Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

AVG Can' Remove - Replicates


  • Please log in to reply
11 replies to this topic

#1 JayJax

JayJax

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 09:17 PM

I just downloaded from CNET a program called AVG (ha ha, to prevent the kind of problems I just got myself into).

 

Immediately I was suspicious because of requirements in the "I approve" section so I did not approve and it should not have installed but now it is definitely IN.

 

I have used Uninstall as well as Windows standard uninstaller, it says it is uninstalled but then if I look its still there.

 

If I try to "shred" it, it says its running and so it can't be shredded

 

If I try to turn off the "read only" in the system properties it says I have to be an administrator to do that  I am an administrator and I'm having no luck with this obviously pernicious piece of crap i downloaded.   I thought I could trust CNET but obviously I was wrong.

 

What to do to get rid of this intruder?



BC AdBot (Login to Remove)

 


#2 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 09:49 PM

I have the dds report but not sure how to attach it or if I can?

 

I also ran the ADS Spy Tool and came up with 13 entries from AVG - tried to remove it said they were locked by another program.


Edited by JayJax, 09 February 2013 - 09:58 PM.


#3 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,759 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:43 PM

Posted 09 February 2013 - 09:50 PM

Try AVG Remover: http://www.avg.com/us-en/utilities


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#4 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 10:02 PM

Try AVG Remover: http://www.avg.com/us-en/utilities

Thanks I did download the program and tried to run it.  Does it run in the background because i can't tll this it is running?

 

I do not think its running and all the AVG files are still alive and healthy.

 

Surely this is not a legitimate company the puts something on your computer at which point it locks you out of controlling the program.

 

Not sure what you call something like this - virus or malware or whatever but it certainly has itself well protected.


Edited by JayJax, 09 February 2013 - 10:08 PM.


#5 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,759 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:43 PM

Posted 09 February 2013 - 10:05 PM

It should open some interface.

 

If that doesn't work...

 

Revo Uninstaller is more thorough in deleting programs on your computer than using the Add/Remove option in Windows.  Since it is a more powerful tool, please be sure to follow the instructions carefully.

Please note there is a chance when you look for this program to uninstall through Revo it might not be listed because of the previous uninstall.  If that is the case simply stop and let me know.

  • Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on the program you want to remove
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • When the built-in uninstaller is finished click on Next
  • Once the program has searched for leftovers click Next.
  • Check the items in bold only on the list then click Delete.  You may have to expand some folders by clicking the "+" mark.
  • When prompted click on Yes and then on Next.
  • Put a check on any folders that are found and select Delete
  • When prompted select Yes then Next
  • Once done click Finish.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#6 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 10:17 PM

Thank you.  I did download the Revo Uninstaller - It did not detect any AVG files at all unless they are called something else?

 

How to decide if a file should be deleted when its not clear what it is, I can see the entire name but there are some files labeled MSXML 4.0.

 

The first report I ran showed AVG in the root directory.

 

Hope its okay if I post the results here:

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457  BrowserJavaVersion: 10.9.2
Run by AR at 20:41:15 on 2013-02-09
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3886.2310 [GMT -6:00]
.
AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\System32\alg.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Users\AR\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Windows\System32\msdtc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.yahoo.com?type=198484&fr=spigot-yhp-ie
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: IObit Apps Toolbar: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.8\iobitappsToolbarIE.dll
mWinlogon: Userinit = userinit.exe
BHO: IObit Apps Toolbar: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.8\iobitappsToolbarIE.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file>
TB: IObit Apps Toolbar: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\6.8\iobitappsToolbarIE.dll
uRun: [Advanced SystemCare 6] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
StartupFolder: C:\Users\AR\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\AR\AppData\Roaming\Dropbox\bin\Dropbox.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{74324FEE-6F27-4831-8FEA-74C3F519ECD6} : DHCPNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
SSODL: WebCheck - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com?type=198484&fr=spigot-yhp-ff
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npdf.dll
FF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npnitroie.dll
FF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll
FF - plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-12-17 00:42; giorgio@gilestro.tk; C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\extensions\giorgio@gilestro.tk.xpi
FF - ExtSQL: 2012-12-30 00:00; map@quickmaps.me; C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\extensions\map@quickmaps.me.xpi
FF - ExtSQL: 2012-12-30 00:02; artur.dubovoy@gmail.com; C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\extensions\artur.dubovoy@gmail.com.xpi
FF - ExtSQL: 2013-01-29 15:15; feca4b87-3be4-43da-a1b1-137c24220968@jetpack; C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi
FF - ExtSQL: 2013-02-02 19:44; {7443739c-bff6-4af0-aea5-7ed29006966c}; C:\Users\AR\AppData\Roaming\Mozilla\Firefox\Profiles\zwwuvgxv.default\extensions\{7443739c-bff6-4af0-aea5-7ed29006966c}
FF - ExtSQL: 2013-02-08 18:53; iobitapps@mybrowserbar.com; C:\Program Files (x86)\IObit Apps Toolbar\FF
FF - ExtSQL: 2013-02-08 18:53; wtxpcom@mybrowserbar.com; C:\Program Files (x86)\Common Files\Spigot\wtxpcom
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=download&ir=download&cd=2XzuyEtN2Y1L1QzuyEzzyD0DyCtDyCyDyDyByC0E0C0FtAtCtN0D0Tzu0CtAzztAtN1L2XzutBtFtBtFtCtFyEtDyB&cr=121090373
FF - user.js: extensions.funmoods.dfltSrch - true
FF - user.js: extensions.funmoods.srchPrvdr - Funmoods
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=download&ir=download&cd=2XzuyEtN2Y1L1QzuyEzzyD0DyCtDyCyDyDyByC0E0C0FtAtCtN0D0Tzu0CtAzztAtN1L2XzutBtFtBtFtCtFyEtDyB&cr=121090373
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=download&ir=download&cd=2XzuyEtN2Y1L1QzuyEzzyD0DyCtDyCyDyDyByC0E0C0FtAtCtN0D0Tzu0CtAzztAtN1L2XzutBtFtBtFtCtFyEtDyB&cr=121090373&q=
FF - user.js: extensions.funmoods.id - 485D6065576ECF31
FF - user.js: extensions.funmoods.instlDay - 15722
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2220:13:27
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - download
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - download
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-11-15 111968]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-11-12 30568]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2013-1-4 465216]
R2 Application Updater;Application Updater;C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2013-2-7 800120]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 128456]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 EUCR;EUCR;C:\Windows\System32\drivers\EUCR6SK.sys [2012-12-21 88912]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-9 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-9 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-19 1255736]
S4 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [2012-12-17 230416]
S4 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe --> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [?]
.
=============== File Associations ===============
.
FileExt: .txt: Jarte.txt="C:\Program Files (x86)\Jarte\Jarte.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2013-02-10 01:23:42    --------    d-----w-    C:\Users\AR\AppData\Roaming\Malwarebytes
2013-02-10 01:23:12    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-02-10 01:23:10    24176    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-02-10 01:23:10    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-10 01:22:41    --------    d-----w-    C:\Users\AR\AppData\Local\Programs
2013-02-09 18:07:01    9161176    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1989296E-8DF5-44F3-8B55-9979C2E672A1}\mpengine.dll
2013-02-09 00:56:41    --------    d-----w-    C:\Users\AR\AppData\Roaming\Wise Registry Cleaner
2013-02-09 00:54:14    --------    d-----w-    C:\Program Files (x86)\Wise
2013-02-09 00:52:59    --------    d-----w-    C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-02-09 00:52:57    --------    d-----w-    C:\Program Files (x86)\Application Updater
2013-02-09 00:52:55    --------    d-----w-    C:\Program Files (x86)\IObit Apps Toolbar
2013-02-09 00:52:55    --------    d-----w-    C:\Program Files (x86)\Common Files\Spigot
2013-02-08 03:04:44    9161176    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-06 19:09:48    --------    d-----w-    C:\ProgramData\Norton
2013-02-06 18:59:20    --------    d-----w-    C:\Users\AR\AppData\Roaming\Synaptics
2013-02-06 17:13:26    --------    d-----w-    C:\Users\AR\AppData\Local\Conduit
2013-02-06 17:08:24    --------    d-----w-    C:\Users\AR\AppData\Local\Coupon Companion Plugin
2013-01-28 06:34:16    --------    d-----w-    C:\Users\AR\AppData\Roaming\Kingsoft
2013-01-28 06:34:15    --------    d-----w-    C:\ProgramData\Kingsoft
2013-01-28 06:33:40    --------    d-----w-    C:\Program Files (x86)\Kingsoft
2013-01-22 23:59:01    25472    ----a-w-    C:\Windows\System32\RegistryDefragBootTime.exe
2013-01-20 16:41:40    --------    d-----w-    C:\Users\AR\.clipbak
2013-01-19 10:21:35    --------    d-----w-    C:\Program Files (x86)\MSXML 4.0
2013-01-19 10:19:04    800768    ----a-w-    C:\Windows\System32\usp10.dll
2013-01-19 10:19:04    626688    ----a-w-    C:\Windows\SysWow64\usp10.dll
2013-01-19 10:16:22    3149824    ----a-w-    C:\Windows\System32\win32k.sys
2013-01-18 02:13:34    --------    d-----w-    C:\Users\AR\AppData\Roaming\Funmoods
2013-01-18 02:12:38    639984    ----a-w-    C:\Users\AR\jarte-setup.exe
2013-01-18 02:04:33    --------    d-----w-    C:\Users\AR\BOOKS
2013-01-16 09:15:59    --------    d-----w-    C:\Users\AR\AppData\Roaming\PDFlite
2013-01-16 09:15:53    87040    ----a-w-    C:\Windows\System32\redmonnt.dll
2013-01-16 09:15:53    46080    ----a-w-    C:\Windows\System32\unredmon.exe
2013-01-16 09:15:50    --------    d-----w-    C:\Program Files (x86)\PDFlite
2013-01-16 06:08:45    --------    d-----w-    C:\Users\AR\AppData\Local\Thunderbird
2013-01-15 19:05:34    --------    d-----w-    C:\Program Files (x86)\Mozilla Maintenance Service
.
==================== Find3M  ====================
.
2013-01-30 10:53:22    273840    ------w-    C:\Windows\System32\MpSigStub.exe
2013-01-16 05:06:08    74248    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-16 05:06:08    697864    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2012-12-22 23:40:08    178728    ----a-w-    C:\Program Files (x86)\4zres.dll
2012-12-22 23:40:07    707728    ----a-w-    C:\Program Files (x86)\4zUninstall VideoDownloadConverter.dll
2012-12-17 20:15:34    29712    ----a-w-    C:\Windows\System32\nitrolocalmon2.dll
2012-12-17 20:15:34    17936    ----a-w-    C:\Windows\System32\nitrolocalui2.dll
2012-12-16 17:11:22    46080    ----a-w-    C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03    367616    ----a-w-    C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28    295424    ----a-w-    C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20    34304    ----a-w-    C:\Windows\SysWow64\atmlib.dll
2012-12-12 21:37:56    4472832    ----a-w-    C:\Windows\SysWow64\GPhotos.scr
2012-12-07 13:20:16    441856    ----a-w-    C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31    2746368    ----a-w-    C:\Windows\System32\gameux.dll
2012-12-07 12:26:17    308736    ----a-w-    C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43    2576384    ----a-w-    C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04    30720    ----a-w-    C:\Windows\System32\usk.rs
2012-12-07 11:20:03    43520    ----a-w-    C:\Windows\System32\csrr.rs
2012-12-07 11:20:03    23552    ----a-w-    C:\Windows\System32\oflc.rs
2012-12-07 11:20:01    45568    ----a-w-    C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01    44544    ----a-w-    C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01    20480    ----a-w-    C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00    20480    ----a-w-    C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59    20480    ----a-w-    C:\Windows\System32\pegi.rs
2012-12-07 11:19:58    46592    ----a-w-    C:\Windows\System32\fpb.rs
2012-12-07 11:19:57    40960    ----a-w-    C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57    21504    ----a-w-    C:\Windows\System32\grb.rs
2012-12-07 11:19:57    15360    ----a-w-    C:\Windows\System32\djctq.rs
2012-12-07 11:19:56    55296    ----a-w-    C:\Windows\System32\cero.rs
2012-12-07 11:19:55    51712    ----a-w-    C:\Windows\System32\esrb.rs
2012-11-30 05:45:35    362496    ----a-w-    C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35    243200    ----a-w-    C:\Windows\System32\wow64.dll
2012-11-30 05:45:35    13312    ----a-w-    C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14    215040    ----a-w-    C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12    16384    ----a-w-    C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07    424448    ----a-w-    C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59    274944    ----a-w-    C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48    338432    ----a-w-    C:\Windows\System32\conhost.exe
2012-11-30 02:44:06    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04    14336    ----a-w-    C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03    2048    ----a-w-    C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59    6144    ---ha-w-    C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59    4608    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59    3584    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59    3072    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-26 23:25:05    95208    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-26 23:25:02    821736    ----a-w-    C:\Windows\SysWow64\npDeployJava1.dll
2012-11-26 23:25:02    746984    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2012-11-23 03:13:57    68608    ----a-w-    C:\Windows\System32\taskhost.exe
2012-11-20 05:48:49    307200    ----a-w-    C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09    220160    ----a-w-    C:\Windows\SysWow64\ncrypt.dll
2012-11-16 05:33:24    111968    ----a-w-    C:\Windows\System32\drivers\avgmfx64.sys
2012-11-14 06:11:44    2312704    ----a-w-    C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11    1392128    ----a-w-    C:\Windows\System32\wininet.dll
2012-11-14 06:02:49    1494528    ----a-w-    C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46    599040    ----a-w-    C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35    173056    ----a-w-    C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40    2382848    ----a-w-    C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22    1800704    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15    1427968    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37    1129472    ----a-w-    C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25    142848    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27    420864    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42    2382848    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2012-11-12 16:14:52    30568    ----a-w-    C:\Windows\System32\drivers\avgtpx64.sys
.


Edited by JayJax, 09 February 2013 - 10:29 PM.


#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,759 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:43 PM

Posted 09 February 2013 - 10:19 PM

Do you see any AVG activity?


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#8 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 10:37 PM

Not sure what you mean by activity but I definitely resent something getting installed on my computer even though I did not approve it and now that it is there it has made it impossible to delete.

 

It's always running, according to the uninstall program I first tried to use which has a shred option.    It says the program must be closed but I can see no way of closing it since it prohibits me from changing it at all.



#9 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 09 February 2013 - 10:42 PM


Also, when I run the Windows Program which allows me to see running processes which enables me to stop them, it does not work, it keeps right on running with whatever it is doing.

 

i just saw a discussion on CNET with several people who took issue with AVG back in 2009.  I think it is irresponsible of CNET to review this as a good program and to mislead people.

 

As i said, I never even approved of the install, I cancelled out and it installed anyway.  I'm getting more angry about this the more I see.

 

It is apparently authentic AVG, but how in the world it has a reputation as one of the best when its virtually doing exactly what it is supposed to prevent.


Edited by JayJax, 09 February 2013 - 10:50 PM.


#10 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,759 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:43 PM

Posted 09 February 2013 - 10:49 PM

I'm confused.

What exactly it IT, which is running?


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#11 JayJax

JayJax
  • Topic Starter

  • Members
  • 723 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lee's Summit Missouri
  • Local time:05:43 PM

Posted 10 February 2013 - 12:59 PM

AVG was running and it was impossible to stop it.   The windows program that lets you decide what you want running and what not was unable to turn it off. 

 

It's not running anymore because I wiped out my hard drive but I sure as the heck will make a note of my experience and not go near that service/company again.   To put something on someone's hard drive and make it impossible to delete by any number of programs that should have worked is the sign of disreputable people.

 

I also noticed on the first report a bunch of stuff from "funmoods" which should have been deleted but parts of it remained.

 

Anyway, it/they are history.  I have this peculiar belief that since i bought the computer I should be able to add and remove programs at will.

 

Thanks for the links and attempts to help.   I did not like having to wipe out my hard drive and start over but it appeared the only choice.


Edited by JayJax, 10 February 2013 - 01:04 PM.


#12 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,759 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:43 PM

Posted 10 February 2013 - 01:21 PM

Good luck :)


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users