click OK to apply the changes.

    Note: If Windows prompts you to confirm these changes, allow it.

  • Close the window.
Recommended Reading

To help you maintain a clean, safe, and healthy system, the following informative articles may be of interest to you:

How to Prevent Malware by Miekiemoes HERE
So How Did I Get Infected In the First Place? By Tony Klein HERE
Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams HERE
PC Safety and Security – What do I need to do? by Glaswegian HERE

Please respond to this thread one last time so that we can mark the problem solved and close this topic.

Wishing you always a safe browsing experience.
~fbfbfb
Hi fbfbfb, Thanks, Everything was fine until I activated Windows updates. Windows downloaded and installed 59 important updates, then restarted to configure the updates but failed and reverted the changes. I attempted this 3 times and my hard drive has been grinding away for about an hour. I now have IE10 which was an update I was not sure I really wanted, but I guess it is ok. Could you please advise if I have stuffed something up. Many thanks,Kevin
Hello, Kevin.

Regarding Internet Explorer 10, you may wish to give it a chance. IE10 is Microsoft's most secure web browser and features many security and privacy enhancements. For example, websites are barred by default from collecting your private information, offers more security against malware attacks, and prevents any modification to your browser settings without your approval. It also better supports today's web standards and is considerably faster than past versions.

Regarding Windows Updates, you have done nothing wrong during the update process; sometimes, updating Windows is just a bit finicky. Try the following option to resolve any update issues.

1. Microsoft Fixit

Please download the Microsoft Fixit tool from HERE.
  • Click Run now .
  • Click Save File.
  • Double click the saved file (MicrosoftFixit.wu.LB.1482…Run.exe) to run it and follow the prompts.
  • Reboot your computer.
Are you still receiving the failure configuring windows updates reverting changes error message? If so, follow the next step.

2. Check Update History

Checking the update history allows you to see if any of the updates have a failed status.
  • To open Windows Update, click Start.
  • In the search box, type Update, click Windows Update in the list of results.
  • In the left pane, click View update history.
Are there any updates that show a failed status? If so, please send me the description of the updates that have failed to install.

Let's see where we stand before we go any further.
Hi fbfbfb, Apologies for the late response, The reason is as follows. I ran the Microsoft fixit tool and attempted to install the updates again. They failed again twice. So I thought I would install the updates in batches of 10, then 5, etc and to my surprise I managed to get them all successfully installed. This took some time with numerous restarts, but at least they are all in now.There were quite a few updates that were attempting to generate restore points. I am probably wrong, but would this have been a likely cause of failure. Please let me know if you want me to do anything further. Thanks and regards, Kevin
Hello, Kevin.

I'm glad to know that you have successfully installed all your updates. It is possible that the difficulty installing them was due to the attempts to create restore points. There could be other possibilities as well including monitoring programs that run in the background (anti-spyware, anti-virus, third party firewalls, proxy servers, . . . .), the need to download the latest Windows Installer, and even simply trying to install updates during peak hours.

Unless you have any other concerns, there is nothing more I need you to do. Please let me know before I close this topic.
Hi fbfbfb, I think that is it for now. Many thanks for your help, it has been much appreciated and your prompt response to my messages was outstanding. Best regards, Kevin

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI