It appears you`re running two AV programmes, Mcafee and AVG. This is not recommended, will slow your system down and can cause serious conflicts.
Uninstall one AV programme ASAP. Personally I recommend you uninstall McAfee.
Download the McAfee removal tool below.
McAfee removal tool.
For instructions read the bottom two paragraphs
HERE.
Then, do the following.
You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.
Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how
HERE.
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how
HERE.
Go to add remove programmes in your control panel and uninstall anything to do with(
if there).
MyWaySA
SrchAsDe
Close control panel.
Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(
if there).
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKUS\S-1-5-18\..\RunOnce: [RealUpgradeHelper] "C:\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe" "RealNetworks|RealPlayer|6.0" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RealUpgradeHelper] "C:\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe" "RealNetworks|RealPlayer|6.0" (User 'Default user')
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O16 - DPF: ActiveGS.cab -
http://www.virtualapple.org/activegs.cab
O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) -
http://interact.ccsd.net/ClientDownloads/fcplugin.cab
O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
Click on the fix checked button.
Close HJT.
Locate and delete the following
bold files and/or directories(
if there).
C:\WINDOWS\Downloaded Program Files\
fcplugin.dll
C:\Program Files\
MyWaySA<Delete the entire folder.
Reboot into normal mode and rehide your protected OS files.
Post fresh HJT and Combofix logs.
Regards Howard
This thread is for the use of eldacheese only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.