Computer Suddenly Extremly SLOW 100% CPU Usage

View previous topic View next topic Go down

Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Sun Feb 24, 2013 5:12 pm

My husband's, Windows XP Computer was working fine, haven't installed any new programs or downloaded anything new. Suddenly computer stalled. It takes more than 40 minutes for any browser to open. Have tried Firefox and Internet Explorer. Once the browser opens it takes hours to open a page and then you can't scroll down the page. Task Manager shows the CPU is at 100%.

I have attempted to perform Malwarebytes Scan, and SuperantiSpyware, but I am unable to do these scans. I did a Malewarebytes Scan in Safe Mode, which was a black screen that popped up.

The computer runs fine is Safe Mode. I was able to download OLT in Safe Mode, but when I start the computer in normal mode OLT locks up and will not scan. I attempted to run OLT in Safe Mode, but the Custom Scans/Fixes box will not expand and when I attempt to copy and paste in the field it doesn't appear anything has pasted.

I am stumped. Any ideas what to do next without the OLT scan? Is there any way I can work around these issues to perform the scan? Possibly a way to do the scan in Safe Mode?

Thank you,

Gypsy

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Sun Feb 24, 2013 7:59 pm

Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
Please try to run MBAM again in Safe Mode. If that doesn't work, please try this.

Avira AntiVir Rescue System

1. Download the [You must be registered and logged in to see this link.]
- If you need a free burning application, [You must be registered and logged in to see this link.] works on all operating systems from Microsoft Windows 2000 SP4 onwards.
2. Place a blank CD in your burner and double-click on the downloaded file.
3. The program will automatically burn the CD for you.
4. Place the burned CD into the affected computer and start the computer with the CD in the CD tray.
5. On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
6. Click on the Configuration button.

- Select Scan all files
- Select Try to repair infected files and Rename files, if they cannot be removed
- Select Scan for dialers
- Select Scan for joke programs (Jokes)
- Select Scan for games
- Select Scan for spyware (SPR)

7. Click on Virus scanner
8. Click on Start scanner at the bottom of the screen.

9. Let Avira finish it's scan and then remove any threats found and then exit out of the scanner.
10. Take the CD out of the CD/DVD tray and then restart the computer.

If needed see this [You must be registered and logged in to see this link.]

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Mon Feb 25, 2013 2:50 am

I downloaded Avira to my working computer, but when I attempted to put it on a CD, I kept getting a message that there was not a CD in the CD drive. I ended up dragging the download to my desktop, downloaded CDBurnerXP, and burned Avira as an ISO. I put the disk in the malfunctioning computer, and started the computer. The computer slowly booted up, and then went to it's normal desktop screen. I waited for an hour thinking that maybe the program was talking a very long time to open. Nothing happened. I restarted the computer in Safe Mode with the disk installed. Safe mode started normally as well. I attempted to open the disk, and got an error message that stated "Windows cannot read from this disk. The disk might be corrupted or it could be using a different format.

I am not sure if I used the wrong option in CDBurnerXP, or what they problem is.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Mon Feb 25, 2013 8:07 pm

Please try it in your working computer. If it's burned correctly, it should start

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Tue Feb 26, 2013 8:14 am

I downloaded the Avira virus program to a different computer and when I double clicked on the download it burned to the CD. I place the disk in the non working computer and attempted to start the computer in normal mode and in safe mode with the CD, but it did not work. In Safe Mode when I opened the disk drive and attempted to open the disk, I got the error message, "Windows cannot read from this disk. The disk might be corrupted or it could be using a different format". I also tried the disk in my working computer, but had no luck at all.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Tue Feb 26, 2013 7:38 pm

Here's another rescue disk. This one if created correctly will boot your computer. It will completely bypass the harddrive. I would recommend using CD-RW's which are rewritable.

We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

Download the OTLPE Standard REATOGO Windows Recovery Environment.

  • Place a blank CD-R disc in to your CD burning drive.
  • Download [You must be registered and logged in to see this link.] and double-click on it to burn to a CD using an ISO Burner. One can be found [You must be registered and logged in to see this link.]
  • Reboot your system using the boot CD you just created.
  • Note : If you do not know how to set your computer to boot from CD follow the steps [You must be registered and logged in to see this link.]
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
  • Change Drivers to Non-Microsoft
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\_OTL\MovedFiles
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the OTL.txt file in your reply.


Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Thu Feb 28, 2013 8:38 am

I can not get this to work and I have tried it several times and burned it to several disks thinking I did something wrong.

I downloaded OTLPEStd.exe,

I then double click on the download and a message pops up asking if I want to burn to a CD. I select, Yes

IMGBurn appears and then I select burn, and when it's done with the process a message pops up showing the process is complete.

Once this is done, I place the disk in the computer. When I turn on the computer I press the Delete key.

The screen gives me the option to move my arrow to Boot.

Then I select 4th Boot Device Atapi CDROM

Then I select F10 Save and Exit

Then I am asked if I wish to Save Configuration changes and exit now. I select yes.

The computer loads into Windows and after some time goes to the desk top. Once I got a Disk Drive Error message, and the option to press Del to Resume, but other than that one time, it always goes right to Windows.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Thu Feb 28, 2013 8:25 pm

Then I select 4th Boot Device Atapi CDROM
Then I select 4th Boot Device Atapi CDROM
You need to set your CDrom as your first boot device.
The computer loads into Windows and after some time goes to the desk top.
You are able to boot to the desktop?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Fri Mar 01, 2013 12:00 am

Okay this is what I have done today.

I chose the boot sequence as 1st Boot ATAPI CDROM
I select F10 to Save and Exit
Saved Configuration and exited

Black Screen comes up with a black blinking dash at the top left corner that lasts for about 1 minute.

Microsoft XP Comes on the screen and loads for about 2 minutes.

Welcome screen comes on.

Then MY desk top comes up with the icons for whatever programs I have saved to the desk top.

My wireless modem antenna starts to load which takes a very long time. If I select Firefox or Internet Explorer it takes about 40 minutes for them to come up, then I can't access a website. If I open Malwarebytes, or another program it takes a very long time for those to open as well, and I can not update them.

Last night I selected the option to end a SVCHost System in Task Manager that shows to be using a huge amount of space, and I was able to open Malwarebytes, and run a scan, but it would not update and the scan showed to be clean.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Fri Mar 01, 2013 2:50 am

Ok. Let's try this:

Save these instructions so you can have access to them while in Safe Mode.

Please click [You must be registered and logged in to see this link.] to download AVP Tool by Kaspersky.

  • Save it to your desktop.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
  • Double click the setup file to run it.
  • Click Next to continue.
  • Accept the License agreement and click on next.
  • It will, by default, install it to your desktop folder. Click Next.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • Hidden Startup Objects
  • System Memory
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)

Leave the rest of the settings as they appear as default.
•Then click on Scan at the to right hand Corner.
•It will automatically Neutralize any objects found.
•If some objects are left un-neutralized then click the button that says Neutralize all
•If it says it cannot be neutralized then choose the delete option when prompted.
•After that is done click on the reports button at the bottom and save it to file name it Kas.
•Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

Note: This tool will self uninstall when you close it so please save the log before closing it.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Fri Mar 01, 2013 3:37 am

Will I be able to download in Safe Mode, because I can't get to the internet on that computer in normal mode?

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Fri Mar 01, 2013 8:06 pm

[You must be registered and logged in to see this link.] wrote:Will I be able to download in Safe Mode, because I can't get to the internet on that computer in normal mode?
When you boot in Safe mode, select Safe mode with NetWorking.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Mon Mar 04, 2013 5:39 pm

Okay, I got it to work. 14 different viruses and adware were found. I chose to save the file, or so I thought, but I can not find the file on the desk top or anywhere. The computer does seem to be working again. Is there something else I should do? Of something I should copy and paste here?

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Mon Mar 04, 2013 7:21 pm

Good job. Now we finish up with the cleaning.

Please download [You must be registered and logged in to see this link.]by Xplode onto your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

*********************************************
Please download Malwarebytes Anti-Malware from [You must be registered and logged in to see this link.]
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Mon Mar 04, 2013 8:06 pm

The AdwCleaner report is below. Will update MBAM now.

# AdwCleaner v2.113 - Logfile created 03/04/2013 at 14:00:10
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Robert - R2D2
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Robert\My Documents\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\searchplugins\Ask.xml
File Found : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\searchplugins\Conduit.xml
File Found : C:\Program Files\Mozilla FireFox\Components\AskSearch.js
File Found : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Found : C:\Documents and Settings\All Users\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
Folder Found : C:\Documents and Settings\Robert\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\ConduitCommon
Folder Found : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\CT3008668
Folder Found : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\extensions\{9427041a-a8dc-4d06-9a68-93873486e957}
Folder Found : C:\Documents and Settings\Robert\Local Settings\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\Robert\Local Settings\Application Data\AVG Security Toolbar
Folder Found : C:\Program Files\AVG Secure Search
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\Program Files\Viewpoint

***** [Registry] *****

Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\AVG Security Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\Software\AskBarDis
Key Found : HKLM\Software\AVG Secure Search
Key Found : HKLM\Software\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKU\S-1-5-21-1214440339-1078145449-854245398-1004\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKU\S-1-5-21-1214440339-1078145449-854245398-1004\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = [You must be registered and logged in to see this link.] 03:43:50&pid=avg&sg=&v=14.2.0.1&sap=nt

-\\ Mozilla Firefox v19.0 (en-US)

File : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\prefs.js

Found : user_pref("CT3008668..clientLogIsEnabled", false);
Found : user_pref("CT3008668..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT3008668..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT3008668.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT3008668.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT3008668.AppTrackingLastCheckTime", "Tue Mar 20 2012 13:39:41 GMT-0500 (Central Daylight[...]
Found : user_pref("CT3008668.BrowserCompStateIsOpen_129558882344224997", true);
Found : user_pref("CT3008668.BrowserCompStateIsOpen_129683379764764212", true);
Found : user_pref("CT3008668.CT3008668", "CT3008668");
Found : user_pref("CT3008668.CurrentServerDate", "22-3-2012");
Found : user_pref("CT3008668.DSChangedManually", false);
Found : user_pref("CT3008668.DSInstall", true);
Found : user_pref("CT3008668.DSProtectChoice", true);
Found : user_pref("CT3008668.DSProtectCount", 1);
Found : user_pref("CT3008668.DialogsAlignMode", "LTR");
Found : user_pref("CT3008668.DialogsGetterLastCheckTime", "Wed Mar 21 2012 13:39:49 GMT-0500 (Central Daylig[...]
Found : user_pref("CT3008668.DownloadReferralCookieData", "");
Found : user_pref("CT3008668.EMailNotifierCheckInterval", "5");
Found : user_pref("CT3008668.EMailNotifierPollDate", "Wed Mar 21 2012 23:54:07 GMT-0500 (Central Daylight Ti[...]
Found : user_pref("CT3008668.EMailNotifierSound", "C:\\WINDOWS\\MEDIA\\ding.wav");
Found : user_pref("CT3008668.ExternalComponentPollDate129498282979356777", "Wed Mar 21 2012 23:43:52 GMT-050[...]
Found : user_pref("CT3008668.FirstServerDate", "15-3-2012");
Found : user_pref("CT3008668.FirstTime", true);
Found : user_pref("CT3008668.FirstTimeFF3", true);
Found : user_pref("CT3008668.FixPageNotFoundErrors", false);
Found : user_pref("CT3008668.GroupingServerCheckInterval", 1440);
Found : user_pref("CT3008668.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT3008668.HPInstall", true);
Found : user_pref("CT3008668.HasUserGlobalKeys", true);
Found : user_pref("CT3008668.HomePageProtectorEnabled", true);
Found : user_pref("CT3008668.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=[...]
Found : user_pref("CT3008668.Initialize", true);
Found : user_pref("CT3008668.InitializeCommonPrefs", true);
Found : user_pref("CT3008668.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT3008668.InstallationType", "Unknown");
Found : user_pref("CT3008668.InstalledDate", "Thu Mar 15 2012 13:39:56 GMT-0500 (Central Daylight Time)");
Found : user_pref("CT3008668.InvalidateCache", false);
Found : user_pref("CT3008668.IsAlertDBUpdated", true);
Found : user_pref("CT3008668.IsGrouping", false);
Found : user_pref("CT3008668.IsInitSetupIni", true);
Found : user_pref("CT3008668.IsMulticommunity", false);
Found : user_pref("CT3008668.IsOpenThankYouPage", true);
Found : user_pref("CT3008668.IsOpenUninstallPage", true);
Found : user_pref("CT3008668.IsProtectorsInit", true);
Found : user_pref("CT3008668.LanguagePackLastCheckTime", "Wed Mar 21 2012 13:39:56 GMT-0500 (Central Dayligh[...]
Found : user_pref("CT3008668.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT3008668.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT3008668.LastLogin_3.10.0.1", "Wed Mar 21 2012 23:43:55 GMT-0500 (Central Daylight Time)[...]
Found : user_pref("CT3008668.LatestVersion", "3.10.0.1");
Found : user_pref("CT3008668.Locale", "en");
Found : user_pref("CT3008668.MCDetectTooltipHeight", "83");
Found : user_pref("CT3008668.MCDetectTooltipShow", false);
Found : user_pref("CT3008668.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT3008668.MCDetectTooltipWidth", "295");
Found : user_pref("CT3008668.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT3008668.OriginalFirstVersion", "3.10.0.1");
Found : user_pref("CT3008668.RadioIsPodcast", false);
Found : user_pref("CT3008668.RadioLastCheckTime", "Wed Mar 21 2012 13:41:17 GMT-0500 (Central Daylight Time)[...]
Found : user_pref("CT3008668.RadioLastUpdateIPServer", "3");
Found : user_pref("CT3008668.RadioLastUpdateServer", "3");
Found : user_pref("CT3008668.RadioMediaID", "9962");
Found : user_pref("CT3008668.RadioMediaType", "Media Player");
Found : user_pref("CT3008668.RadioMenuSelectedID", "EBRadioMenu_CT30086689962");
Found : user_pref("CT3008668.RadioShrinkedFromSetup", false);
Found : user_pref("CT3008668.RadioStationName", "California%20Rock");
Found : user_pref("CT3008668.RadioStationURL", "hxxp://feedlive.net/california.asx");
Found : user_pref("CT3008668.SavedHomepage", "hxxp://mail.google.com/mail/?shva=1#inbox");
Found : user_pref("CT3008668.SearchCaption", "Productivity 3.1 Customized Web Search");
Found : user_pref("CT3008668.SearchEngineBeforeUnload", "Productivity 3.1 Customized Web Search");
Found : user_pref("CT3008668.SearchFromAddressBarIsInit", true);
Found : user_pref("CT3008668.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT300[...]
Found : user_pref("CT3008668.SearchInNewTabEnabled", true);
Found : user_pref("CT3008668.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT3008668.SearchInNewTabLastCheckTime", "Wed Mar 21 2012 13:40:47 GMT-0500 (Central Dayli[...]
Found : user_pref("CT3008668.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT3008668.SearchProtectorEnabled", true);
Found : user_pref("CT3008668.SearchProtectorToolbarDisabled", true);
Found : user_pref("CT3008668.SendProtectorDataViaLogin", true);
Found : user_pref("CT3008668.ServiceMapLastCheckTime", "Wed Mar 21 2012 13:39:41 GMT-0500 (Central Daylight [...]
Found : user_pref("CT3008668.SettingsLastCheckTime", "Wed Mar 21 2012 23:43:49 GMT-0500 (Central Daylight Ti[...]
Found : user_pref("CT3008668.SettingsLastUpdate", "1330964899");
Found : user_pref("CT3008668.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=13");
Found : user_pref("CT3008668.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT3008668.ThirdPartyComponentsLastCheck", "Thu Mar 15 2012 13:39:29 GMT-0500 (Central Day[...]
Found : user_pref("CT3008668.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT3008668.ToolbarDisabled", true);
Found : user_pref("CT3008668.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT3008668.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3008668");
Found : user_pref("CT3008668.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT3008668.UserID", "UN99091306974699165");
Found : user_pref("CT3008668.ValidationData_Toolbar", 2);
Found : user_pref("CT3008668.WeatherNetwork", "");
Found : user_pref("CT3008668.WeatherPollDate", "Wed Mar 21 2012 23:44:04 GMT-0500 (Central Daylight Time)");
Found : user_pref("CT3008668.WeatherUnit", "F");
Found : user_pref("CT3008668.alertChannelId", "1400399");
Found : user_pref("CT3008668.approveUntrustedApps", false);
Found : user_pref("CT3008668.backendstorage.cb_firstuse0100", "31");
Found : user_pref("CT3008668.backendstorage.cb_user_id_000", "43423434303235363635353631325F46697265666F78")[...]
Found : user_pref("CT3008668.backendstorage.cbfirsttime", "546875204D617220313520323031322031333A34313A31342[...]
Found : user_pref("CT3008668.backendstorage.event_data", "253542253544");
Found : user_pref("CT3008668.backendstorage.fired_events", "");
Found : user_pref("CT3008668.backendstorage.key_date", "3231");
Found : user_pref("CT3008668.backendstorage.shoppingapp.gk.exipres", "4D6F6E204D617220323620323031322031323A[...]
Found : user_pref("CT3008668.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
Found : user_pref("CT3008668.backendstorage.url_history0001", "687474703A2F2F7777772E6666746F6F6C626F782E636[...]
Found : user_pref("CT3008668.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT3008668.globalFirstTimeInfoLastCheckTime", "Thu Mar 15 2012 13:39:35 GMT-0500 (Central [...]
Found : user_pref("CT3008668.homepageProtectorEnableByLogin", true);
Found : user_pref("CT3008668.initDone", true);
Found : user_pref("CT3008668.isAppTrackingManagerOn", true);
Found : user_pref("CT3008668.isFirstRadioInstallation", false);
Found : user_pref("CT3008668.myStuffEnabled", true);
Found : user_pref("CT3008668.myStuffPublihserMinWidth", 400);
Found : user_pref("CT3008668.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT3008668.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT3008668.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT3008668.navigateToUrlOnSearch", false);
Found : user_pref("CT3008668.revertSettingsEnabled", false);
Found : user_pref("CT3008668.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT3008668.searchProtectorEnableByLogin", true);
Found : user_pref("CT3008668.testingCtid", "");
Found : user_pref("CT3008668.toolbarAppMetaDataLastCheckTime", "Wed Mar 21 2012 13:39:46 GMT-0500 (Central D[...]
Found : user_pref("CT3008668.toolbarContextMenuLastCheckTime", "Thu Mar 15 2012 13:39:48 GMT-0500 (Central D[...]
Found : user_pref("CT3008668.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3008668&Search[...]
Found : user_pref("CommunityToolbar.ConduitSearchList", "Productivity 3.1 Customized Web Search");
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3008668/CT3008668[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1400399/1396057/US", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3008668", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3008668",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"15c[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Robert\\Applicatio[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT3008668");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT3008668");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT3008668");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Wed Mar 21 2012 13:40:01 GMT-0500 (Cen[...]
Found : user_pref("CommunityToolbar.globalUserId", "dc5f93a7-52b8-4d9e-93fd-6ddcd1246666");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3008668");
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Mar 15 2012 13:39:4[...]
Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Mar 21 2012 23:44:04 GMT-050[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Mar 21 2012 13:39:44 GMT-0500 (C[...]
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "d7d8a32c-80b2-4307-9733-bf558d0a9484");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://mail.google.com/mail/?shva=1#inbox");
Found : user_pref("CommunityToolbar.originalSearchEngine", "AVG Secure Search");
Found : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Application Data\\AV[...]
Found : user_pref("avg.install.userHPSettings", "hxxp://mail.google.com/mail/?shva=1#inbox");
Found : user_pref("avg.toolbar.websearchlink", "hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg");
Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Found : user_pref("browser.search.defaultthis.engineName", "Productivity 3.1 Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3008668&Sea[...]
Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=13");
Found : user_pref("extensions.snipit.askTbInstalled", true);
Found : user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&g[...]
Found : user_pref("startup.homepage_override_url", "hxxp://www.ask.com/?o=20011&l=dis");

*************************

AdwCleaner[R1].txt - [21193 octets] - [04/03/2013 14:00:10]

########## EOF - C:\AdwCleaner[R1].txt - [21254 octets] ##########

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Mon Mar 04, 2013 11:07 pm

Remove the Adware:

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Mon Mar 04, 2013 11:23 pm

Mbam scan was clean

Should I run another search with AdwCleaner, or just select delete?

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Mon Mar 04, 2013 11:35 pm

Should I run another search with AdwCleaner, or just select delete?
Just run it again and select "Delete" instead of Search.

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

To prevent your anti-virus application interfering with ComboFix we need to disable it. See [You must be registered and logged in to see this link.] for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:



Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Mon Mar 04, 2013 11:43 pm

This is the report from AdwCleaner


# AdwCleaner v2.113 - Logfile created 03/04/2013 at 17:30:18
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Robert - R2D2
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Robert\My Documents\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search
File Deleted : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\searchplugins\Ask.xml
File Deleted : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\searchplugins\Conduit.xml
File Deleted : C:\Program Files\Mozilla FireFox\Components\AskSearch.js
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
Folder Deleted : C:\Documents and Settings\Robert\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\ConduitCommon
Folder Deleted : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\CT3008668
Folder Deleted : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\extensions\{9427041a-a8dc-4d06-9a68-93873486e957}
Folder Deleted : C:\Documents and Settings\Robert\Local Settings\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Robert\Local Settings\Application Data\AVG Security Toolbar
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\Viewpoint

***** [Registry] *****

Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\Software\AskBarDis
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = [You must be registered and logged in to see this link.] 03:43:50&pid=avg&sg=&v=14.2.0.1&sap=nt --> [You must be registered and logged in to see this link.]

-\\ Mozilla Firefox v19.0 (en-US)

File : C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\prefs.js

C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\o2ztdjru.default\user.js ... Deleted !

Deleted : user_pref("CT3008668..clientLogIsEnabled", false);
Deleted : user_pref("CT3008668..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT3008668..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT3008668.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT3008668.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT3008668.AppTrackingLastCheckTime", "Tue Mar 20 2012 13:39:41 GMT-0500 (Central Daylight[...]
Deleted : user_pref("CT3008668.BrowserCompStateIsOpen_129558882344224997", true);
Deleted : user_pref("CT3008668.BrowserCompStateIsOpen_129683379764764212", true);
Deleted : user_pref("CT3008668.CT3008668", "CT3008668");
Deleted : user_pref("CT3008668.CurrentServerDate", "22-3-2012");
Deleted : user_pref("CT3008668.DSChangedManually", false);
Deleted : user_pref("CT3008668.DSInstall", true);
Deleted : user_pref("CT3008668.DSProtectChoice", true);
Deleted : user_pref("CT3008668.DSProtectCount", 1);
Deleted : user_pref("CT3008668.DialogsAlignMode", "LTR");
Deleted : user_pref("CT3008668.DialogsGetterLastCheckTime", "Wed Mar 21 2012 13:39:49 GMT-0500 (Central Daylig[...]
Deleted : user_pref("CT3008668.DownloadReferralCookieData", "");
Deleted : user_pref("CT3008668.EMailNotifierCheckInterval", "5");
Deleted : user_pref("CT3008668.EMailNotifierPollDate", "Wed Mar 21 2012 23:54:07 GMT-0500 (Central Daylight Ti[...]
Deleted : user_pref("CT3008668.EMailNotifierSound", "C:\\WINDOWS\\MEDIA\\ding.wav");
Deleted : user_pref("CT3008668.ExternalComponentPollDate129498282979356777", "Wed Mar 21 2012 23:43:52 GMT-050[...]
Deleted : user_pref("CT3008668.FirstServerDate", "15-3-2012");
Deleted : user_pref("CT3008668.FirstTime", true);
Deleted : user_pref("CT3008668.FirstTimeFF3", true);
Deleted : user_pref("CT3008668.FixPageNotFoundErrors", false);
Deleted : user_pref("CT3008668.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT3008668.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT3008668.HPInstall", true);
Deleted : user_pref("CT3008668.HasUserGlobalKeys", true);
Deleted : user_pref("CT3008668.HomePageProtectorEnabled", true);
Deleted : user_pref("CT3008668.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=[...]
Deleted : user_pref("CT3008668.Initialize", true);
Deleted : user_pref("CT3008668.InitializeCommonPrefs", true);
Deleted : user_pref("CT3008668.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT3008668.InstallationType", "Unknown");
Deleted : user_pref("CT3008668.InstalledDate", "Thu Mar 15 2012 13:39:56 GMT-0500 (Central Daylight Time)");
Deleted : user_pref("CT3008668.InvalidateCache", false);
Deleted : user_pref("CT3008668.IsAlertDBUpdated", true);
Deleted : user_pref("CT3008668.IsGrouping", false);
Deleted : user_pref("CT3008668.IsInitSetupIni", true);
Deleted : user_pref("CT3008668.IsMulticommunity", false);
Deleted : user_pref("CT3008668.IsOpenThankYouPage", true);
Deleted : user_pref("CT3008668.IsOpenUninstallPage", true);
Deleted : user_pref("CT3008668.IsProtectorsInit", true);
Deleted : user_pref("CT3008668.LanguagePackLastCheckTime", "Wed Mar 21 2012 13:39:56 GMT-0500 (Central Dayligh[...]
Deleted : user_pref("CT3008668.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT3008668.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT3008668.LastLogin_3.10.0.1", "Wed Mar 21 2012 23:43:55 GMT-0500 (Central Daylight Time)[...]
Deleted : user_pref("CT3008668.LatestVersion", "3.10.0.1");
Deleted : user_pref("CT3008668.Locale", "en");
Deleted : user_pref("CT3008668.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT3008668.MCDetectTooltipShow", false);
Deleted : user_pref("CT3008668.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT3008668.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT3008668.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT3008668.OriginalFirstVersion", "3.10.0.1");
Deleted : user_pref("CT3008668.RadioIsPodcast", false);
Deleted : user_pref("CT3008668.RadioLastCheckTime", "Wed Mar 21 2012 13:41:17 GMT-0500 (Central Daylight Time)[...]
Deleted : user_pref("CT3008668.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT3008668.RadioLastUpdateServer", "3");
Deleted : user_pref("CT3008668.RadioMediaID", "9962");
Deleted : user_pref("CT3008668.RadioMediaType", "Media Player");
Deleted : user_pref("CT3008668.RadioMenuSelectedID", "EBRadioMenu_CT30086689962");
Deleted : user_pref("CT3008668.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT3008668.RadioStationName", "California%20Rock");
Deleted : user_pref("CT3008668.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT3008668.SavedHomepage", "hxxp://mail.google.com/mail/?shva=1#inbox");
Deleted : user_pref("CT3008668.SearchCaption", "Productivity 3.1 Customized Web Search");
Deleted : user_pref("CT3008668.SearchEngineBeforeUnload", "Productivity 3.1 Customized Web Search");
Deleted : user_pref("CT3008668.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT3008668.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT300[...]
Deleted : user_pref("CT3008668.SearchInNewTabEnabled", true);
Deleted : user_pref("CT3008668.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT3008668.SearchInNewTabLastCheckTime", "Wed Mar 21 2012 13:40:47 GMT-0500 (Central Dayli[...]
Deleted : user_pref("CT3008668.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT3008668.SearchProtectorEnabled", true);
Deleted : user_pref("CT3008668.SearchProtectorToolbarDisabled", true);
Deleted : user_pref("CT3008668.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT3008668.ServiceMapLastCheckTime", "Wed Mar 21 2012 13:39:41 GMT-0500 (Central Daylight [...]
Deleted : user_pref("CT3008668.SettingsLastCheckTime", "Wed Mar 21 2012 23:43:49 GMT-0500 (Central Daylight Ti[...]
Deleted : user_pref("CT3008668.SettingsLastUpdate", "1330964899");
Deleted : user_pref("CT3008668.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=13");
Deleted : user_pref("CT3008668.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT3008668.ThirdPartyComponentsLastCheck", "Thu Mar 15 2012 13:39:29 GMT-0500 (Central Day[...]
Deleted : user_pref("CT3008668.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT3008668.ToolbarDisabled", true);
Deleted : user_pref("CT3008668.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT3008668.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3008668");
Deleted : user_pref("CT3008668.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT3008668.UserID", "UN99091306974699165");
Deleted : user_pref("CT3008668.ValidationData_Toolbar", 2);
Deleted : user_pref("CT3008668.WeatherNetwork", "");
Deleted : user_pref("CT3008668.WeatherPollDate", "Wed Mar 21 2012 23:44:04 GMT-0500 (Central Daylight Time)");
Deleted : user_pref("CT3008668.WeatherUnit", "F");
Deleted : user_pref("CT3008668.alertChannelId", "1400399");
Deleted : user_pref("CT3008668.approveUntrustedApps", false);
Deleted : user_pref("CT3008668.backendstorage.cb_firstuse0100", "31");
Deleted : user_pref("CT3008668.backendstorage.cb_user_id_000", "43423434303235363635353631325F46697265666F78")[...]
Deleted : user_pref("CT3008668.backendstorage.cbfirsttime", "546875204D617220313520323031322031333A34313A31342[...]
Deleted : user_pref("CT3008668.backendstorage.event_data", "253542253544");
Deleted : user_pref("CT3008668.backendstorage.fired_events", "");
Deleted : user_pref("CT3008668.backendstorage.key_date", "3231");
Deleted : user_pref("CT3008668.backendstorage.shoppingapp.gk.exipres", "4D6F6E204D617220323620323031322031323A[...]
Deleted : user_pref("CT3008668.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
Deleted : user_pref("CT3008668.backendstorage.url_history0001", "687474703A2F2F7777772E6666746F6F6C626F782E636[...]
Deleted : user_pref("CT3008668.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT3008668.globalFirstTimeInfoLastCheckTime", "Thu Mar 15 2012 13:39:35 GMT-0500 (Central [...]
Deleted : user_pref("CT3008668.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT3008668.initDone", true);
Deleted : user_pref("CT3008668.isAppTrackingManagerOn", true);
Deleted : user_pref("CT3008668.isFirstRadioInstallation", false);
Deleted : user_pref("CT3008668.myStuffEnabled", true);
Deleted : user_pref("CT3008668.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT3008668.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT3008668.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT3008668.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT3008668.navigateToUrlOnSearch", false);
Deleted : user_pref("CT3008668.revertSettingsEnabled", false);
Deleted : user_pref("CT3008668.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT3008668.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT3008668.testingCtid", "");
Deleted : user_pref("CT3008668.toolbarAppMetaDataLastCheckTime", "Wed Mar 21 2012 13:39:46 GMT-0500 (Central D[...]
Deleted : user_pref("CT3008668.toolbarContextMenuLastCheckTime", "Thu Mar 15 2012 13:39:48 GMT-0500 (Central D[...]
Deleted : user_pref("CT3008668.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3008668&Search[...]
Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Productivity 3.1 Customized Web Search");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3008668/CT3008668[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1400399/1396057/US", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3008668", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3008668",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"15c[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Robert\\Applicatio[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT3008668");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT3008668");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT3008668");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Wed Mar 21 2012 13:40:01 GMT-0500 (Cen[...]
Deleted : user_pref("CommunityToolbar.globalUserId", "dc5f93a7-52b8-4d9e-93fd-6ddcd1246666");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3008668");
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Mar 15 2012 13:39:4[...]
Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Mar 21 2012 23:44:04 GMT-050[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Mar 21 2012 13:39:44 GMT-0500 (C[...]
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "d7d8a32c-80b2-4307-9733-bf558d0a9484");
Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://mail.google.com/mail/?shva=1#inbox");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "AVG Secure Search");
Deleted : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Application Data\\AV[...]
Deleted : user_pref("avg.install.userHPSettings", "hxxp://mail.google.com/mail/?shva=1#inbox");
Deleted : user_pref("avg.toolbar.websearchlink", "hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg");
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.defaultthis.engineName", "Productivity 3.1 Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3008668&Sea[...]
Deleted : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3008668&SearchSource=13");
Deleted : user_pref("extensions.snipit.askTbInstalled", true);
Deleted : user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&g[...]
Deleted : user_pref("startup.homepage_override_url", "hxxp://www.ask.com/?o=20011&l=dis");

*************************

AdwCleaner[R1].txt - [21324 octets] - [04/03/2013 14:00:10]
AdwCleaner[S1].txt - [346 octets] - [04/03/2013 17:27:01]
AdwCleaner[S2].txt - [21642 octets] - [04/03/2013 17:30:18]

########## EOF - C:\AdwCleaner[S2].txt - [21703 octets] ##########

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Tue Mar 05, 2013 7:57 am

I installed ComboFix and have attempted several times to use it, but every single time it freezes up. I even turned off the screen saver after the third attempt so that nothing can interfere. The mouse was not clicked. The computer was left untouched. Each time the blue screen appears that states the scan can take up to 10 minutes though in cases of virus infestation the time can double. A cursor comes up under this paragraph and it blinks for about 30 minutes, and then the cursor disappears. At first I thought perhaps it was still scanning, then I realized the clock in the tray had stopped running. I let it set for a couple of hours waiting for something to happen. Nothing did. Each attempt ends with the same result. The computer freezing up.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Tue Mar 05, 2013 6:54 pm

CF can be tricky or cranky at times. Let's try this"

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
[You must be registered and logged in to see this link.]

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Tue Mar 05, 2013 8:26 pm

Can I turn my virus protection back on for this?

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Tue Mar 05, 2013 8:45 pm

[You must be registered and logged in to see this link.] wrote:Can I turn my virus protection back on for this?
Yes.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Wed Mar 06, 2013 1:37 am

The scan has completed, but before I select "Finish", should I select, Uninstall Application on Close, and Delete Quarantined Flies?

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Wed Mar 06, 2013 2:53 am

[You must be registered and logged in to see this link.] wrote:The scan has completed, but before I select "Finish", should I select, Uninstall Application on Close, and Delete Quarantined Flies?
Yes please and post the log if it gives you one.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Wed Mar 06, 2013 3:20 am

This is the scan information.
C:\Program Files\MusicMatch\MusicMatch Jukebox\HWUpdateMove.exe Win32/Adware.HiWire application cleaned by deleting - quarantined
C:\Documents and Settings\Robert\Desktop\couponprinter.exe probably a variant of Win32/Adware.Softomate.AD application cleaned by deleting - quarantined

I did a search and I could not find
C:\Program Files\ESET\ESET Online Scanner\log.txt


GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Wed Mar 06, 2013 7:05 pm

How's your computer running now? Any other issues?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by GypsyCowgirl on Fri Mar 08, 2013 4:01 am

It seems to be doing okay.

GypsyCowgirl
Novice
Novice

Posts Posts : 43
Joined Joined : 2009-04-07
OS OS : XP
Points Points : 28231
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Computer Suddenly Extremly SLOW 100% CPU Usage

Post by Superdave on Fri Mar 08, 2013 6:42 pm

Ok. We can do some cleanup.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
**************************************************
To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
********************************************
Go to [You must be registered and logged in to see this link.] and get all critical updates.

----------

I suggest using [You must be registered and logged in to see this link.]. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

[You must be registered and logged in to see this link.]- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* [You must be registered and logged in to see this link.] from Spyware and Malware
* If you don't know what ActiveX controls are, see [You must be registered and logged in to see this link.]

Protect yourself against spyware using the Immunize feature in [You must be registered and logged in to see this link.] Guide: [You must be registered and logged in to see this link.] to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. [You must be registered and logged in to see this link.]

Check out [You must be registered and logged in to see this link.] for tips and free tools to help keep you safe in the future.

Also see [You must be registered and logged in to see this link.] for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83161
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum