Virtumonde-New Thread-As Per request

Do you believe this was a valid CF Update?
Yes, CF checks for available update before it runs.

QUESTION: Do you want me to paste (or attach) the DDS_Attach Log?
Won't need attach.txt anymore :)

C:\atapi.sys.vir can be deleted. How is your system running now?
 
As per my previous post...

"The system appears to be running pretty good except for Windows Security Alert in Tray... "AVG A/V is out of date!" (I have not run or updated AVG or SpyBot for awhile.) Windows Automatic Updates are also turned off."

Did you mean you want me to Delete: C:\atapi.sys.vir ... and then tell you again "how the system is running?" after that???

Also... when we searched for all instances of "atapi.sys" it was found in 5 or 6 locations. Then we replaced the bad one with a good one we copied from the C:\....ServicePackFolder. Is there a possibility that any of the other instances/locations could be copies of the bad "atapi.sys"
 
As per my previous post...

"The system appears to be running pretty good except for Windows Security Alert in Tray... "AVG A/V is out of date!" (I have not run or updated AVG or SpyBot for awhile.) Windows Automatic Updates are also turned off."
Sorry, seems that I paid too much attention to those two bolded questions of yours and missed this.

See if you're able to get AVG and Spybot updated now. Better let Windows Automatic Updates be until we've finished the cleaning process.

Is there a possibility that any of the other instances/locations could be copies of the bad "atapi.sys"
Never should say it's impossible but what is important is that healthy copy is in the location we put the file in. There's nothing to worry about :)
 
Thanks Blade

I will try to update AVG and SpyBot and reply with results.

Please advise when I should start and enable the SpyBot and AVG Resident Shields?

One thing I noticed in IE7... When logging on to the Malware Removal Forum, after the page loads... the bottom left corner of the IE screen shows... "Done, But with errors on page." I do not see this on other Websites I've tried. Is this a problem with the forum's page? Or a problem with my Computer or IE settings?
 
Hi,

You can enable Spybot and AVG resident shield after we've finished.
One thing I noticed in IE7... When logging on to the Malware Removal Forum, after the page loads... the bottom left corner of the IE screen shows... "Done, But with errors on page." I do not see this on other Websites I've tried. Is this a problem with the forum's page? Or a problem with my Computer or IE settings?
Don't have to worry about that error message. Happens also in one of my machines with IE7.
 
Followup

I will try to update AVG and SpyBot and reply with results.

Please advise when I should start and enable the SpyBot and AVG Resident Shields?

One thing I noticed in IE7... When logging on to the Malware Removal Forum, after the page loads... the bottom left corner of the IE screen shows... "Done, But with errors on page." I do not see this on other Websites I've tried. Is this a problem with the forum's page? Or a problem with my Computer or IE settings?

Hi again Blades,

I have updated Spybot succesfully but I have not yet run a Spybot Scan or enabled Spybot's SDhelper or Teatimer.

I was not able to update AVG. I can open the AVG User Interface but when I click UPDATE NOW, the display shows Searching for updates... but nothing happens. Seems to be hanging here. I tried restart, after setting update on restart, but that did not help. Do you think the infection could have disabled or misdirected AVG's Update feature? Any suggestions for this?

I look forward to your reply!
 
Infection may have harmed AVG installation. Better try to reinstall it.
 
Need help with AVG

Infection may have harmed AVG installation. Better try to reinstall it.

Just when I think we're getting close... More problems!

I cannot re-install fresh AVG Free 9.0. First I used Windows' Add/Remove Programs to uninstall the current AVG Free 8.5. When completed, message said, "You must Restart to Complete the Removal.) and press DETAIL to view unsuccessful items. Details showed... Action Failed: file avgmfx86.sys. Windows' Search did not find ay file named "avgmfx86.sys"

After restart, AVG Desktop and Start Menu Icons were removed. Add/Remove programs no longer shows AVG 8.5 to remove.

But the START>ALL PROGRAMS>AVG Free Edition program group was still there. Selecting AVG Control Center, Virus Vault, or Test Center, displayed "Bad Shortcut" but Selecting Uninstall AVG from the Program Group, displayed, "Searching for setup.exe" with a Browse Button. If you just wait nothing happens and the window disappears. I didn't press Browse because there are probably many "setup.exe" files on the system and I wouldn't know which to choose.

Windows Explorer still shows (in... C:\Program Files...) the AVG Free Folder & Subfolders (not much in there) and in the Grisoft Folder an older version AVG 7.0 with just an AVG install exe file.

I downloaded AVG 9.0 from the free.avg.com site and was redirected for the download to Cnet. I downloaded and ran the AVG installation but after copying files got a message saying "Some potentially incompatible software is currently installed on this computer. (OLE (Part 1 of 5). Click uninstall s/w button to launch Windows Add/Remove programs to uninstall the incompatible software. The Add/Remove Program screen did not show the OLE program.

Restarted and downloaded a fresh AVG instal exe program and got the same results.

I'm stuck again and apologize for all the trouble I'm having!
 
This removal tool from AVG is worth trying.

Thank you much Blade!

I will close out of what I'm doing here on this machine and reconnect the infected computer to download the AVG removal tool. I will post my results.

I do appreciate your assistance!
Tom
 
Thank you much Blade!

I will close out of what I'm doing here on this machine and reconnect the infected computer to download the AVG removal tool. I will post my results.

I do appreciate your assistance!
Tom

Hi Blade,

I tried the AVG removal tool. It launched a black dos cmd window with two lines showing...

2009-11-27 22:01:14 WARN AvgDir param empty
2009-11-27 22:01:14 WARN AvgDataDir param empty

...and a message box that said, "This application will remove AVG from your computer. This can require one or more restarts during the cleaning process. Please save all work and close all other applications. Do you want to continue. I clicked Yes. The program ran, created an "avgremoval.log, and then closed.

I then restarted the computer and tried to install the new version again and had the same results...

Installation stopped to warn of "Potentially Incompatible Software (OLE (Part 1 of 5)). Do you want to uninstall this software?... Options...
SKIP (Not recommended!) or UNINSTALL the software.

(Uninstall goes nowhere... Can't find the OLE software.)

I then went into Windows Explorer and manually deleted all AVG folders, restarted, and ran the AVG removal tool again. It ran like before, created a log and closed. I've copied that log (avgremoval.log) below.

Then retarted the computer and tried to install AVG again. Same results. I fear something is preventing the installation of AVG. Do you think I should try the SKIP (Not recommended) option?

The AVG removal log is below... Hope this helps!
====================================
2009-11-27 22:35:21,890 DEBUG Avg9Uninstall\Directories key failed to open (error: e0010013)
2009-11-27 22:35:21,921 DEBUG Avg8Uninstall\Directories key failed to open (error: e0010013)
2009-11-27 22:35:21,921 DEBUG Reading HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion:ProgramFilesDir (x86) value failed (error: e001003d)
2009-11-27 22:35:21,921 WARN AvgDir param empty.
2009-11-27 22:35:21,921 WARN AvgDataDir param empty.
2009-11-27 22:35:34,703 INFO AvgRemover runs in attempt number 1
2009-11-27 22:35:34,703 INFO ***** Services *****
2009-11-27 22:35:34,703 INFO Processing service avg8emc
2009-11-27 22:35:34,718 INFO Service avg8emc is not installed
2009-11-27 22:35:34,718 DEBUG Service avg8emc RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service avg8emc are not present
2009-11-27 22:35:34,734 INFO Processing service avgfws8
2009-11-27 22:35:34,734 INFO Service avgfws8 is not installed
2009-11-27 22:35:34,734 DEBUG Service avgfws8 RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service avgfws8 are not present
2009-11-27 22:35:34,734 INFO Processing service avg8wd
2009-11-27 22:35:34,734 INFO Service avg8wd is not installed
2009-11-27 22:35:34,734 DEBUG Service avg8wd RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service avg8wd are not present
2009-11-27 22:35:34,734 INFO Processing service AvgWFPx
2009-11-27 22:35:34,734 INFO Service AvgWFPx is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgWFPx RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgWFPx are not present
2009-11-27 22:35:34,734 INFO Processing service AvgWFPa
2009-11-27 22:35:34,734 INFO Service AvgWFPa is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgWFPa RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgWFPa are not present
2009-11-27 22:35:34,734 INFO Processing service AvgMfx86
2009-11-27 22:35:34,734 INFO Service AvgMfx86 is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgMfx86 RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgMfx86 are not present
2009-11-27 22:35:34,734 INFO Processing service AvgMfx64
2009-11-27 22:35:34,734 INFO Service AvgMfx64 is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgMfx64 RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgMfx64 are not present
2009-11-27 22:35:34,734 INFO Processing service AvgLdx86
2009-11-27 22:35:34,734 INFO Service AvgLdx86 is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgLdx86 RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgLdx86 are not present
2009-11-27 22:35:34,734 INFO Processing service AvgLdx64
2009-11-27 22:35:34,734 INFO Service AvgLdx64 is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgLdx64 RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgLdx64 are not present
2009-11-27 22:35:34,734 INFO Processing service AvgTdiX
2009-11-27 22:35:34,734 INFO Service AvgTdiX is not installed
2009-11-27 22:35:34,734 DEBUG Service AvgTdiX RegCleanup
2009-11-27 22:35:34,734 DEBUG Registry keys for service AvgTdiX are not present
2009-11-27 22:35:34,734 INFO Processing service AvgTdiA
2009-11-27 22:35:34,750 INFO Service AvgTdiA is not installed
2009-11-27 22:35:34,750 DEBUG Service AvgTdiA RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AvgTdiA are not present
2009-11-27 22:35:34,750 INFO Processing service AvgRkx86
2009-11-27 22:35:34,750 INFO Service AvgRkx86 is not installed
2009-11-27 22:35:34,750 DEBUG Service AvgRkx86 RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AvgRkx86 are not present
2009-11-27 22:35:34,750 INFO Processing service AvgRkx64
2009-11-27 22:35:34,750 INFO Service AvgRkx64 is not installed
2009-11-27 22:35:34,750 DEBUG Service AvgRkx64 RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AvgRkx64 are not present
2009-11-27 22:35:34,750 INFO Processing service avg9emc
2009-11-27 22:35:34,750 INFO Service avg9emc is not installed
2009-11-27 22:35:34,750 DEBUG Service avg9emc RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service avg9emc are not present
2009-11-27 22:35:34,750 INFO Processing service avgfws9
2009-11-27 22:35:34,750 INFO Service avgfws9 is not installed
2009-11-27 22:35:34,750 DEBUG Service avgfws9 RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service avgfws9 are not present
2009-11-27 22:35:34,750 INFO Processing service avg9wd
2009-11-27 22:35:34,750 INFO Service avg9wd is not installed
2009-11-27 22:35:34,750 DEBUG Service avg9wd RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service avg9wd are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSAgent
2009-11-27 22:35:34,750 INFO Service AVGIDSAgent is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSAgent RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSAgent are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSShimxpx
2009-11-27 22:35:34,750 INFO Service AVGIDSShimxpx is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSShimxpx RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSShimxpx are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSFilterxpx
2009-11-27 22:35:34,750 INFO Service AVGIDSFilterxpx is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSFilterxpx RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSFilterxpx are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSDriverxpx
2009-11-27 22:35:34,750 INFO Service AVGIDSDriverxpx is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSDriverxpx RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSDriverxpx are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSShimvtx
2009-11-27 22:35:34,750 INFO Service AVGIDSShimvtx is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSShimvtx RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSShimvtx are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSFiltervtx
2009-11-27 22:35:34,750 INFO Service AVGIDSFiltervtx is not installed
2009-11-27 22:35:34,750 DEBUG Service AVGIDSFiltervtx RegCleanup
2009-11-27 22:35:34,750 DEBUG Registry keys for service AVGIDSFiltervtx are not present
2009-11-27 22:35:34,750 INFO Processing service AVGIDSDrivervtx
2009-11-27 22:35:34,765 INFO Service AVGIDSDrivervtx is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSDrivervtx RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSDrivervtx are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSFiltervta
2009-11-27 22:35:34,765 INFO Service AVGIDSFiltervta is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSFiltervta RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSFiltervta are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSDrivervta
2009-11-27 22:35:34,765 INFO Service AVGIDSDrivervta is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSDrivervta RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSDrivervta are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSShimw7x
2009-11-27 22:35:34,765 INFO Service AVGIDSShimw7x is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSShimw7x RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSShimw7x are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSFilterw7x
2009-11-27 22:35:34,765 INFO Service AVGIDSFilterw7x is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSFilterw7x RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSFilterw7x are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSDriverw7x
2009-11-27 22:35:34,765 INFO Service AVGIDSDriverw7x is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSDriverw7x RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSDriverw7x are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSFilterw7a
2009-11-27 22:35:34,765 INFO Service AVGIDSFilterw7a is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSFilterw7a RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSFilterw7a are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSDriverw7a
2009-11-27 22:35:34,765 INFO Service AVGIDSDriverw7a is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSDriverw7a RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSDriverw7a are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSErHrxpx
2009-11-27 22:35:34,765 INFO Service AVGIDSErHrxpx is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSErHrxpx RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSErHrxpx are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSErHrvtx
2009-11-27 22:35:34,765 INFO Service AVGIDSErHrvtx is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSErHrvtx RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSErHrvtx are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSErHrvta
2009-11-27 22:35:34,765 INFO Service AVGIDSErHrvta is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSErHrvta RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSErHrvta are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSErHrw7x
2009-11-27 22:35:34,765 INFO Service AVGIDSErHrw7x is not installed
2009-11-27 22:35:34,765 DEBUG Service AVGIDSErHrw7x RegCleanup
2009-11-27 22:35:34,765 DEBUG Registry keys for service AVGIDSErHrw7x are not present
2009-11-27 22:35:34,765 INFO Processing service AVGIDSErHrw7a
2009-11-27 22:35:34,781 INFO Service AVGIDSErHrw7a is not installed
2009-11-27 22:35:34,781 DEBUG Service AVGIDSErHrw7a RegCleanup
2009-11-27 22:35:34,781 DEBUG Registry keys for service AVGIDSErHrw7a are not present
2009-11-27 22:35:34,781 INFO ***** Registry keys and values *****
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Mozilla\Firefox\Extensions
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Mozilla\Firefox\Extensions:{3f963a5b-e555-4543-90e2-c3908898db71} Remove
2009-11-27 22:35:34,781 INFO Value SOFTWARE\Mozilla\Firefox\Extensions:{3f963a5b-e555-4543-90e2-c3908898db71} is not present
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Mozilla\Firefox\Extensions
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Mozilla\Firefox\Extensions:{1d5287d1-8a92-0001-1f31-1cec198018d8} Remove
2009-11-27 22:35:34,781 INFO Value SOFTWARE\Mozilla\Firefox\Extensions:{1d5287d1-8a92-0001-1f31-1cec198018d8} is not present
2009-11-27 22:35:34,781 INFO Processing registry SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg8Alrt
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg8Alrt ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg8Alrt not found
2009-11-27 22:35:34,781 INFO Processing registry SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg9Alrt
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg9Alrt ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg9Alrt not found
2009-11-27 22:35:34,781 INFO Processing registry SYSTEM\CurrentControlSet\Services\Eventlog\Application\AvgEms
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\AvgEms ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Eventlog\Application\AvgEms not found
2009-11-27 22:35:34,781 INFO Processing registry SYSTEM\CurrentControlSet\Services\Avg
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Avg ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Avg not found
2009-11-27 22:35:34,781 INFO Processing registry SYSTEM\CurrentControlSet\Services\Avg
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Avg ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SYSTEM\CurrentControlSet\Services\Avg not found
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AF1721-312E-4B07-8B17-CEB780DCD054}
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AF1721-312E-4B07-8B17-CEB780DCD054} ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AF1721-312E-4B07-8B17-CEB780DCD054} not found
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\Toolbar
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Microsoft\Internet Explorer\Toolbar:{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Remove
2009-11-27 22:35:34,781 INFO Value SOFTWARE\Microsoft\Internet Explorer\Toolbar:{CCC7A320-B3CA-4199-B1A6-9F516DD69829} is not present
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,781 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Exchange\Client\Extensions
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Microsoft\Exchange\Client\Extensions:Outlook Setup Extension Remove
2009-11-27 22:35:34,781 INFO Value SOFTWARE\Microsoft\Exchange\Client\Extensions:Outlook Setup Extension is not present
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Exchange\Client\Extensions
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Microsoft\Exchange\Client\Extensions:AVG Exchange Extension Remove
2009-11-27 22:35:34,781 INFO Value SOFTWARE\Microsoft\Exchange\Client\Extensions:AVG Exchange Extension is not present
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:AppInit_DLLs Modify
2009-11-27 22:35:34,781 DEBUG Value SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:AppInit_DLLs doesn't need to be modified
2009-11-27 22:35:34,781 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved:{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Run
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Run:AVG8_TRAY Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Run:AVG8_TRAY is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Run
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\Microsoft\Windows\CurrentVersion\Run:AVG9_TRAY Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\Microsoft\Windows\CurrentVersion\Run:AVG9_TRAY is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG8Uninstall
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG8Uninstall ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG8Uninstall not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG7Uninstall
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG7Uninstall ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG7Uninstall not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG9Uninstall
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG9Uninstall ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG9Uninstall not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C} ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3 ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3 not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3 ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3 not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\AvgDiagFile
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\AvgDiagFile ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\AvgDiagFile not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\AvgDiagFile
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\AvgDiagFile ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\AvgDiagFile not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\.avgdi
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\.avgdi ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\.avgdi not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\piffile\shellex\ContextMenuHandlers\AVG8 Shell Extension
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\piffile\shellex\ContextMenuHandlers\AVG8 Shell Extension ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\piffile\shellex\ContextMenuHandlers\AVG8 Shell Extension not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG8 Shell Extension
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG8 Shell Extension ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG8 Shell Extension not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\Classes\*\shellex\ContextMenuHandlers\AVG8 Shell Extension
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\*\shellex\ContextMenuHandlers\AVG8 Shell Extension ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\Classes\*\shellex\ContextMenuHandlers\AVG8 Shell Extension not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\Clients
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\Clients ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\Clients not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\AVG8
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG8 ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG8 not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\AVG9
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG9 ForceRemove
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\AVG IDS
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG IDS ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG IDS not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG
2009-11-27 22:35:34,796 DEBUG Value SOFTWARE\AVG:DumpType Remove
2009-11-27 22:35:34,796 INFO Value SOFTWARE\AVG:DumpType is not present
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG Remove
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG Security Toolbar
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG Security Toolbar ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG Security Toolbar not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\AVG8
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG8 ForceRemove
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG8 not found
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG\AVG9
2009-11-27 22:35:34,796 DEBUG Key SOFTWARE\AVG\AVG9 ForceRemove
2009-11-27 22:35:34,796 INFO Processing registry SOFTWARE\AVG
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\AVG Remove
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\AVG Security Toolbar
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\AVG Security Toolbar ForceRemove
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\AVG Security Toolbar not found
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
2009-11-27 22:35:34,812 DEBUG Value SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks:{A3BC75A2-1F87-4686-AA43-5347D756017C} Remove
2009-11-27 22:35:34,812 INFO Value SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks:{A3BC75A2-1F87-4686-AA43-5347D756017C} is not present
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser
2009-11-27 22:35:34,812 DEBUG Value SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser:{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Remove
2009-11-27 22:35:34,812 INFO Value SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser:{CCC7A320-B3CA-4199-B1A6-9F516DD69829} is not present
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,812 INFO Processing registry SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3BC75A2-1F87-4686-AA43-5347D756017C}
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3BC75A2-1F87-4686-AA43-5347D756017C} ForceRemove
2009-11-27 22:35:34,812 DEBUG Key SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found
2009-11-27 22:35:34,812 INFO Processing registry aAvgAPI.AvgBro
2009-11-27 22:35:34,812 DEBUG Key aAvgAPI.AvgBro ForceRemove
2009-11-27 22:35:34,812 DEBUG Key aAvgAPI.AvgBro not found
2009-11-27 22:35:34,812 INFO Processing registry AVG.Office
2009-11-27 22:35:34,812 DEBUG Key AVG.Office ForceRemove
2009-11-27 22:35:34,812 DEBUG Key AVG.Office not found
2009-11-27 22:35:34,812 INFO Processing registry AVG.Office.8
2009-11-27 22:35:34,812 DEBUG Key AVG.Office.8 ForceRemove
2009-11-27 22:35:34,812 DEBUG Key AVG.Office.8 not found
2009-11-27 22:35:34,812 INFO Processing registry avgtoolbar.AVGTOOLBAR
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBAR ForceRemove
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBAR not found
2009-11-27 22:35:34,921 INFO Processing registry avgtoolbar.AVGTOOLBARMenu Button
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBARMenu Button ForceRemove
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBARMenu Button not found
2009-11-27 22:35:34,921 INFO Processing registry avgtoolbar.AVGTOOLBARToggle Button
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBARToggle Button ForceRemove
2009-11-27 22:35:34,921 DEBUG Key avgtoolbar.AVGTOOLBARToggle Button not found
2009-11-27 22:35:34,921 INFO Processing registry LinkScannerIE.NavFilter
2009-11-27 22:35:34,921 DEBUG Key LinkScannerIE.NavFilter ForceRemove
2009-11-27 22:35:34,921 DEBUG Key LinkScannerIE.NavFilter not found
2009-11-27 22:35:34,921 INFO Processing registry LinkScannerIE.NavFilter.1
2009-11-27 22:35:34,921 DEBUG Key LinkScannerIE.NavFilter.1 ForceRemove
2009-11-27 22:35:34,921 DEBUG Key LinkScannerIE.NavFilter.1 not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{04373D9C-5ED8-44f2-BA00-7895D6A5A2DA} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{04373D9C-5ED8-44f2-BA00-7895D6A5A2DA} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E2698E} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E2698E} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{A057A204-BACC-4D26-9990-79A187E2698F}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{A057A204-BACC-4D26-9990-79A187E26990}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E26990} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A057A204-BACC-4D26-9990-79A187E26990} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{9781B2D1-AF27-474F-A3A5-C0763FBDF3B7}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9781B2D1-AF27-474F-A3A5-C0763FBDF3B7} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{9781B2D1-AF27-474F-A3A5-C0763FBDF3B7} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found
2009-11-27 22:35:34,921 INFO Processing registry CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,921 DEBUG Key CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,921 INFO Processing registry Interface\{52261B0E-CA1A-4FA9-9805-4D01202DF09D}
2009-11-27 22:35:34,921 DEBUG Key Interface\{52261B0E-CA1A-4FA9-9805-4D01202DF09D} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key Interface\{52261B0E-CA1A-4FA9-9805-4D01202DF09D} not found
2009-11-27 22:35:34,921 INFO Processing registry Interface\{8EA1F9F2-997A-4832-8E09-815E3D0C0A0C}
2009-11-27 22:35:34,921 DEBUG Key Interface\{8EA1F9F2-997A-4832-8E09-815E3D0C0A0C} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key Interface\{8EA1F9F2-997A-4832-8E09-815E3D0C0A0C} not found
2009-11-27 22:35:34,921 INFO Processing registry Interface\{7F24AABF-C822-4C18-9432-21433208F4DC}
2009-11-27 22:35:34,921 DEBUG Key Interface\{7F24AABF-C822-4C18-9432-21433208F4DC} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key Interface\{7F24AABF-C822-4C18-9432-21433208F4DC} not found
2009-11-27 22:35:34,921 INFO Processing registry TypeLib\{3E536428-8E1A-4A2C-8463-4A8F74763C30}
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{3E536428-8E1A-4A2C-8463-4A8F74763C30} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{3E536428-8E1A-4A2C-8463-4A8F74763C30} not found
2009-11-27 22:35:34,921 INFO Processing registry TypeLib\{5DAB1D4C-D020-41CD-936F-D63FF662E9F7}
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{5DAB1D4C-D020-41CD-936F-D63FF662E9F7} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{5DAB1D4C-D020-41CD-936F-D63FF662E9F7} not found
2009-11-27 22:35:34,921 INFO Processing registry TypeLib\{A0C8F0F1-DE25-4ADB-8F0B-508F6CA43DE9}
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{A0C8F0F1-DE25-4ADB-8F0B-508F6CA43DE9} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{A0C8F0F1-DE25-4ADB-8F0B-508F6CA43DE9} not found
2009-11-27 22:35:34,921 INFO Processing registry TypeLib\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} ForceRemove
2009-11-27 22:35:34,921 DEBUG Key TypeLib\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found
2009-11-27 22:35:34,921 INFO ***** Files and folders *****
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 0
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 1
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 2
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 3
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 4
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 5
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 6
2009-11-27 22:35:34,921 DEBUG Missing ParentDir path for fileItem number 7
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 8
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 9
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 10
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 11
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 12
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 13
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 14
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 15
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 16
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\Tom McNeal\Application Data\AVGTOOLBAR
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\Tom McNeal\Application Data\AVGTOOLBAR not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Start Menu\Programs\avg 8.0
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Start Menu\Programs\avg 8.0 not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Start Menu\Programs\avg free 8.0
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Start Menu\Programs\avg free 8.0 not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Start Menu\Programs\avg 8.5
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Start Menu\Programs\avg 8.5 not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Start Menu\Programs\avg free 8.5
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Start Menu\Programs\avg free 8.5 not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg 8.0.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg 8.0.lnk not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg free 8.0.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg free 8.0.lnk not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg 8.5.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg 8.5.lnk not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg free 8.5.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg free 8.5.lnk not found
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 27
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 28
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 29
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 30
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 31
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 32
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 33
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 34
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 35
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 36
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 37
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 38
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 39
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 40
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 41
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 42
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 43
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 44
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 45
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 46
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 47
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 48
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 49
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 50
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 51
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 52
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 53
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 54
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 55
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 56
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 57
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 58
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 59
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 60
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 61
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 62
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 63
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 64
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 65
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 66
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 67
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 68
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 69
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 70
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar\Languages
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar\Languages not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2009-11-27 22:35:34,937 INFO Directory C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg 9.0.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg 9.0.lnk not found
2009-11-27 22:35:34,937 DEBUG Processing item C:\Documents and Settings\All Users\Desktop\avg free 9.0.lnk
2009-11-27 22:35:34,937 INFO File C:\Documents and Settings\All Users\Desktop\avg free 9.0.lnk not found
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 76
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 77
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 78
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 79
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 80
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 81
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 82
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 83
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 84
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 85
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 86
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 87
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 88
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 89
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 90
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 91
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 92
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 93
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 94
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 95
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 96
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 97
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 98
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 99
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 100
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 101
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 102
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 103
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 104
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 105
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 106
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 107
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 108
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 109
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 110
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 111
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 112
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 113
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 114
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 115
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 116
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 117
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 118
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 119
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 120
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 121
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 122
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 123
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 124
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 125
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 126
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 127
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 128
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 129
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 130
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 131
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 132
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 133
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 134
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 135
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 136
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 137
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 138
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 139
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 140
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 141
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 142
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 143
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 144
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 145
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 146
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 147
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 148
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 149
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 150
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 151
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 152
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 153
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 154
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 155
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 156
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 157
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 158
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 159
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 160
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 161
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 162
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 163
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 164
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 165
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 166
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 167
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 168
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 169
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 170
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 171
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 172
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 173
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 174
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 175
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 176
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 177
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 178
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 179
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 180
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 181
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 182
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 183
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 184
2009-11-27 22:35:34,937 DEBUG Missing ParentDir path for fileItem number 185
2009-11-27 22:35:34,937 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,937 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,937 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,953 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,953 DEBUG Processing item C:\WINDOWS\System32\Drivers
2009-11-27 22:35:34,953 DEBUG Processing item C:\WINDOWS\System32\Drivers\avg
2009-11-27 22:35:34,953 INFO Directory C:\WINDOWS\System32\Drivers\avg not found
2009-11-27 22:35:34,953 DEBUG Processing item C:\WINDOWS\System32
2009-11-27 22:35:34,953 DEBUG Processing item C:\Program Files\AVG
2009-11-27 22:35:34,953 INFO Directory C:\Program Files\AVG not found
2009-11-27 22:35:34,953 DEBUG Missing ParentDir path for fileItem number 194
2009-11-27 22:35:34,953 INFO ***** Avg Fw NDIS driver *****
2009-11-27 22:35:35,562 INFO FW NDIS driver not present
 
AVG 9 Installed Successfully

Hi Blade,
I dug into the AVG Support Forum and have solved the AVG 9.0 Installation Issue. AVG is now installed and updated. I have not yet performed an AVG scan and have disabled the AVG Resident Shield. I will wait until you give me the OK before doing so.

FYI: In case it may help others, the warning of potentially incompatible software (OLE (Part 1 of 5)) issue is a known problem and this compatability check will be omitted in the next release.

The AVG forum recommends doing a regedit to find the entry that may be causing the problem OR SIMPLY CHOOSE THE SKIP OPTION!

I chose SKIP and the remainder of the installation went fine.

Again, I apologize for all the trouble I'm having!
 
Good. Seems that it's time for the final steps now :)


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis


Now lets uninstall ComboFix:
  • Click START then RUN
  • Now copy-paste Combofix /uninstall in the runbox and click OK


Please download OTC and save it to desktop.
  • Double-click OTC.exe.
  • Click the CleanUp! button.
  • Select Yes when the
    Begin cleanup Process?
    prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.



UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • hosts file:
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. [*]Click the start button (at the lower left hand corner of your screen) [*]Click run [*]In the dialog box, type services.msc [*]hit enter, then locate dns client [*]Highlight it, then double-click it. [*]On the dropdown box, change the setting from automatic to manual. [*]Click ok


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:
 
OTC: Did not complete reboot

Hi Blade,

I was happy to hear that it's time for final cleanup. Unfortunately, I am posting this from one of my other computers.

I completed the Reset of System Restore and then uninstalled ComboFix.

I ran OTC and it appeared to do everything you said it would do...
UNTIL OTC rebooted the machine... The reboot did not complete successfully.

The computer is displaying a black screen with a blinking cursor in the upper left hand corner. I've waited about 15 minutes but nothing is happening.

Should I turn the machine OFF and then ON again to see if it will boot?

Help needed!
 
Wait a minute...

After posting the above, while waiting for your reply, I opened the two CD trays to make sure there was no disks inserted there.

After closing the second CD drive tray, the Windows screen appeared and the machine booted up. Why this behavior? Should I still be worried?
 
It may have tried to load from cd of some reason. Still, I don't think there's any need to be worried.
 
Thanks Blade... That's a relief!

I will continue with the cleanup and updating of Windows and Office then post a reply with a few questions.

For now, what should I do with the remaining tools on my desktop...

HJT - ATF - GMER - MBAM Setup - SystemLook - MalwareBytes A/M

Any special instructions for removing those tools?

Should I consider keeping the MalwareBytes Anti-Malware, perhaps in instead of the AVG 9.0?
 
HJT - ATF - GMER - MBAM Setup - SystemLook - MalwareBytes A/M

Any special instructions for removing those tools?
Uninstall HJT from add/remove programs and then delete its C:\Program Files\Trend Micro\HijackThis folder. I'd keep ATF Cleaner and run it occasionally to clean needless temporary items. MBAM Setup file and SystemLook can be deleted without special ways. MBAM itself I've commented below :)

Should I consider keeping the MalwareBytes Anti-Malware, perhaps in instead of the AVG 9.0?
Malwarebytes Anti-Malware is for antispyware protection while AVG 9 is for antivirus protection. Both protect from different things and should be left installed.
 
A few more questions

1. Do you think I should upgrade from IE7 to IE8 at this time? Or stay with IE7 for now?

2. Should I leave the Recovery Console installed by ERUNT on the machine

3. Is it safe now to reconnect our other computers to the home network?

4. TASHI suggested that I ask my volunteer about this... One of our computers, is an old Dell Dimension P166x running the DOS based Windows for Workgroups Ver. 3.11. This system pre-dates Internet Explorer and I know of no Anti-Virus or Anti-Malware programs compatible with this OS. The machine is never used to access the internet directly but is connected to our network via the old NETBUI network protocol that I've installed on a couple of our XP machines. Is this Windows 3.11 machine vulnerable to infections or pose any threat to our other machines if I leave it connected to our network?

5 Do you recommend installing and running ERUNT - ATF or MBAM on our other XP machines?
 
Back
Top