This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infested computer

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix log and HJT log (after combofix was run)

IE still getting redirected :(

ComboFix 08-11-23.02 - Owner 2008-11-24 18:50:28.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.43 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.

2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-23 15:11 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-23 14:28 . 2008-11-23 14:28 d——– c:\program files\Trend Micro
2008-11-23 13:58 . 2008-11-23 14:30 d——– C:\HIJACK LOG
2008-11-23 12:45 . 2008-11-23 12:45 d——– c:\program files\NoAdware
2008-11-23 11:36 . 2008-11-23 11:37 d——– c:\program files\Easy SpyRemover
2008-11-23 11:35 . 2008-11-23 11:35 d——– c:\program files\ERUNT
2008-11-19 23:38 . 2008-11-23 15:20 d–h—– C:\$AVG8.VAULT$
2008-11-19 22:07 . 2008-11-19 22:07 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-11-19 22:07 . 2008-11-19 22:07 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-11-19 22:06 . 2008-11-24 16:33 d——– c:\windows\system32\drivers\Avg
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\program files\AVG
2008-11-19 22:06 . 2008-11-23 10:53 d——– c:\documents and settings\Owner\Application Data\AVGTOOLBAR
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\documents and settings\All Users\Application Data\avg8
2008-11-19 21:39 . 2008-11-19 21:39 d——– c:\documents and settings\All Users\Application Data\America Online
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\scripting
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\en
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\l2schemas
2008-11-19 17:27 . 2008-09-04 11:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-19 17:27 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-18 18:16 . 2008-11-18 18:22 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-18 18:13 . 2008-11-18 18:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-18 16:38 . 2008-11-18 16:38 53,938 –a—— c:\windows\system32\cont_adsoftinc-remove.exe
2008-11-18 16:36 . 2008-04-13 12:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-07 09:25 . 2008-11-23 11:01 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-07 09:25 . 2008-11-07 09:25 1,409 –a—— c:\windows\QTFont.for
2008-11-07 08:02 . 2008-11-07 08:02 118 –a—— c:\windows\system32\MRT.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 05:49 ——— d—–w c:\program files\Java
2008-11-19 03:41 ——— d—–w c:\program files\SpywareGuard
2008-11-19 03:37 ——— d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2008-11-19 00:19 ——— d—–w c:\program files\Lavasoft
2008-11-19 00:19 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2008-11-11 20:27 ——— d—–w c:\program files\Zune
2008-11-09 18:29 30 —-a-w c:\documents and settings\Owner\jagex_runescape_preferences.dat
2008-10-25 16:54 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-10 12:02 ——— d—–w c:\documents and settings\Owner\Application Data\U3
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-19 1234712]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CompuServe 2000 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CompuServe 2000 Tray Icon.lnk
backup=c:\windows\pss\CompuServe 2000 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
–a—— 2002-06-18 00:11 69632 c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\checktime]
–a–c— 2002-01-26 14:05 45056 c:\program files\HPSelect\frontend\ct.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy SpyRemover]
–a—— 2008-11-18 14:20 4011760 c:\program files\Easy SpyRemover\EasySpyRemover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2002-05-15 04:29 155648 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 09:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2001-07-06 22:56 61440 c:\hp\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-09-22 18:20 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2002-06-14 17:39 81920 c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 22:37 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2003-11-16 08:46 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2001-12-19 00:39 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
–a—— 2002-05-09 09:01 155648 c:\program files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"28938:TCP"= 28938:TCP:*:Disabled:SolidNetworkManager
"28938:UDP"= 28938:UDP:*:Disabled:SolidNetworkManager

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-19 97928]
R1 RCFOX;SonicWALL IPsec Driver;\??\c:\windows\system32\Drivers\RCFOX.sys [2008-05-17 101528]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-19 231704]
R2 PackethSvc;Virtual NIC Service;c:\windows\system32\PackethSvc.exe [2003-11-16 64512]
R2 zumbus;Zune Bus Enumerator Driver;c:\windows\system32\DRIVERS\zumbus.sys [2008-01-11 40832]
R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\DRIVERS\rcvpn.sys [2008-05-17 24876]
S4 hpt3xx;hpt3xx; []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921c-ceb1-11db-8e86-00402b4b6c81}]
\Shell\AutoRun\command - F:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2007-01-19 c:\windows\Tasks\easy Internet sign-up.job
- c:\program files\Hewlett-Packard\EZ Internet Signup\HPSdpApp.exe [2002-04-19 22:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-24 18:59:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-24 19:05:28
ComboFix-quarantined-files.txt 2008-11-25 01:04:59
ComboFix2.txt 2008-11-24 01:44:07

Pre-Run: 13,443,313,664 bytes free
Post-Run: 13,430,484,992 bytes free

167 — E O F — 2008-11-24 03:13:37

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:08:48 PM, on 11/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227054735773
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

–
End of file - 5294 bytes
I have no idea why AVG has hijacked IE

NoAdware claims to be a serious antispyware application. It gives warnings for false positives and cookies from sites used by it thus urging the user to buy the software.

Easy SpyRemover is a corrupt anti-spyware program that uses false positives.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\program files\Hewlett-Packard\EZ Internet Signup\HPSdpApp.exe

Folder::
c:\program files\NoAdware
c:\program files\Easy SpyRemover

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy SpyRemover]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Both programs that you mentioned are recommended downloads on this site!

AVG hijacking - I had a problem with AVE on a DB program I had helped in setting up… ummm, can't think of the name of it right now and no longer have it loaded on any of my computers. Had to remove AVG because it messed with the coding (sure wish I could remember the name of the program!!!! gonna IM the programmer for the name so I can tell you which program it is.) VFP - FP, Visual Fox Pro, Fox Pro (I think, haven't received confirmation from programmer yet)

So, maybe need to uninstall AVG and go with another freebie antivirus?

Both programs that you mentioned are recommended downloads on this site!

AVG hijacking - I had a problem with AVE on a DB program I had helped in setting up… ummm, can't think of the name of it right now and no longer have it loaded on any of my computers. Had to remove AVG because it messed with the coding (sure wish I could remember the name of the program!!!! gonna IM the programmer for the name so I can tell you which program it is.)

So, maybe need to uninstall AVG and go with another freebie antivirus?

We really don't have much control on those Google ads. Google pays the site owner to post ads. Once you have registered and logged in, you won't see those ads.

I would uninstall AVG8,

Try one of these:


avast! 4
http://www.avast.com/eng/download-avast-home.html

Or

Avira AntiVir Personal - FREE Antivirus
http://www.free-av.com/en/download/1/downl…_antivirus.html
Umm, they weren't adds, they were in one of the self help forums :( but know what you mean about the adds you see before logging in and understand why they have to have them.

avast was the recommended anti virus program by the programmer I worked with. I really thought it was more specific to VFP than "in general" programs, guess I was wrong. Having said that, I have not checked this computer for specialty software, only asked if they had any.

Will remove AVG after Combofix runs. Then will re-run it and HJT then post results from both (with info on how computer is running).

It probably wont be tonight. Have to get some work done for a company I consult for.

Thank you again for all your help. Really wish I could stay on task with this as we are sooo close to getting it cleaned up!!!

Warning, I'll be back tomorrow PM. LOL
I warned you I would come back lol Log into WTT and click Home - on the right side are (you were right - ads) for these products. I did misspeak - I didn't see them in a forum. Guess I had been to to many areas to remember correctly. Ashame they can't put good free product adds on the front page. Getting ready to remove AVG and load another antivirus program (probably avast). I will let you know if everything is clear, which I am sure it will be. Again, many many thanks for your help. Boss and his family appreciate it as well :D
All done and everything that I have tried is working well. Avast found one Trojan and I had it clean it up. Can't thank you enough for your support and quick responses!!! Enjoy your holidays!!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI