Results 1 to 8 of 8

Thread: combofix log     submit to reddit submit to twitter

  1. #1
    Cerberus
    Join Date
    Oct 2008
    Posts
    436
    BG Level
    4

    Requesting help on cleaning 2 pc's

    So decided to clean up my pc and finley get around to adblock noscript. This is my combo fix log but idk how to read it, can someone shead some light on it, would like to know if anything bad was found. Also how the hell i get rid of AVG i've uninstalled, its not on my program file list, and i've deleted the program files for it....


    Combo fix log
    Code:
    ComboFix 09-10-30.01 - Brett 10/30/2009 20:11.1.2 - NTFSx86
    Microsoft® Windows Vista™ Home Basic   6.0.6000.0.1252.1.1033.18.1022.407 [GMT -5:00]
    Running from: e:\clean up files\combo.exe
    AV: avast! antivirus 4.8.1356 [VPS 091030-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    SP: avast! antivirus 4.8.1356 [VPS 091030-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .
    
    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    
    c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
    c:\$recycle.bin\S-1-5-21-962818335-2667958646-3167542101-500
    c:\users\Brett\Documents\notepad.exe
    
    .
    (((((((((((((((((((((((((   Files Created from 2009-09-28 to 2009-10-31  )))))))))))))))))))))))))))))))
    .
    
    2009-10-31 01:19 . 2009-10-31 01:19	--------	d-----w-	c:\users\Default\AppData\Local\temp
    2009-10-31 01:19 . 2009-10-31 01:19	--------	d-----w-	c:\users\Brett\AppData\Local\temp
    2009-10-31 01:11 . 2006-11-02 09:50	112232	----a-w-	c:\windows\system32\drivers\vsmraid.sys
    2009-10-31 01:11 . 2005-07-20 18:52	89088	----a-w-	c:\windows\system32\drivers\viamraid.sys
    2009-10-31 01:11 . 2008-11-22 17:12	21560	----a-w-	c:\windows\system32\drivers\atapi.sys
    2009-10-30 23:42 . 2009-09-15 10:54	23152	----a-w-	c:\windows\system32\drivers\aswRdr.sys
    2009-10-30 23:42 . 2009-09-15 10:54	52368	----a-w-	c:\windows\system32\drivers\aswTdi.sys
    2009-10-30 23:42 . 2009-09-15 10:55	114768	----a-w-	c:\windows\system32\drivers\aswSP.sys
    2009-10-30 23:42 . 2009-09-15 10:55	20560	----a-w-	c:\windows\system32\drivers\aswFsBlk.sys
    2009-10-30 23:42 . 2009-09-15 10:53	97480	----a-w-	c:\windows\system32\AvastSS.scr
    2009-10-30 23:41 . 2009-09-15 10:59	1279968	----a-w-	c:\windows\system32\aswBoot.exe
    2009-10-30 23:41 . 2009-09-15 10:55	53328	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
    2009-10-30 23:41 . 2003-03-18 21:20	1060864	----a-w-	c:\windows\system32\MFC71.dll
    2009-10-30 23:41 . 2009-10-30 23:41	--------	d-----w-	c:\program files\Alwil Software
    2009-10-21 19:55 . 2009-10-21 20:03	--------	d-----w-	c:\users\Brett\AppData\Roaming\Ventrilo
    2009-10-21 18:21 . 2009-10-21 18:21	--------	d-----w-	c:\program files\Ventrilo
    2009-10-21 18:13 . 2009-10-21 18:13	--------	d-----w-	c:\program files\Common Files\Wise Installation Wizard
    2009-10-13 20:21 . 2009-10-13 20:22	--------	d-----w-	c:\users\Brett\AppData\Roaming\Notepad++
    2009-10-13 20:21 . 2009-10-13 20:22	--------	d-----w-	c:\program files\Notepad++
    2009-10-06 17:19 . 2009-08-07 02:24	44768	----a-w-	c:\windows\system32\wups2.dll
    2009-10-06 17:19 . 2009-08-07 02:24	53472	----a-w-	c:\windows\system32\wuauclt.exe
    2009-10-06 17:19 . 2009-08-07 02:23	1929952	----a-w-	c:\windows\system32\wuaueng.dll
    2009-10-06 17:19 . 2009-08-07 01:45	2421760	----a-w-	c:\windows\system32\wucltux.dll
    2009-10-06 17:19 . 2009-08-07 02:24	35552	----a-w-	c:\windows\system32\wups.dll
    2009-10-06 17:19 . 2009-08-07 02:23	575704	----a-w-	c:\windows\system32\wuapi.dll
    2009-10-06 17:19 . 2009-08-07 01:44	87552	----a-w-	c:\windows\system32\wudriver.dll
    2009-10-06 17:18 . 2009-08-07 00:23	171608	----a-w-	c:\windows\system32\wuwebv.dll
    2009-10-06 17:18 . 2009-08-06 23:44	33792	----a-w-	c:\windows\system32\wuapp.exe
    
    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-31 00:54 . 2008-10-12 15:32	--------	d-----w-	c:\programdata\NOS
    2009-10-30 23:22 . 2008-10-12 15:23	--------	d-----w-	c:\program files\Java
    2009-10-30 23:09 . 2008-10-12 15:31	1	----a-w-	c:\users\Brett\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
    2009-10-30 23:09 . 2008-10-12 15:30	--------	d-----w-	c:\users\Brett\AppData\Roaming\OpenOffice.org2
    2009-10-11 02:42 . 2008-11-14 18:18	--------	d-----w-	c:\users\Brett\AppData\Roaming\Apple Computer
    2009-09-30 04:46 . 2009-09-30 04:46	--------	d-----w-	c:\users\Brett\AppData\Roaming\Hewlett-Packard
    2009-09-28 04:59 . 2009-09-28 03:36	20454	----a-w-	c:\windows\hpoins01.dat
    2009-09-28 04:58 . 2009-09-28 03:38	--------	d-----w-	c:\program files\Hewlett-Packard
    2009-09-28 04:58 . 2009-09-28 04:58	77004	----a-w-	c:\windows\system32\drivers\AFS.SYS
    2009-09-28 03:42 . 2009-09-28 03:42	--------	d-----w-	c:\program files\Common Files\Hewlett-Packard
    2009-09-26 17:46 . 2008-10-10 21:43	--------	d-----w-	c:\program files\FFXI App
    2009-09-26 17:43 . 2009-09-26 03:31	--------	d-----w-	c:\program files\Wizbot v2
    2009-09-26 05:31 . 2009-09-26 02:01	--------	d-----w-	c:\users\Brett\AppData\Roaming\GetRightToGo
    2009-09-26 05:22 . 2009-09-26 05:22	--------	d-----w-	c:\program files\Perfect World Entertainment
    2009-09-26 01:29 . 2009-09-26 01:29	--------	d-----w-	c:\program files\Common Files\INCA Shared
    2009-09-26 01:14 . 2009-09-26 01:14	--------	d-----w-	c:\program files\GALA-NET
    2009-09-26 00:28 . 2009-09-26 00:27	--------	d-----w-	c:\programdata\PMB Files
    2009-09-26 00:27 . 2009-09-26 00:27	--------	d-----w-	c:\program files\Pando Networks
    2009-09-24 04:03 . 2008-11-14 18:14	--------	d-----w-	c:\programdata\Apple
    2009-09-21 04:16 . 2009-09-21 04:16	--------	d-----w-	c:\programdata\McAfee
    2009-09-20 18:35 . 2009-09-20 18:34	--------	d-----w-	c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2009-09-20 18:35 . 2009-09-20 18:34	--------	d-----w-	c:\program files\iTunes
    2009-09-20 18:34 . 2009-09-20 18:34	--------	d-----w-	c:\program files\iPod
    2009-09-20 18:34 . 2008-11-14 18:14	--------	d-----w-	c:\program files\Common Files\Apple
    2009-09-20 18:32 . 2009-09-20 18:31	--------	d-----w-	c:\program files\QuickTime
    2009-09-19 04:11 . 2009-09-19 04:11	--------	d-----w-	c:\programdata\McAfee Security Scan
    2009-09-19 02:25 . 2006-11-02 11:18	--------	d-----w-	c:\program files\Windows Mail
    2009-09-16 22:27 . 2009-09-16 22:27	--------	d-----w-	c:\program files\Respondus LockDown Browser
    2009-09-16 22:27 . 2008-10-10 19:38	--------	d--h--w-	c:\program files\InstallShield Installation Information
    2009-09-16 22:25 . 2009-09-16 22:25	--------	d-----w-	c:\users\Brett\AppData\Roaming\InstallShield
    2009-09-14 18:38 . 2008-10-16 19:13	--------	d-----w-	c:\programdata\avg8
    2009-09-05 03:59 . 2009-09-05 03:59	--------	d-----w-	c:\program files\Microsoft
    2009-09-05 03:59 . 2009-09-05 03:58	--------	d-----w-	c:\program files\Windows Live
    2009-09-05 03:58 . 2009-09-05 03:58	--------	d-----w-	c:\program files\Windows Live SkyDrive
    2009-09-05 03:55 . 2009-09-05 03:55	--------	d-----w-	c:\program files\Common Files\Windows Live
    2009-08-29 03:41 . 2009-09-03 00:38	1686528	----a-w-	c:\windows\system32\gameux.dll
    2009-08-29 03:40 . 2009-09-03 00:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll
    2009-08-29 00:42 . 2009-08-29 00:42	40448	----a-w-	c:\windows\system32\drivers\usbaapl.sys
    2009-08-29 00:42 . 2009-08-29 00:42	2065696	----a-w-	c:\windows\system32\usbaaplrc.dll
    2009-08-28 23:31 . 2009-09-03 00:38	4247552	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll
    2009-08-14 17:16 . 2009-09-08 18:31	213592	----a-w-	c:\windows\system32\drivers\netio.sys
    2009-08-14 16:42 . 2009-09-08 18:31	167424	----a-w-	c:\windows\system32\tcpipcfg.dll
    2009-08-14 16:40 . 2009-09-08 18:31	103936	----a-w-	c:\windows\system32\netiohlp.dll
    2009-08-14 16:40 . 2009-09-08 18:31	15360	----a-w-	c:\windows\system32\netevent.dll
    2009-08-14 14:25 . 2009-09-08 18:31	9728	----a-w-	c:\windows\system32\TCPSVCS.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	17920	----a-w-	c:\windows\system32\ROUTE.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	11264	----a-w-	c:\windows\system32\MRINFO.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	27136	----a-w-	c:\windows\system32\NETSTAT.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	8704	----a-w-	c:\windows\system32\HOSTNAME.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	19968	----a-w-	c:\windows\system32\ARP.EXE
    2009-08-14 14:25 . 2009-09-08 18:31	10240	----a-w-	c:\windows\system32\finger.exe
    2009-08-14 14:24 . 2009-09-08 18:31	813568	----a-w-	c:\windows\system32\drivers\tcpip.sys
    2009-08-14 14:23 . 2009-09-08 18:31	22016	----a-w-	c:\windows\system32\netiougc.exe
    .
    
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown 
    REGEDIT4
    
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "LWBMOUSE"="c:\program files\Belkin\Wireless Mouse Driver\MOUSE32A.EXE" [2001-11-09 356352]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-01 3772416]
    
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-6 323646]
    hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
    backupExtension=.CommonStartup
    
    [HKLM\~\startupfolder\C:^Users^Brett^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
    path=c:\users\Brett\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
    backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
    backupExtension=.Startup
    
    R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [9/27/2009 11:58 PM 77004]
    R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [10/30/2009 6:42 PM 114768]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2/1/2009 2:13 PM 108552]
    R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [10/30/2009 6:42 PM 20560]
    R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [10/30/2009 6:41 PM 53328]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/16/2008 2:09 PM 809296]
    S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/16/2008 2:14 PM 327688]
    S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
    S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/16/2008 2:13 PM 298776]
    S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork	REG_MULTI_SZ   	PLA DPS BFE mpssvc
    .
    Contents of the 'Scheduled Tasks' folder
    
    2009-10-04 c:\windows\Tasks\Driver Robot.job
    - c:\program files\Driver Robot\1.0.7.1\DriverRobot.exe [2009-06-11 17:09]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.com/
    FF - ProfilePath - c:\users\Brett\AppData\Roaming\Mozilla\Firefox\Profiles\uo3pzh8m.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    
    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    .
    - - - - ORPHANS REMOVED - - - -
    
    HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
    
    
    
    **************************************************************************
    scanning hidden processes ...  
    
    scanning hidden autostart entries ... 
    
    scanning hidden files ...  
    
    scan completed successfully
    hidden files: 
    
    **************************************************************************
    
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Completion time: 2009-10-31 20:22
    ComboFix-quarantined-files.txt  2009-10-31 01:22
    
    Pre-Run: 45,801,197,568 bytes free
    Post-Run: 45,600,260,096 bytes free
    
    Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5
    - - End Of File - - 6C78EFFF2333586E2C759DA547DC8C00
    hijackthis log

    Code:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:30:21 PM, on 10/30/2009
    Platform: Windows Vista  (WinNT 6.00.1904)
    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
    Boot mode: Normal
    
    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\Belkin\Wireless Mouse Driver\Mouse32A.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Electronic Arts\EADM\Core.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\Explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Belkin\Wireless Mouse Driver\MOUSE32A.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://games.adultswim.com/carls-freakin-strip-poker-puzzle-online-game.html"
    O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    
    --
    End of file - 5464 bytes

  2. #2
    Cerberus
    Join Date
    Oct 2008
    Posts
    436
    BG Level
    4

    nvm AVG is still on the program file list... but not under start menu or under add or remove programs, how can i get rid of damn thing.

    Also in precautions i have done the fallowing, is there anything else i can do?

    Installed noscript
    installed adblock
    updated flash player
    updated java
    installed avasta
    installed malewarebytes
    ran combo fix
    ran hijackthis

  3. #3
    Kavier
    Guest

    If you google avg remover or something like that you should get something that will remove it, I've got a program that is meant for removing avg in my computer repair kit but can't remember where I got it.

    Didn't see you say anything about the hijackthis log but from what I see they all look legit, haven't used hijackthis but so much so don't take my word on that. As for combofix, not much experience with that as well, haven't had many chances or needs so far saying merely just fix people's computers on my dorm for free heh.

    edit: Did you put filter subscriptions up for adblock?

  4. #4
    Melee Summoner
    Join Date
    Oct 2009
    Posts
    38
    BG Level
    1

    Quote Originally Posted by Skie View Post
    nvm AVG is still on the program file list... but not under start menu or under add or remove programs, how can i get rid of damn thing.
    Start -> Search -> "AVG"

    Delete everything manually.

    Start -> Run -> msconfig -> OK

    Startup Tab, Deselect anything that resembles AVG.


    ... According to your logs, you have quite a lot of unnecessary software installed.

  5. #5
    Cerberus
    Join Date
    Oct 2008
    Posts
    436
    BG Level
    4

    Quote Originally Posted by Princemercury View Post
    Start -> Search -> "AVG"

    Delete everything manually.

    Start -> Run -> msconfig -> OK

    Startup Tab, Deselect anything that resembles AVG.


    ... According to your logs, you have quite a lot of unnecessary software installed.
    yes i used usa filters not sure best settings.

    i would love to get rid of anything unnessary to speed up pc and try to help over heating, can you tell me waht and how to get rid of it.

    Also last night i redownloaded avg to unintall it. i think it solved the problem but the program files are still there under C://programfiles. if i try to delete the folder it says i need premission, and ask to retry. Also running everything on gfs pc today will post logs. Her's stars realy slow

  6. #6
    Cerberus
    Join Date
    Oct 2008
    Posts
    436
    BG Level
    4

    gfs log

    combo fix log on gfs pc.

    Code:
    ComboFix 09-10-30.01 - Whitney 10/31/2009 15:35.2.2 - NTFSx86
    Microsoft® Windows Vista™ Home Basic   6.0.6000.0.1252.1.1033.18.1022.458 [GMT -5:00]
    Running from: e:\clean up files\combo.exe
    SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .
    
    (((((((((((((((((((((((((   Files Created from 2009-09-28 to 2009-10-31  )))))))))))))))))))))))))))))))
    .
    
    2009-10-31 20:40 . 2009-10-31 20:40	--------	d-----w-	c:\users\Whitney\AppData\Local\temp
    2009-10-31 20:40 . 2009-10-31 20:40	--------	d-----w-	c:\users\Public\AppData\Local\temp
    2009-10-31 20:40 . 2009-10-31 20:40	--------	d-----w-	c:\users\Default\AppData\Local\temp
    2009-10-31 20:35 . 2006-11-02 09:49	19048	----a-w-	c:\windows\system32\drivers\atapi.sys
    2009-10-31 19:23 . 2009-10-31 19:23	--------	d-----w-	c:\programdata\Avg8
    2009-10-31 00:50 . 2009-10-31 19:24	--------	d-----w-	c:\users\Whitney\AppData\Roaming\Uniblue
    2009-10-31 00:50 . 2009-10-31 19:24	--------	d-----w-	c:\program files\Uniblue
    2009-10-20 13:35 . 2009-10-20 13:35	53472	----a-w-	c:\windows\system32\wuauclt.exe
    2009-10-20 13:35 . 2009-10-20 13:35	44768	----a-w-	c:\windows\system32\wups2.dll
    2009-10-20 13:35 . 2009-10-20 13:35	2421760	----a-w-	c:\windows\system32\wucltux.dll
    2009-10-20 13:35 . 2009-10-20 13:35	1929952	----a-w-	c:\windows\system32\wuaueng.dll
    2009-10-20 13:34 . 2009-10-20 13:34	87552	----a-w-	c:\windows\system32\wudriver.dll
    2009-10-20 13:34 . 2009-10-20 13:34	35552	----a-w-	c:\windows\system32\wups.dll
    2009-10-20 13:34 . 2009-10-20 13:34	575704	----a-w-	c:\windows\system32\wuapi.dll
    2009-10-20 13:33 . 2009-10-20 13:33	33792	----a-w-	c:\windows\system32\wuapp.exe
    2009-10-20 13:33 . 2009-10-20 13:33	171608	----a-w-	c:\windows\system32\wuwebv.dll
    2009-10-18 19:54 . 2009-10-18 20:13	--------	d-----w-	c:\users\Whitney\AppData\Roaming\Ventrilo
    2009-10-18 19:52 . 2009-10-18 19:52	--------	d-----w-	c:\program files\Ventrilo
    2009-10-18 19:51 . 2009-10-18 19:51	--------	d-----w-	c:\program files\Common Files\Wise Installation Wizard
    
    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-31 00:57 . 2009-08-17 16:02	--------	d-----w-	c:\programdata\NOS
    2009-10-31 00:38 . 2008-12-06 23:16	--------	d-----w-	c:\program files\Java
    2009-09-30 19:20 . 2009-09-30 19:20	--------	d-----w-	c:\program files\Microsoft
    2009-09-30 19:20 . 2009-09-30 19:20	--------	d-----w-	c:\program files\Windows Live
    2009-09-30 19:20 . 2009-09-30 19:20	--------	d-----w-	c:\program files\Windows Live SkyDrive
    2009-09-30 19:16 . 2009-09-30 19:16	--------	d-----w-	c:\program files\Common Files\Windows Live
    2009-09-27 07:05 . 2009-09-27 07:05	--------	d-----w-	c:\program files\Wizbot v2
    2009-09-26 01:39 . 2009-09-26 01:39	--------	d-----w-	c:\programdata\PMB Files
    2009-09-26 01:38 . 2009-09-26 01:38	--------	d-----w-	c:\program files\Pando Networks
    2009-09-23 15:54 . 2009-09-23 15:54	494592	----a-w-	c:\windows\system32\kerberos.dll
    2009-09-23 15:54 . 2009-09-23 15:54	408136	----a-w-	c:\windows\system32\drivers\ksecdd.sys
    2009-09-23 15:54 . 2009-09-23 15:54	216576	----a-w-	c:\windows\system32\msv1_0.dll
    2009-09-23 15:54 . 2009-09-23 15:54	175104	----a-w-	c:\windows\system32\wdigest.dll
    2009-09-23 15:54 . 2009-09-23 15:54	7680	----a-w-	c:\windows\system32\lsass.exe
    2009-09-23 15:54 . 2009-09-23 15:54	72704	----a-w-	c:\windows\system32\secur32.dll
    2009-09-23 15:54 . 2009-09-23 15:54	1233920	----a-w-	c:\windows\system32\lsasrv.dll
    2009-09-23 15:54 . 2009-09-23 15:54	272384	----a-w-	c:\windows\system32\schannel.dll
    2009-09-16 22:24 . 2009-09-16 22:24	--------	d-----w-	c:\program files\Respondus LockDown Browser
    2009-09-16 22:24 . 2008-10-13 03:06	--------	d--h--w-	c:\program files\InstallShield Installation Information
    2009-09-16 22:24 . 2009-09-16 22:24	--------	d-----w-	c:\users\Whitney\AppData\Roaming\InstallShield
    2009-09-15 22:48 . 2009-09-15 22:48	--------	d-----w-	c:\programdata\McAfee
    2009-09-15 22:01 . 2009-09-15 22:01	--------	d-----w-	c:\programdata\McAfee Security Scan
    2009-09-06 19:25 . 2008-10-13 20:18	--------	d-----w-	c:\program files\FFXI App
    2009-08-29 02:19 . 2009-08-29 02:19	974336	----a-w-	c:\windows\system32\crypt32.dll
    2009-08-29 02:19 . 2009-08-29 02:19	0	----a-w-	c:\windows\ativpsrm.bin
    2009-08-03 23:56 . 2009-08-03 23:56	530	----a-w-	c:\windows\eReg.dat
    .
    
    (((((((((((((((((((((((((((((   SnapShot@2009-10-31_19.45.50   )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-13 02:40 . 2009-10-31 20:06	35900              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 13:02 . 2009-10-31 20:06	45380              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-10-13 02:40 . 2009-10-31 20:06	8964              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1081374283-556129546-2706615731-1000_UserData.bin
    - 2009-10-31 19:33 . 2009-10-31 19:33	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2009-10-31 20:03 . 2009-10-31 20:03	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2009-10-31 20:03 . 2009-10-31 20:03	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2009-10-31 19:33 . 2009-10-31 19:33	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown 
    REGEDIT4
    
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-12 90112]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-01-08 3772416]
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute	REG_MULTI_SZ   	autocheck autochk /r \??\E:\0autocheck autochk *
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/13/2008 3:11 PM 809296]
    
    --- Other Services/Drivers In Memory ---
    
    *Deregistered* - mbr
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork	REG_MULTI_SZ   	PLA DPS BFE mpssvc
    .
    Contents of the 'Scheduled Tasks' folder
    
    2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{A6CEE5A1-ACCF-4898-8DF1-5A7C689E5425}.job
    - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
    .
    .
    ------- Supplementary Scan -------
    .
    FF - ProfilePath - c:\users\Whitney\AppData\Roaming\Mozilla\Firefox\Profiles\hbtt6yg9.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
    
    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    .
    
    **************************************************************************
    
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-31 15:40
    Windows 6.0.6000  NTFS
    
    scanning hidden processes ...  
    
    scanning hidden autostart entries ... 
    
    scanning hidden files ...  
    
    scan completed successfully
    hidden files: 0
    
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Completion time: 2009-10-31 15:42
    ComboFix-quarantined-files.txt  2009-10-31 20:42
    ComboFix2.txt  2009-10-31 19:48
    
    Pre-Run: 42,551,021,568 bytes free
    Post-Run: 42,525,114,368 bytes free
    
    Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,5
    - - End Of File - - F28E0147324C72DD122F4869D47FD44E
    one thing about this one is that everytime i run combo fix and it finishes i cant open anything... says that its been qued for deletion and i have to restart the pc :/ but anyway anything wrong with this one?

    hijackthis log on gfs pc

    Code:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:48:56 PM, on 10/31/2009
    Platform: Windows Vista  (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16851)
    Boot mode: Normal
    
    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    
    --
    End of file - 3084 bytes

  7. #7
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    Remove that one.

    Other than that, doesn't really seem to be anything. Are you letting Combofix run in safe mode? It's far more effective there. Let Malware Bytes take a pass at it, too.

  8. #8
    Cerberus
    Join Date
    Oct 2008
    Posts
    436
    BG Level
    4

    Quote Originally Posted by Cephius View Post
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    Remove that one.

    Other than that, doesn't really seem to be anything. Are you letting Combofix run in safe mode? It's far more effective there. Let Malware Bytes take a pass at it, too.

    how do i remove it?