View Full Version : Request for help

2013-03-18, 23:35
My children have been downloading stuff which has changed search engine and possibly infected my PC with spyware/malware. Would like to request assistance please.

DDS (Ver_2012-11-20.01)
Internet Explorer: 9.0.8112.16470
Run by Rick at 6:49:41 on 2013-03-18
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.1155 [GMT 0:00]
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
2013-03-20, 03:09
Hello nellie. :snwelcome:

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your DDS log now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
Please be patient. Logs are lengthy and can take time to analyze.
Read and follow my directions carefully, in the sequence they are posted. If you are unsure about anything, please ask for clarification before continuing.
Use only those tools that you have been directed to use.
Do not install or uninstall any applications or run any other scans without being directed to do so.
Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
Stay with me until your machine has been deemed all clear.
Please reply within 3 days to avoid closing this topic.

2013-03-21, 04:29
Hello, nellie.

Your DDS log shows several entries that require attention. I would like to take a closer look at your system.

Please run the following scans

1. aswMBR

Please download aswMBR from HERE (public.avast.com/~gmerek/aswMBR.exe).
Double click aswMBR.exe to run it.
When asked if you want to download Avast's virus definitions, please select Yes.
Click the Scan button to start the scan.
On completion of the scan, click save log, save it to your desktop, and post in your next reply.

2. TDSSKiller

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)

Extract it to your desktop
Double click TDSSKiller.exe
When the window opens, click on Change Parameters.
Under Additional options, put a check mark in the box next to Detect TDLFS File System.
Click OK.
Press Start Scan.
As we are only looking for a log of what is on the machine right now, choose to skip whatever is found.
Then click Continue > Reboot now.
Copy and paste the log in your next reply.

A copy of the log will be saved automatically to the root of the drive (typically C:\)

2013-03-23, 01:20
Hello, nellie.

Do you still need help?

2013-03-23, 10:36
Hello fbfbfb, yes I still require help. Please find logs requested below. I have put in two posts as the character count was too long for a single post.


2013-03-23, 20:51
Hello, nellie.

Thank you for the logs. These logs appear to be clean. Please continue with the following scan:

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings. Please download ComboFix from HERE (http://www.bleepingcomputer.com/download/combofix/dl/12/) or HERE (http://www.infospyware.net/antimalware/combofix/).Very Important! Save ComboFix.exe to to your Desktop.
Close all browsers.
Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:
Right click on the System Tray icon, or
Refer to this link HERE (http://forums.whatthetech.com/index.php?showtopic=96260&pid=494216#entry494216) for further assistance. Double click on ComboFix.exe and follow the prompts.
When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.Warnings:
Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
Do not attempt to surf the internet while ComboFix is scanning.
Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2013-03-24, 18:28
I have run combofix but it has not left my computrer in a good state. It now keeps hanging completely and the network connection has been lost so i am unable to connect to the internet!

The log file below has been uploaded via another computer within the household.


2013-03-25, 02:42
Hello, nellie.

A lost internet connection can sometimes occur as the result of infections being removed from your system. Let's try to restore your internet connection manually.

If you already tried to reboot your computer and still could not connect to the internet, please follow these steps:
Click on the Start button.
Click on the Settings menu option.
Click on the Control Panel option.
When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
You will now see a menu similar to the image below. Simply click on the Repair menu option.
http://www.bleepstatic.com/combofix/en/repair.jpg Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.
OR If your network icon also appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair as shown below.
If your internet connection has been restored, please continue with the next step.

Please run the following scan

Farbar Service Scanner

Please download Farbar Service Scanner from HERE (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and save the file to your desktop.
Run the tool on the infected machine.
Ensure the following options are checked:

Internet Services
Windows Firewall
System Restore
Security Center
Windows Update
Windows Defender Click on Scan.
It will create a log (FSS.txt) in the same directory the tool is run.Please copy and paste the log into your next reply.

2013-03-25, 11:40
Hi thanks for the response. I am using Windows 7 not XP and don't see the option to 'repair' a network connection. I have tried the 'Troubleshoot problems' button but it is suggesting the issue is with my router even though it is clearly not! Gotta love Microsoft (!). Is there an equivalent 'repair' option on Windows 7?

Also for your info, since i used Combofix the PC seems to have developed a serious resource issue in that after it boots up the CPU and memory are heavily utilised and the amount of virtual memory committed to 'services.exe' creeps up and up until the PC crashes.

2013-03-25, 23:49
I managed to repair the network issue. Here is the FSS log.

Farbar Service Scanner Version: 03-03-2013
Ran by Rick (administrator) on 25-03-2013 at 21:47:53
Running from "C:\Users\Rick\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal

Internet Services:

Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.

Windows Firewall:

Firewall Disabled Policy:

System Restore:

System Restore Disabled Policy:

Action Center:

Windows Update:

Windows Autoupdate Disabled Policy:

Windows Defender:
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]

Other Services:

File Check:
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit

**** End of log ****

2013-03-26, 02:59
Hello, nellie.

Thank you for the FSS log. Glad you were able to resolve your internet connection issue. Let's work to restore the functionality of your system.

Please run the following scan

Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
Start > Run.
Type notepad in the Open field
Click OK.
Copy and paste the text inside the code box below:


C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
C:\Program Files (x86)\Solid Savings\Solid Savings.dll
C:\Program Files (x86)\Delta\delta\\bh\delta.dll
c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll c:\progra~3\browse~1\261095~1.52\{c16c1~1\browserprotect.dll

C:\Program Files (x86)\Optimizer Pro
C:\Program Files (x86)\PriceGong
C:\Users\Rick\AppData\Local\Solid Savings
C:\Program Files (x86)\Solid Savings
C:\Program Files (x86)\Delta
C:\Program Files (x86)\Wajam

[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211621178}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
"Optimizer Pro"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.

Please let me know how your computer is running at this stage.

2013-03-27, 00:40
Hi fbfbfb

computer is running much better at this stage thank you.

Below are requested logs from combofix after running with your script as input.


ComboFix 13-03-26.01 - Rick 26/03/2013 22:26:07.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.1730 [GMT 0:00]
Running from: c:\users\Rick\Desktop\ComboFix.exe
Command switches used :: c:\users\Rick\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
"c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll c:\progra~3\browse~1\261095~1.52\{c16c1~1\browserprotect.dll"
"c:\program files (x86)\Delta\delta\\bh\delta.dll"
"c:\program files (x86)\Optimizer Pro\OptProLauncher.exe"
"c:\program files (x86)\Solid Savings\Solid Savings.dll"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
c:\program files (x86)\Delta
c:\program files (x86)\Delta\delta\\bh\delta.dll
c:\program files (x86)\Delta\delta\\deltaApp.dll
c:\program files (x86)\Delta\delta\\deltaEng.dll
c:\program files (x86)\Delta\delta\\deltasrv.exe
c:\program files (x86)\Delta\delta\\deltaTlbr.dll
c:\program files (x86)\Delta\delta\\escortShld.dll
c:\program files (x86)\Delta\delta\\GUninstaller.exe
c:\program files (x86)\Delta\delta\\uninstall.exe
c:\program files (x86)\Optimizer Pro
c:\program files (x86)\Optimizer Pro\OptimizerPro.exe
c:\program files (x86)\Optimizer Pro\OptProGuard.exe
c:\program files (x86)\Optimizer Pro\OptProLauncher.exe
c:\program files (x86)\Optimizer Pro\OptProReminder.exe
c:\program files (x86)\Optimizer Pro\OptProSchedule.exe
c:\program files (x86)\Optimizer Pro\OptProSmartScan.exe
c:\program files (x86)\Optimizer Pro\OptProStart.exe
c:\program files (x86)\Optimizer Pro\OptProUninstaller.exe
c:\program files (x86)\Optimizer Pro\unins000.dat
c:\users\Rick\AppData\Local\Solid Savings
---- Previous Run -------
((((((((((((((((((((((((( Files Created from 2013-02-26 to 2013-03-26 )))))))))))))))))))))))))))))))
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\Megan.26NC-PC\AppData\Local\temp
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\Kate\AppData\Local\temp
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\hedev\AppData\Local\temp
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\Alfie\AppData\Local\temp
2013-03-26 22:35 . 2013-03-26 22:35 -------- d-----w- c:\users\Alfie.26NC-PC\AppData\Local\temp
2013-03-26 22:20 . 2013-03-14 23:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{45868155-17A4-4721-9198-554AFF9922E3}\mpengine.dll
2013-03-25 22:15 . 2013-03-25 22:15 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D5F599EB-B21C-4B32-B5A8-A087EA46E282}\gapaengine.dll
2013-03-25 22:15 . 2013-03-14 23:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-25 22:13 . 2013-03-25 22:13 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2013-03-25 22:13 . 2013-03-25 22:13 -------- d-----w- c:\program files\Microsoft Security Client
2013-03-25 22:07 . 2013-03-19 05:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02C2F498-B349-4EA6-A7DC-9E7C2C97B8E9}\mpengine.dll
2013-03-25 22:06 . 2013-03-25 22:07 -------- d-----w- c:\users\Rick\AppData\Local\Avg2013
2013-03-18 06:48 . 2013-03-18 06:48 -------- d-----w- c:\program files (x86)\ERUNT
2013-03-17 11:59 . 2013-03-17 12:00 -------- d-----w- c:\users\Rick\AppData\Roaming\Kingsoft
2013-03-17 11:59 . 2013-03-17 11:59 -------- d-----w- c:\programdata\Kingsoft
2013-03-17 11:59 . 2013-03-17 11:59 -------- d-----w- c:\program files (x86)\Kingsoft
2013-03-17 11:56 . 1998-06-24 00:00 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-03-17 11:56 . 2005-03-12 00:07 87040 ----a-w- c:\windows\system32\pdfcmnnt.dll
2013-03-17 11:56 . 2013-03-17 11:56 -------- d-----w- c:\program files (x86)\PDFCreator
2013-03-17 11:56 . 1998-07-06 00:00 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-03-17 11:54 . 2013-03-17 11:54 -------- d-----w- c:\windows\SysWow64\searchplugins
2013-03-17 11:54 . 2013-03-17 11:54 -------- d-----w- c:\windows\SysWow64\Extensions
2013-03-16 06:30 . 2013-03-16 06:30 4546560 ----a-w- c:\windows\SysWow64\GPhotos.scr
2013-03-12 15:33 . 2013-03-12 15:33 -------- d-----w- c:\program files\iPod
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\program files\iTunes
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\program files (x86)\iTunes
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-03-14 23:18 . 2009-11-09 22:15 72013344 ----a-w- c:\windows\system32\MRT.exe
2013-03-14 12:15 . 2012-04-10 07:10 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-14 12:15 . 2011-06-03 11:06 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-12 05:45 . 2013-03-14 11:35 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-14 11:35 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-14 11:35 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-14 11:35 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-14 11:35 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-14 11:35 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-01-30 10:53 . 2009-11-09 22:22 273840 ------w- c:\windows\system32\MpSigStub.exe
2013-01-20 15:59 . 2013-01-20 15:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 15:59 . 2013-01-20 15:59 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-05 05:53 . 2013-02-13 17:26 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-05 05:00 . 2013-02-13 17:26 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00 . 2013-02-13 17:26 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-01-04 05:46 . 2013-02-13 17:26 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 04:51 . 2013-02-13 17:26 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-01-04 04:43 . 2013-02-13 17:26 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-01-04 03:26 . 2013-02-13 17:26 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-01-04 02:47 . 2013-02-13 17:26 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-01-04 02:47 . 2013-02-13 17:26 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-01-04 02:47 . 2013-02-13 17:26 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-01-04 02:47 . 2013-02-13 17:26 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-01-03 06:00 . 2013-02-13 17:26 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 06:00 . 2013-02-13 17:26 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2011-07-17 09:37 . 2011-09-28 18:05 161744 ----a-w- c:\program files (x86)\u4res.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [BU]
"Spotify Web Helper"="c:\users\Rick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-10-12 1193176]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118624]
"dellsupportcenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [BU]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-05-05 25600]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"ServiceManager.exe"="c:\program files (x86)\Virgin Media\Service Manager\ServiceManager.exe" [2011-03-25 4371768]
"DHSClient.exe"="c:\program files (x86)\Virgin Media\Digital Home Support\DHSClient.exe" [2011-03-23 2032952]
"HF_G_Jul"="c:\program files (x86)\AVG Secure Search\HF_G_Jul.exe" [BU]
"Check Point Endpoint Security"="c:\program files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe" [2010-09-26 738824]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
c:\users\Rick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Rick\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HD Writer.lnk - c:\program files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe [2012-1-13 292240]
PURE FlowServer Tray Control.lnk - c:\program files (x86)\PURE Flow Server\twonkymediaserverconfig.exe [2010-12-20 194136]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-06-04 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-06-04 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-05-05 202840]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-05-05 1417304]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-05-05 94808]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 RapportKE64;RapportKE64;c:\windows\system32\Drivers\RapportKE64.sys [2011-09-25 64272]
R3 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-11-07 61712]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2008-10-24 43008]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2007-12-03 24064]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2008-10-24 43008]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1255736]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 RapportCerberus_43926;RapportCerberus_43926;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-30 505720]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-11-07 55056]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-26 203776]
S2 HsdService;HsdService;c:\program files (x86)\Virgin Media\Digital Home Support\HsdService.exe [2011-03-23 1406264]
S2 PURE Flow Server;PURE Flow Server;c:\program files (x86)\PURE Flow Server\twonkymediaserverwatchdog.exe [2010-12-20 153176]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-11-07 931640]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2007-12-11 26624]
S2 ServicepointService;ServicepointService;c:\program files (x86)\Virgin Media\Service Manager\ServicepointService.exe [2011-03-25 689464]
S2 TracSrvWrapper;Check Point Endpoint Security;c:\program files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe [2010-09-26 4142608]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-05-05 202840]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-05-05 1417304]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-05-05 94808]
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 vna_ap;Check Point Virtual Network Adapter - Apollo;c:\windows\system32\DRIVERS\vnaap.sys [2010-09-26 161256]
Contents of the 'Scheduled Tasks' folder
2013-03-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-10 12:15]
2013-03-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1003Core.job
- c:\users\Megan.26NC-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-16 17:05]
2013-03-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1003UA.job
- c:\users\Megan.26NC-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-16 17:05]
2013-03-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1001Core.job
- c:\users\Rick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 12:59]
2013-03-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1001UA.job
- c:\users\Rick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 12:59]
2013-03-12 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
2013-01-22 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-20 16:07]
2013-03-26 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
2013-03-26 c:\windows\Tasks\WpsUpdateTask_Rick.job
- c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2011-10-29 16:00]
--------- X64 Entries -----------
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
"VX3000"="c:\windows\vVX3000.exe" [2009-06-30 762224]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
------- Supplementary Scan -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.delta-search.com/?affID=121240&babsrc=HP_ss&mntrId=14AD54335A199D0E
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer =
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - (no file)
BHO-{C1AF5FA5-852C-4C90-812E-A7F75E011D87} - c:\program files (x86)\Delta\delta\\bh\delta.dll
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
WebBrowser-{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - (no file)
HKLM-Run-PocketCloud Location - c:\program files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-delta - c:\program files (x86)\Delta\delta\\GUninstaller.exe
AddRemove-Optimizer Pro_is1 - c:\program files (x86)\Optimizer Pro\unins000.exe
AddRemove-Spotify - c:\users\Rick\AppData\Roaming\Spotify\Spotify.exe
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
@Denied: (Full) (Everyone)
Completion time: 2013-03-26 22:38:02
ComboFix-quarantined-files.txt 2013-03-26 22:38
Pre-Run: 332,458,659,840 bytes free
Post-Run: 332,177,997,824 bytes free
- - End Of File - - 63DBE5215A7DC2B7A7AB5F69B7B46DF4

2013-03-27, 15:03
Hello, nellie.

Thank you for the CF log. Glad your computer is showing improvement.

Please continue with the following tasks

1. Uninstall Programs/Toolbars

We need to uninstall: Browser Protect, Quickshare, and Solid Savings.
Click Start and select Control Panel.
When the Control Panel window opens, click on Uninstall a program found under the Programs category.
If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Look through the list of programs, locate Browser Protect, and then left-click on it once to highlight it.
Click on the Uninstall button.
When asked if you are sure you want to uninstall, click Yes.
The program will uninstall, and when completed, you will be back at the list of programs installed on your computer.
Repeat these steps to uninstall the other 2 programs.
When finished, close the Programs and Features screen2. Uninstall Programs/Toolbars from Internet Explorer

If any of these programs (Browser Protect, Quickshare, Solid Savings) or the Smartbar Toolbar still appear in your browser, continue as follows:
Open Internet Explorer.
Click Tools > Manage Add-ons.
In the Manage Add-ons window, under Add-on Types (found on left side) highlight Toolbars and Extensions.
Under the Show: drop-down menu (found on left side) make sure All add-ons is selected.
Highlight the programs/toolbar you wish to remove, and select Disable.
The Disable add-on window may pop up to warn you that related services and add-ons will also be disabled. Click Disable.
Click Close to dismiss the add-ons window.3. Reset Your Home Page and Default Search Engine

Removing toolbars during the clean-up process may have changed your browser settings (homepage, default search engines). If so, please follow the instructions found HERE (http://eula.mindspark.com/reset-homepage-default-search-settings/).

Please run the following scans

1. Junkware Removal Tool

Please download Junkware Removal Tool from HERE (http://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/).
This will bring you to a prompt screen showing 2 buttons: Save File and Cancel.
Click on the Save File button. The file jrt.exe should save to your desktop or in another location such as your downloads folder.
Locate jrt.exe and double click it to start.
Note: If you receive a prompt asking if you want to open this executable file, click OK. Otherwise continue to the next step. Click Run. A black information screen appears. Click any key to continue.
JRT will begin to backup your registry and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

2. AdwCleaner

Please download AdwCleaner from HERE (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/).
This will bring you to a prompt screen showing 2 buttons: Save File and Cancel.
Click on the Save File button. The file adwcleaner.exe should save to your desktop or in another location such as your downloads folder.
Locate adwcleaner.exe and double click it to start.
Note: If you receive a prompt asking if you want to open this executable file, click OK. Otherwise continue to the next step. Click Run and the AdwCleaner screen will appear.
You will see 4 buttons: Click Delete and wait for the scan to finish.
Note: AdwCleaner needs to close all open programs—save any work in progress, then click OK to continue. At the next prompt (AdwCleaner Information screen), click OK.
AdwCleaner will restart your computer.
A report will open on reboot.Copy and paste the adwcleaner.txt report into your next reply.

3. Malwarebytes Anti-Malware

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.

When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.Post the report please.

4. ESET Online Scanner
Note: Disable any antivirus program and antispyware programs to avoid conflicts.
If using Mozilla Firefox, you will need to download esetsmartinstaller_enu.exe when prompted, then double click on it to install.
Please do not surf the internet while your security programs are disabled.
Let the scan run uninterrupted to avoid a stall.
Remember to enable your security programs when the scan has finished.
Run ESET Online Scanner from HERE (http://www.eset.eu/online-scanner).
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box YES, I accept the Terms of Use.
Click on the Start button next to it.
If prompted, allow the Add-On/Active X to install.
Under Computer scan settings:
Do not check Remove found threats
Check Scan Archives.
Click Advanced settings and select the following:
Scan potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth technology Click Start. ESET will download updates, install itself, and begin scanning your computer. Please be patient as this scan could take up to a few hours to complete.
Wait for the scan to finish. When the scan completes, click List of found threats.
Click Export and save the file to your desktop using a unique name, such as ESETScan.
Copy and paste the contents of this report in your next reply.
Click the Back button.
Click the Finish button.
SUMMARY: In your next reply, please post the following:
MBAM log
ESET log
Are there any outstanding issues we need to address?

2013-03-28, 21:31
Ok fbfbfb thats a lot to concentrate on but hopefully we have everything here...

Junkware Removal Tool (JRT) by Thisisu
Version: 4.7.3 (03.23.2013:1)
OS: Windows 7 Home Premium x64
Ran by Rick on 27/03/2013 at 21:24:00.45

~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113}

~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_classes_root\escort.escortiepane
Successfully deleted: [Registry Key] hkey_classes_root\escort.escortiepane.1
Successfully deleted: [Registry Key] hkey_current_user\software\1clickdownload
Successfully deleted: [Registry Key] hkey_local_machine\software\babylon
Successfully deleted: [Registry Key] hkey_current_user\software\babylontoolbar
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Failed to delete: [Registry Key] hkey_local_machine\software\datamngr
Failed to delete: [Registry Key] hkey_current_user\software\datamngr_toolbar
Successfully deleted: [Registry Key] hkey_current_user\software\optimizer pro
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\crossrider
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\pricegong
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escort.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escortapp.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escorteng.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escortlbr.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\esrv.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\delta.deltaappcore
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\delta.deltaappcore.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\esrv.deltaesrvc
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\esrv.deltaesrvc.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\quickshare_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\quickshare_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\wajam_install_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\wajam_install_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\wajamupdater_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\wajamupdater_rasmancs
Failed to delete: [Registry Key] hkey_local_machine\software\wow6432node\datamngr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3196716
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ae07101b-46d4-4a98-af68-0333ea26e113}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{c1af5fa5-852c-4c90-812e-a7f75e011d87}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{c1af5fa5-852c-4c90-812e-a7f75e011d87}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Rick\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Rick\appdata\local\opencandy"
Successfully deleted: [Folder] "C:\Users\Rick\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"

~~~ Event Viewer Logs were cleared

Scan was completed on 27/03/2013 at 21:32:19.32
End of JRT log

# AdwCleaner v2.115 - Logfile created 03/27/2013 at 21:35:22
# Updated 17/03/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Rick - 26NC-PC
# Boot Mode : Normal
# Running from : C:\Users\Rick\Desktop\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

File Deleted : C:\END
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\Users\Alfie.26NC-PC\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Alfie.26NC-PC\AppData\LocalLow\Guffins
Folder Deleted : C:\Users\Alfie.26NC-PC\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Kate\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Kate\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Megan.26NC-PC\AppData\LocalLow\Guffins

***** [Registry] *****

Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\5a28f8dbd38ba40
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\Messenger Plus!\OpenCandy
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{006BFF73-D6B8-4CC0-A982-1E041D625B08}
Key Deleted : HKLM\Software\OpenCandy NSIS SDK
Key Deleted : HKLM\SOFTWARE\Wow6432Node\5a28f8dbd38ba40
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{224469FC-D32A-423E-90C3-0F69EF5724B8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49A32F81-0BA1-4B43-856C-9A61425E5BF1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D22421A9-9464-4365-AE9B-D4AD70B99924}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D22421A9-9464-4365-AE9B-D4AD70B99924}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF777BF5-D424-4519-A61E-2B5BB204894D}
Key Deleted : HKU\S-1-5-21-1546463944-2749064583-3027644177-1005\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}
Key Deleted : HKU\S-1-5-21-1546463944-2749064583-3027644177-1005\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKU\S-1-5-21-1546463944-2749064583-3027644177-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16470

[OK] Registry is clean.

-\\ Google Chrome v25.0.1364.172

File : C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.1815] : homepage = "hxxp://www.delta-search.com/?affID=121240&babsrc=HP_ss&mntrId=14AD54335A199D0E",

-\\ Opera v [Unable to get version]

File : C:\Users\Rick\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.


AdwCleaner[S1].txt - [5715 octets] - [27/03/2013 21:35:22]

########## EOF - C:\AdwCleaner[S1].txt - [5775 octets] ##########

Malwarebytes Anti-Malware

Database version: v2013.03.27.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rick :: 26NC-PC [administrator]

27/03/2013 21:42:22
mbam-log-2013-03-27 (21-42-22).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 322307
Time elapsed: 7 minute(s), 11 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Rick\Downloads\PDFCreatorSetup.exe (PUP.Adware.InstallCore) -> Quarantined and deleted successfully.
C:\Users\Rick\Downloads\PDFLite.exe (PUP.BundleInstaller.OI) -> Quarantined and deleted successfully.



C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptimizerPro.exe.vir a variant of Win32/SpeedingUpMyPC application
C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir a variant of Win32/Adware.SpeedingUpMyPC.C application
C:\Users\Alfie.26NC-PC\AppData\Local\GuffinsAuto.exe a variant of Win32/AdInstaller application
C:\Users\Megan.26NC-PC\Downloads\Guffins.exe a variant of Win32/AdInstaller application
C:\Users\Rick\AppData\LocalLow\GuffinsEI\Installr\Cache\11040881.exe a variant of Win32/Toolbar.MyWebSearch.O application
C:\Users\Rick\Downloads\BitTorrent-6.4.exe multiple threats
C:\Users\Rick\Downloads\cbsidlm-tr1_5-Nokia_PC_Suite-10598525.exe multiple threats
C:\Users\Rick\Downloads\FreemakeVideoConverterSetup.exe Win32/OpenCandy application
C:\Users\Rick\Downloads\m4a-to-mp3-converter (1).exe a variant of Win32/Bundled.Toolbar.Ask application
C:\Users\Rick\Downloads\m4a-to-mp3-converter.exe a variant of Win32/Bundled.Toolbar.Ask application
C:\Users\Rick\Downloads\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application
C:\Users\Rick\Downloads\reginout_setup.exe multiple threats
C:\Users\Rick\Downloads\Setup.exe a variant of Win32/Adware.iBryte.G application
C:\Users\Rick\Downloads\U2_-_Rattle_And_Hum_(1988)_[XviD_-_AC3_Eng_-_Sub_Ita_Eng_Fra_Esp]_Rockumentary.exe Win32/Adware.1ClickDownload.S application
C:\Users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].rar Win32/HackTool.WpaKill.B application
C:\Users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].ISO Win32/HackTool.WpaKill.B application

2013-03-29, 17:15
Hello, nellie. Thank you for the logs. You have done very well with the workload. Your JRT and ESET logs indicate that there are still some bad entries we need to remove.

Many of the infections on your system appear to be the result of using a P2P (peer-to-peer) file sharing program (µTorrent, Bit Torrent). P2P programs are a major conduit for malicious software. Some P2P programs will expose your personal information to others by default. Some of the P2P programs themselves contain spyware and divulge your internet activities as well as use your computer's resources without your knowledge. Even if you are using a safe P2P program, downloaded files from uncertified sources are often infected. It is strongly recommend that you uninstall any P2P programs you have on your system. You can uninstall your P2P programs from the Programs list. Should you decide to keep the program, be aware that you will most likely be reinfected.

Please take the time to read through the following articles:

The Dangers of P2P File Sharing HERE (http://www.esecurityguy.com/p2p_file_sharing)
P2P Programs: Popular and Perilous by Robert P. Lipschutz and John Clyman HERE (http://www.pcpitstop.com/spycheck/p2p.asp)

Please work through the following tasks

1. Uninstall Toolbars from Internet Explorer

If any of these toolbars (Datamngr, iLivid, or Searchqu) still appear in your browser, continue as follows:
Open Internet Explorer.
Click Tools > Manage Add-ons.
In the Manage Add-ons window, under Add-on Types (found on left side) highlight Toolbars and Extensions.
Under the Show: drop-down menu (found on left side) make sure All add-ons is selected.
Highlight the toolbars you wish to remove, and select Disable.
The Disable add-on window may pop up to warn you that related services and add-ons will also be disabled. Click Disable.
Click Close to dismiss the add-ons window.2. Reset Your Home Page and Default Search Engine

Removing the toolbars may have changed your browser settings (homepage, default search engines). If so, please follow the instructions found HERE (http://eula.mindspark.com/reset-homepage-default-search-settings/).

Please run the following CF scan

Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
Start > Run.
Type notepad in the Open field
Click OK.
Copy and paste the text inside the code box below:


C:\Users\Rick\Downloads\m4a-to-mp3-converter (1).exe
C:\Users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].rar
C:\Users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].ISO

Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2013-04-01, 23:23
ComboFix 13-04-01.01 - Rick 01/04/2013 21:07:02.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.2241 [GMT 1:00]
Running from: c:\users\Rick\Desktop\ComboFix.exe
Command switches used :: c:\users\Rick\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
"c:\users\Rick\Downloads\m4a-to-mp3-converter (1).exe"
"c:\users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].rar"
"c:\users\Rick\Downloads\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].ISO"
((((((((((((((((((((((((( Files Created from 2013-03-01 to 2013-04-01 )))))))))))))))))))))))))))))))
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\Megan.26NC-PC\AppData\Local\temp
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\Kate\AppData\Local\temp
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\hedev\AppData\Local\temp
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\Alfie\AppData\Local\temp
2013-04-01 20:17 . 2013-04-01 20:17 -------- d-----w- c:\users\Alfie.26NC-PC\AppData\Local\temp
2013-03-29 07:04 . 2013-03-14 23:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB37A7C6-88C3-4338-831A-3599C9646959}\mpengine.dll
2013-03-29 06:18 . 2013-03-29 06:40 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-03-29 06:18 . 2009-01-25 12:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe
2013-03-29 06:18 . 2013-03-29 06:18 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2013-03-28 07:03 . 2013-03-14 23:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-27 21:41 . 2013-03-27 21:41 -------- d-----w- c:\users\Rick\AppData\Roaming\Malwarebytes
2013-03-27 21:41 . 2013-03-27 21:41 -------- d-----w- c:\programdata\Malwarebytes
2013-03-27 21:41 . 2012-12-14 16:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-27 21:41 . 2013-03-27 21:41 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-03-27 21:41 . 2013-03-27 21:41 -------- d-----w- c:\users\Rick\AppData\Local\Programs
2013-03-27 21:23 . 2013-03-27 21:23 -------- d-----w- c:\windows\ERUNT
2013-03-27 21:23 . 2013-03-27 21:23 -------- d-----w- C:\JRT
2013-03-26 22:11 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-25 22:15 . 2013-03-25 22:15 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D5F599EB-B21C-4B32-B5A8-A087EA46E282}\gapaengine.dll
2013-03-25 22:13 . 2013-03-25 22:13 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2013-03-25 22:13 . 2013-03-25 22:13 -------- d-----w- c:\program files\Microsoft Security Client
2013-03-25 22:07 . 2013-03-19 05:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02C2F498-B349-4EA6-A7DC-9E7C2C97B8E9}\mpengine.dll
2013-03-25 22:06 . 2013-03-25 22:07 -------- d-----w- c:\users\Rick\AppData\Local\Avg2013
2013-03-17 11:59 . 2013-03-29 07:57 -------- d-----w- c:\users\Rick\AppData\Roaming\Kingsoft
2013-03-17 11:59 . 2013-03-17 11:59 -------- d-----w- c:\programdata\Kingsoft
2013-03-17 11:59 . 2013-03-17 11:59 -------- d-----w- c:\program files (x86)\Kingsoft
2013-03-17 11:56 . 1998-06-24 00:00 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-03-17 11:56 . 2005-03-12 00:07 87040 ----a-w- c:\windows\system32\pdfcmnnt.dll
2013-03-17 11:56 . 2013-03-17 11:56 -------- d-----w- c:\program files (x86)\PDFCreator
2013-03-17 11:56 . 1998-07-06 00:00 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-03-17 11:54 . 2013-03-17 11:54 -------- d-----w- c:\windows\SysWow64\searchplugins
2013-03-17 11:54 . 2013-03-17 11:54 -------- d-----w- c:\windows\SysWow64\Extensions
2013-03-16 06:30 . 2013-03-16 06:30 4546560 ----a-w- c:\windows\SysWow64\GPhotos.scr
2013-03-12 15:33 . 2013-03-12 15:33 -------- d-----w- c:\program files\iPod
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\program files\iTunes
2013-03-12 15:33 . 2013-03-12 15:34 -------- d-----w- c:\program files (x86)\iTunes
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-03-14 23:18 . 2009-11-09 22:15 72013344 ----a-w- c:\windows\system32\MRT.exe
2013-03-14 12:15 . 2012-04-10 07:10 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-14 12:15 . 2011-06-03 11:06 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-12 05:45 . 2013-03-14 11:35 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-14 11:35 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-14 11:35 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-14 11:35 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-14 11:35 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-14 11:35 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-01-30 10:53 . 2009-11-09 22:22 273840 ------w- c:\windows\system32\MpSigStub.exe
2013-01-20 15:59 . 2013-01-20 15:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 15:59 . 2013-01-20 15:59 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-05 05:53 . 2013-02-13 17:26 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-05 05:00 . 2013-02-13 17:26 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00 . 2013-02-13 17:26 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-01-04 05:46 . 2013-02-13 17:26 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 04:51 . 2013-02-13 17:26 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-01-04 04:43 . 2013-02-13 17:26 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-01-04 03:26 . 2013-02-13 17:26 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-01-04 02:47 . 2013-02-13 17:26 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-01-04 02:47 . 2013-02-13 17:26 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-01-04 02:47 . 2013-02-13 17:26 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-01-04 02:47 . 2013-02-13 17:26 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-01-03 06:00 . 2013-02-13 17:26 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 06:00 . 2013-02-13 17:26 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2011-07-17 09:37 . 2011-09-28 18:05 161744 ----a-w- c:\program files (x86)\u4res.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
2012-11-13 23:32 129272 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [BU]
"Spotify Web Helper"="c:\users\Rick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-10-12 1193176]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118624]
"dellsupportcenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [BU]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-05-05 25600]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"ServiceManager.exe"="c:\program files (x86)\Virgin Media\Service Manager\ServiceManager.exe" [2011-03-25 4371768]
"DHSClient.exe"="c:\program files (x86)\Virgin Media\Digital Home Support\DHSClient.exe" [2011-03-23 2032952]
"HF_G_Jul"="c:\program files (x86)\AVG Secure Search\HF_G_Jul.exe" [BU]
"Check Point Endpoint Security"="c:\program files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe" [2010-09-26 738824]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
c:\users\Rick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Rick\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HD Writer.lnk - c:\program files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe [2012-1-13 292240]
PURE FlowServer Tray Control.lnk - c:\program files (x86)\PURE Flow Server\twonkymediaserverconfig.exe [2010-12-20 194136]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-06-04 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-06-04 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-05-05 202840]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-05-05 1417304]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-05-05 94808]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 RapportKE64;RapportKE64;c:\windows\system32\Drivers\RapportKE64.sys [2011-09-25 64272]
R3 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-11-07 61712]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2008-10-24 43008]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2007-12-03 24064]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2008-10-24 43008]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1255736]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 RapportCerberus_43926;RapportCerberus_43926;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-30 505720]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-11-07 55056]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-26 203776]
S2 HsdService;HsdService;c:\program files (x86)\Virgin Media\Digital Home Support\HsdService.exe [2011-03-23 1406264]
S2 PURE Flow Server;PURE Flow Server;c:\program files (x86)\PURE Flow Server\twonkymediaserverwatchdog.exe [2010-12-20 153176]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-11-07 931640]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2007-12-11 26624]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-11-13 1103392]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-11-13 1369624]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-11-13 168384]
S2 ServicepointService;ServicepointService;c:\program files (x86)\Virgin Media\Service Manager\ServicepointService.exe [2011-03-25 689464]
S2 TracSrvWrapper;Check Point Endpoint Security;c:\program files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe [2010-09-26 4142608]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-05-05 202840]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-05-05 1417304]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-05-05 94808]
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 vna_ap;Check Point Virtual Network Adapter - Apollo;c:\windows\system32\DRIVERS\vnaap.sys [2010-09-26 161256]
Contents of the 'Scheduled Tasks' folder
2013-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-10 12:15]
2013-03-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1003Core.job
- c:\users\Megan.26NC-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-16 17:05]
2013-04-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1003UA.job
- c:\users\Megan.26NC-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-16 17:05]
2013-03-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1001Core.job
- c:\users\Rick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 12:59]
2013-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1546463944-2749064583-3027644177-1001UA.job
- c:\users\Rick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 12:59]
2013-03-12 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
2013-01-22 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-20 16:07]
2013-04-01 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
--------- X64 Entries -----------
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
2012-11-13 23:32 162552 ----a-w- c:\users\Rick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
"VX3000"="c:\windows\vVX3000.exe" [2009-06-30 762224]
"PocketCloud Location"="c:\program files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe" [BU]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
------- Supplementary Scan -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.uk/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer =
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
- - - - ORPHANS REMOVED - - - -
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Notify-SDWinLogon - SDWinLogon.dll
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Optimizer Pro_is1 - c:\program files (x86)\Optimizer Pro\unins000.exe
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
@Denied: (Full) (Everyone)
Completion time: 2013-04-01 21:20:08
ComboFix-quarantined-files.txt 2013-04-01 20:20
ComboFix2.txt 2013-03-26 22:38
Pre-Run: 342,992,547,840 bytes free
Post-Run: 342,996,193,280 bytes free
- - End Of File - - 13ED651D99A6C406F3E5DBFF37C0E9CB

2013-04-02, 05:33
Hello, nellie.

Thank you for the log. We need to manually remove several entries. Please continue as follows:

1. Show Hidden System Files and Folders

Some of the files and folders we need to delete are hidden and need to be shown before they can be removed. Please do the following:
Click Start, then click Control Panel.
Locate and double-click Folder Options.
Click on the View tab.
Under the Advanced Settings section, please do the following:
Under Hidden files and folders, check Show hidden files, folders, or drives.
Uncheck Hide file extensions for known file types.
Uncheck Hide protected operating system files (Recommended) . When the warning message appears, click YES.
Click Apply > OK.2. Remove Files and Folders

Please do the following:

Click Start > My Computer and double click Local Disk C:.
Click the following folder: Program Files
If it exists, locate the following folder, open it, and click uninstall.exe.

Windows Searchqu Toolbar or Windows iLivid Toolbar

Go back to Local Disk C:.
Click on each of the following folders: Users > Megan.26NC-PC > Downloads.
Locate the following file, right click on it, and then click Delete .


Go back to Users.
Click on each of the following folders: Users > Rick > Downloads.
Locate the following files, right click each file one at a time, and then click Delete after each one.

m4a-to-mp3-converter (1).exe
Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].rar
XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition]\Windows XP Home SP2 [OEM Edition].ISO

Go back to Rick.
Click on each of the following folders: AppData > local.
Locate the following folder, right click on it, and then click Delete.

Go back to Users.
Click on each of the following folders: AppData > local.
Locate the following folder, right click on it, and then click Delete.


3. Hide System Files and Folders

We need to rehide the system files and folders to keep them from being accidentally changed or deleted. Please do the following:
Click Start, then click Control Panel.
Locate and double-click Folder Options.
Click on the View tab.
Under the Advanced Settings section, please do the following:
Under Hidden files and folders, uncheck Show hidden files, folders, or drives.
Check Hide file extensions for known file types.
Check Hide protected operating system files (Recommended) . When the warning message appears, click YES.
Click Apply > OK.

Please run DDS and send me a fresh log.
Let me know how your computer is running and if there are any outstanding issues.

2013-04-03, 21:22
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16470
Run by Rick at 19:21:13 on 2013-04-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.2738 [GMT 1:00]
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Virgin Media\Digital Home Support\HsdService.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Program Files (x86)\PURE Flow Server\twonkymediaserverwatchdog.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
C:\Program Files (x86)\PURE Flow Server\twonkymediaserverconfig.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Virgin Media\Digital Home Support\DHSClient.exe
C:\Program Files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Microsoft Security Client\msseces.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [Spotify Web Helper] "C:\Users\Rick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ServiceManager.exe] "C:\Program Files (x86)\Virgin Media\Service Manager\ServiceManager.exe" /AUTORUN
mRun: [DHSClient.exe] "C:\Program Files (x86)\Virgin Media\Digital Home Support\DHSClient.exe" /AUTORUN
mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
mRun: [Check Point Endpoint Security] "C:\Program Files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\Users\Rick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Rick\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HDWRIT~1.LNK - C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\PUREFL~1.LNK - C:\Program Files (x86)\PURE Flow Server\twonkymediaserverconfig.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDriveAutorun = dword:0
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/m3/photouploadcontrol/VistaMSNPUplden-gb.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab
TCP: NameServer =
TCP: Interfaces\{2C4C7ED0-6783-40CB-8052-DED17AC0FAD8} : DHCPNameServer =
TCP: Interfaces\{B03AE1B0-8357-40AE-803B-242412DBD29A} : DHCPNameServer =
TCP: Interfaces\{E0223885-1943-4AE8-8DC4-C8F81DDEB5BB} : DHCPNameServer =
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [VX3000] C:\Windows\vVX3000.exe
x64-Run: [PocketCloud Location] "C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe"
x64-Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
============= SERVICES / DRIVERS ===============
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-1-13 55856]
R1 RapportCerberus_43926;RapportCerberus_43926;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-30 505720]
R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-11-7 55056]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-8-18 203776]
R2 HsdService;HsdService;C:\Program Files (x86)\Virgin Media\Digital Home Support\HsdService.exe [2012-4-30 1406264]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 130008]
R2 PURE Flow Server;PURE Flow Server;C:\Program Files (x86)\PURE Flow Server\twonkymediaserverwatchdog.exe -serviceversion 0 --> C:\Program Files (x86)\PURE Flow Server\twonkymediaserverwatchdog.exe -serviceversion 0 [?]
R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-11-7 931640]
R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\System32\drivers\RtNdPt60.sys [2009-11-10 26624]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-3-29 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-3-29 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-3-29 168384]
R2 ServicepointService;ServicepointService;C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe [2012-4-30 689464]
R2 TracSrvWrapper;Check Point Endpoint Security;C:\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe [2010-9-26 4142608]
R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\System32\drivers\CT20XUT.sys [2010-5-5 202840]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\System32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\System32\drivers\CTHWIUT.sys [2010-5-5 94808]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680]
R3 vna_ap;Check Point Virtual Network Adapter - Apollo;C:\Windows\System32\drivers\vnaap.sys [2010-9-26 161256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-6-4 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-6-4 79360]
S3 CT20XUT;CT20XUT;C:\Windows\System32\drivers\CT20XUT.sys [2010-5-5 202840]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\System32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
S3 CTHWIUT;CTHWIUT;C:\Windows\System32\drivers\CTHWIUT.sys [2010-5-5 94808]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2011-5-10 22528]
S3 RapportKE64;RapportKE64;C:\Windows\System32\drivers\RapportKE64.sys [2011-2-28 64272]
S3 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-11-7 61712]
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);C:\Windows\System32\drivers\RtTeam60.sys [2009-11-10 43008]
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);C:\Windows\System32\drivers\RtVlan60.sys [2009-11-10 24064]
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);C:\Windows\System32\drivers\RtTeam60.sys [2009-11-10 43008]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-21 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-3 1255736]
=============== Created Last 30 ================
2013-04-01 20:28:46 -------- d-sh--w- C:\$RECYCLE.BIN
2013-04-01 20:21:23 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F74E2272-E67A-413D-8F75-AB2D38EA4D46}\mpengine.dll
2013-03-29 06:18:21 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-03-29 06:18:13 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-03-29 06:18:10 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-03-28 07:03:28 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-27 21:41:41 -------- d-----w- C:\Users\Rick\AppData\Roaming\Malwarebytes
2013-03-27 21:41:26 -------- d-----w- C:\ProgramData\Malwarebytes
2013-03-27 21:41:21 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-03-27 21:41:20 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-03-27 21:41:03 -------- d-----w- C:\Users\Rick\AppData\Local\Programs
2013-03-27 21:23:57 -------- d-----w- C:\Windows\ERUNT
2013-03-27 21:23:48 -------- d-----w- C:\JRT
2013-03-26 22:24:34 98816 ----a-w- C:\Windows\sed.exe
2013-03-26 22:24:34 256000 ----a-w- C:\Windows\PEV.exe
2013-03-26 22:24:34 208896 ----a-w- C:\Windows\MBR.exe
2013-03-26 22:11:12 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-03-25 22:15:10 972264 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D5F599EB-B21C-4B32-B5A8-A087EA46E282}\gapaengine.dll
2013-03-25 22:13:39 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2013-03-25 22:13:15 -------- d-----w- C:\Program Files\Microsoft Security Client
2013-03-25 22:07:49 9311288 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{02C2F498-B349-4EA6-A7DC-9E7C2C97B8E9}\mpengine.dll
2013-03-25 22:06:51 -------- d-----w- C:\Users\Rick\AppData\Local\Avg2013
2013-03-17 11:59:56 -------- d-----w- C:\Users\Rick\AppData\Roaming\Kingsoft
2013-03-17 11:59:56 -------- d-----w- C:\ProgramData\Kingsoft
2013-03-17 11:59:54 -------- d-----w- C:\Program Files (x86)\Kingsoft
2013-03-17 11:56:34 137000 ----a-w- C:\Windows\SysWow64\MSMAPI32.OCX
2013-03-17 11:56:33 87040 ----a-w- C:\Windows\System32\pdfcmnnt.dll
2013-03-17 11:56:32 23552 ----a-w- C:\Windows\SysWow64\MSMPIDE.DLL
2013-03-17 11:56:32 -------- d-----w- C:\Program Files (x86)\PDFCreator
2013-03-17 11:54:44 -------- d-----w- C:\Windows\SysWow64\searchplugins
2013-03-17 11:54:44 -------- d-----w- C:\Windows\SysWow64\Extensions
2013-03-16 06:30:42 4546560 ----a-w- C:\Windows\SysWow64\GPhotos.scr
2013-03-12 15:33:49 -------- d-----w- C:\Program Files\iPod
2013-03-12 15:33:48 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-03-12 15:33:48 -------- d-----w- C:\Program Files\iTunes
2013-03-12 15:33:48 -------- d-----w- C:\Program Files (x86)\iTunes
==================== Find3M ====================
2013-03-14 12:15:15 73432 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-14 12:15:15 693976 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-02-02 06:57:02 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-02-02 06:47:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-02-02 06:47:19 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-02-02 06:42:18 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-02-02 06:41:51 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-02-02 06:38:01 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-02-02 03:38:35 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-02-02 03:30:32 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-02-02 03:30:21 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-02-02 03:26:47 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-02-02 03:26:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-02-02 03:23:28 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-01-30 10:53:22 273840 ------w- C:\Windows\System32\MpSigStub.exe
2013-01-20 15:59:04 230320 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2013-01-20 15:59:04 130008 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2013-01-05 05:53:43 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-01-05 05:00:15 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-01-04 05:46:09 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-01-04 04:51:16 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-01-04 03:26:48 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-01-04 02:47:35 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-01-04 02:47:34 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-01-04 02:47:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-01-04 02:47:33 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-17 09:37:55 161744 ----a-w- C:\Program Files (x86)\u4res.dll
============= FINISH: 19:21:41.91 ===============

2013-04-03, 21:24
DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 09/11/2009 22:11:25
System Uptime: 03/04/2013 18:25:38 (1 hours ago)
Motherboard: Dell Inc. | | 0M017G
Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz | CPU 1 | 3003/333mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 581 GiB total, 319.504 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 3.874 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP352: 01/04/2013 21:04:48 - ComboFix created restore point
==== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958)
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.4)
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Software Suite
BookSmart® 2.5.1 2.5.1
Check Point Endpoint Security
Creative ALchemy
Creative Audio Control Panel
Creative Console Launcher
Creative MediaSource 5
Creative Software AutoUpdate
Creative Sound Blaster Properties x64 Edition
Creative WaveStudio 7
Dell Driver Download Manager
Dell Support Center
Diagnostic Utility
Facebook Video Calling
FileZilla Client 3.5.1
Free M4a to MP3 Converter 7.1
Freemake Video Converter version 3.1.1
Garmin Communicator Plugin
Garmin Communicator Plugin x64
Garmin USB Drivers
Google Chrome
HD Writer AE 3.0
HP Deskjet 1050 J410 series Basic Device Software
HP Deskjet 1050 J410 series Help
HP Photo Creations
HP Update
Java 7 Update 10 (64-bit)
Lame ACM MP3 Codec
MAGIX 3D Maker (embeded)
MAGIX Movie Edit Pro 16 Plus Download Version (UK)
MAGIX Screenshare
MAGIX Speed burnR
Malwarebytes Anti-Malware version
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Corporation
Microsoft IntelliPoint 8.2
Microsoft IntelliType Pro 8.2
Microsoft LifeCam
Microsoft MapPoint Europe 2010
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access database engine 2007 (English)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Primary Interoperability Assemblies 2005
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable Package
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Maker
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Optimizer Pro v3.0
Paddy Power Poker
Paddy Power Poker Odds Calculator 1.4.2
Photo Common
Photo Gallery
Picasa 3
PURE Flow Server
Radialpoint Security Advisor 2.5.23
Realtek 8136 8168 8169 Ethernet Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
SILKYPIX Developer Studio 3.0 SE
Skype Toolbars
Skype™ 6.1
SoundFont Bank Manager
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2768024) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VBA (2627.01)
Virgin Media Digital Home Support 2.1.27
Virgin Media Service Manager 3.7.47
Visual C++ 8.0 Runtime Setup Package (x64)
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR 4.00 beta 4 (64-bit)
==== Event Viewer Messages From Past Week ========
29/03/2013 07:57:01, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
01/04/2013 21:17:34, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
01/04/2013 21:06:12, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.147.700.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9302.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
01/04/2013 21:06:12, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.147.700.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9302.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
==== End Of File ===========================

Computer is running much better now thank you. Really noticing a difference in my browser response time :)

Anything else you need me to do?

2013-04-04, 04:50
Hello, nellie.

Glad to have assisted you with your problem, and we are pleased that your computer is now working well.

These final steps will take you through some important housekeeping tasks. Please work through the following steps to ensure that unnecessary programs and files have been removed and your system is up-to-date.

Uninstall Combofix.
Click Start > Run command. This will open up the Run dialog box
In the Open field type combofix /uninstall. Please note that there is a space between combofix and /uninstall.
Click OK. The Open File security warning will appear asking if you are sure you want to run ComboFix. Please click the Run button to start the program. This will uninstall Combofix and anything associated with it.
When ComboFix has finished uninstalling, delete the ComboFix.exe program from your computer.Tool Removal

You no longer need the following tools. Please delete these and any logs from your machine: DDS, aswMBR, TDSSKiller, Farbar Service Scanner, JRT and AdwCleaner. You can keep Malwarebytes for future use if you choose.

If you wish to uninstall ESET Online Scanner, please do the following:
Click Start and select Control Panel.
Click the Uninstall a Program option found under the Programs category.
Select the ESET Online Scanner.
Click Remove.
A restart may be required to complete uninstallation.
Clean Up Temp Files

Please download TFC (http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer) by OldTimer to your desktop.
Close any open windows.
Double click the TFC icon to run the program.
TFC will close all open programs itself in order to run.
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish.
Once complete, it should automatically reboot your machine.
If your computer does not automatically reboot, manually reboot to ensure a complete clean.Update Java

To improve your software's performance or stability, please remove any older versions of Java and update to the latest version (update 17).

Click Start > Control Panel.
Click on the Java icon (coffee cup symbol) > Update > Update Now .
Follow the prompts to install the latest version of Java.To remove older versions:

Click Start and select Control Panel.
When the Control Panel window opens, click on Uninstall a program found under the Programs category.
If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Look through the list of programs for any old versions of Java, and then left-click on it once to highlight it.
Click on the Uninstall button.
When finished, close the Programs and Features screen.Update Internet Explorer

Download the latest version of Internet Explorer HERE (http://windows.microsoft.com/en-CA/internet-explorer/downloads/ie-10/worldwide-languages).

Turn On Automatic Updates

You can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
Click Start > click Control Panel > Click Windows Update.
In the left pane, click Change Settings.
Under Important Updates, click the down arrow and select Install updates automatically (recommended).
Under Recommended Updates, check Give me updates the same way I receive Important Updates.
Under Who can install updates, check Allow all users to install updates on this computer.
Click OK to apply the changes.

Note: If Windows prompts you to confirm these changes, allow it. Close the window.Adobe Updates

Adobe Reader
To improve the funtionaility and security of your software, please update Adobe Reader HERE (http://get.adobe.com/reader/). Updates safeguard your system against malicious attacks through PDF files.

Update Adobe Flash
Please update Adobe Flash HERE (http://www.adobe.com/support/flashplayer/downloads.html). Updating your Flash player ensures that it is working properly and guards against security vulnerabilities.

Recommended Reading

To maintain a clean and healthy system, please take the time to read through the following informative articles:
The Dangers of P2P File Sharing HERE (http://www.esecurityguy.com/p2p_file_sharing)
How to Prevent Malware by Miekiemoes HERE (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html)
So How Did I Get Infected In the First Place? By Tony Klein HERE (http://www.spywareinfoforum.com/index.php?showtopic=60955)
Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams HERE (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/)
Help! My computer is Slow – How to improve system performance after malware removal by Miekiemoes HERE (http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html)
Create Strong Passwords by Microsoft HERE (http://www.microsoft.com/security/online-privacy/passwords-create.aspx)
PC Safety and Security – What do I need to do? by Glaswegian HERE (http://www.techsupportforum.com/forums/f112/pc-safety-and-security-what-do-i-need-525915.html)

Wishing you all a very safe browsing experience. :)
~ fbfbfb

2013-04-04, 23:07
thank you SO much fbfbfb!!

My computer is running like new again. Will try my best to keep it this way, which will include 'educating' my kids as to what they do and don't download. I will also be more careful myself in future ;)

Thank you again for your assistance. Your are a valued member of the safer networking team.


2013-04-05, 01:10
Nellie, thank you very much for your kind and supportive words. It was our pleasure to assist you.

All the best,