Jump to content

zosodude13

Members
  • Posts

    19
  • Joined

  • Last visited

Posts posted by zosodude13

  1. Ok. It worked this time.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 3:06:17 PM, on 6/20/2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v8.00 (8.00.7601.17514)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe

    C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

    C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

    C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe

    C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\AVG Secure Search\vprot.exe

    C:\Program Files (x86)\AVG\AVG2012\avgtray.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe

    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll

    O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (file missing)

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (file missing)

    O3 - Toolbar: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll

    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

    O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"

    O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"

    O4 - HKLM\..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

    O4 - HKCU\..\Run: [Wisdom-soft ScreenHunter 5.1 Free] 0

    O4 - HKCU\..\Run: [Wisdom-soft ScreenHunter 5.1 Plus] 0

    O4 - HKCU\..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe

    O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL

    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe

    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe

    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: vToolbarUpdater11.1.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 12295 bytes

  2. Malwarebytes Anti-Malware 1.61.0.1400

    www.malwarebytes.org

    Database version: v2012.06.18.09

    Windows 7 Service Pack 1 x64 NTFS

    Internet Explorer 8.0.7601.17514

    Ben McCracken :: BEN_LAPTOP [administrator]

    6/20/2012 12:02:59 PM

    mbam-log-2012-06-20 (12-02-59).txt

    Scan type: Quick scan

    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

    Scan options disabled: P2P

    Objects scanned: 221179

    Time elapsed: 5 minute(s), 9 second(s)

    Memory Processes Detected: 0

    (No malicious items detected)

    Memory Modules Detected: 0

    (No malicious items detected)

    Registry Keys Detected: 0

    (No malicious items detected)

    Registry Values Detected: 0

    (No malicious items detected)

    Registry Data Items Detected: 0

    (No malicious items detected)

    Folders Detected: 0

    (No malicious items detected)

    Files Detected: 0

    (No malicious items detected)

    (end)

    ---------------------------------------

    Despite the suggestions you gave, Hijackthis will not finish the scan.

  3. This is the report:

    µTorrent

    3D Pinball

    Acoustica Effects Pack

    Acoustica Mixcraft 5

    Adobe AIR

    Adobe Flash Player 11 Plugin

    Adobe Reader X (10.1.3)

    Adobe Shockwave Player 11.6

    Advanced Audio FX Engine

    AIM 7

    AIM Toolbar

    Apple Application Support

    Apple Software Update

    Applian FLV and Media Player 3.1.1.12

    Audacity 1.3.12 (Unicode)

    Cisco EAP-FAST Module

    Cisco LEAP Module

    Cisco PEAP Module

    Compatibility Pack for the 2007 Office system

    Creeper World

    Creeper World Map Editor

    D3DX10

    DarkWave Studio 3.6.7

    Dell DataSafe Local Backup

    Dell DataSafe Local Backup - Support Software

    Dell Getting Started Guide

    Dell Webcam Central

    Download Updater (AOL LLC)

    ESET Online Scanner v3

    Firebird SQL Server - MAGIX Edition

    FLV Player

    GIMP 2.6.11

    Google Chrome

    Google Earth

    Google Update Helper

    GoToAssist 8.0.0.514

    IZArc 4.1.2

    J-Ball

    Java Auto Updater

    Java 6 Update 22

    Java 7 Update 2

    Junk Mail filter update

    Live! Cam Avatar Creator

    LogMeIn

    Malwarebytes Anti-Malware version 1.61.0.1400

    Microsoft Office 2000 Small Business

    Microsoft Office File Validation Add-In

    Microsoft Office PowerPoint 2003

    Microsoft Office PowerPoint Viewer 2007 (English)

    Microsoft Office Suite Activation Assistant

    Microsoft Search Enhancement Pack

    Microsoft SQL Server 2005 Compact Edition [ENU]

    Microsoft Visual C++ 2005 Redistributable

    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    Microsoft Works

    MixMeister BPM Analyzer 1.0

    Mozilla Firefox 13.0.1 (x86 en-US)

    Mozilla Maintenance Service

    MSVCRT

    MSVCRT_amd64

    PowerDVD DX

    QuickTime

    Risk II

    Roll

    Roxio Burn

    Roxio Update Manager

    Safari

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

    swMSM

    Text-To-Speech-Runtime

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

    uTorrentBar Toolbar

    Visual C++ 8.0 Runtime Setup Package (x64)

    Visual Studio 2008 x64 Redistributables

    Vuze_Remote Toolbar

    Warcraft III Reign of Chaos & The Frozen Throne

    Windows Live Communications Platform

    Windows Live Essentials

    Windows Live Installer

    Windows Live Mail

    Windows Live Messenger

    Windows Live Movie Maker

    Windows Live Photo Common

    Windows Live Photo Gallery

    Windows Live PIMT Platform

    Windows Live SOXE

    Windows Live SOXE Definitions

    Windows Live Sync

    Windows Live UX Platform

    Windows Live UX Platform Language Pack

    Windows Live Writer

    Windows Live Writer Resources

    Windows Movie Maker 2.6

  4. I haven't tried any searches yet, but everything else it normal on the laptop so far.

    This is the security check log:

    Results of screen317's Security Check version 0.99.42

    Windows 7 Service Pack 1 x64 (UAC is enabled)

    Internet Explorer 8 Out of date!

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Firewall Disabled!

    AVG Internet Security 2012

    Antivirus up to date!

    `````````Anti-malware/Other Utilities Check:`````````

    Malwarebytes Anti-Malware version 1.61.0.1400

    Java™ 6 Update 22

    Java™ 7 Update 2

    Java version out of Date!

    Adobe Reader X (10.1.3)

    Mozilla Firefox (13.0.1)

    Google Chrome 19.0.1084.52

    Google Chrome 19.0.1084.56

    ````````Process Check: objlist.exe by Laurent````````

    Malwarebytes Anti-Malware mbam.exe

    AVG avgwdsvc.exe

    AVG avgtray.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C: 10%

    ````````````````````End of Log``````````````````````

    ----------------------------------------------------

    And this is the combofix log. It was REALLY long, so I included it as an attachment:

    combofixlog.txt

  5. Hello everyone. I am having some problems with my laptop. If a do a search on google, I sometimes get redirected to pages that look like spam. I'm not great with computers and my son is out of town. I hope you can help me. :)

    I ran the DDS from the pinned topic. These were the results, I hope it helps.

    ----------------------------

    DDS (Ver_2011-08-26.01) - NTFSAMD64

    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.2.0

    Run by Ben McCracken at 21:23:22 on 2012-06-18

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3032.1642 [GMT -4:00]

    .

    AV: AVG Internet Security 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    SP: AVG Internet Security 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    FW: AVG Internet Security 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}

    .

    ============== Running Processes ===============

    .

    C:\PROGRA~2\AVG\AVG2012\avgrsa.exe

    C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe

    C:\Windows\system32\wininit.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Program Files\Dell\DellDock\DockLogin.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\system32\WLANExt.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

    C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files (x86)\AVG\AVG2012\avgfws.exe

    C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

    C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

    C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

    C:\Windows\system32\taskhost.exe

    C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe

    C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Program Files\IDT\WDM\sttray64.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

    C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

    C:\Program Files (x86)\AVG\AVG2012\avgtray.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files\Windows Media Player\wmpnetwk.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Windows\System32\svchost.exe -k LocalServicePeerNet

    C:\Windows\system32\DllHost.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe

    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe

    C:\Windows\system32\wuauclt.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Windows\system32\DllHost.exe

    C:\Windows\system32\DllHost.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\system32\conhost.exe

    C:\Windows\SysWOW64\cscript.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    .

    ============== Pseudo HJT Report ===============

    .

    uInternet Settings,ProxyServer = http=127.0.0.1:49354

    uInternet Settings,ProxyOverride = *.local

    uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    mURLSearchHooks: H - No File

    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll

    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll

    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

    uRun: [Wisdom-soft ScreenHunter 5.1 Free] 0

    uRun: [Wisdom-soft ScreenHunter 5.1 Plus] 0

    uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe

    mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

    mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

    mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"

    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll

    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL

    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

    DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab

    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3} : DhcpNameServer = 209.18.47.61 209.18.47.62

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\0527966716475602E4564777F627B6 : DhcpNameServer = 192.168.1.1

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\350796465627D616E6 : DhcpNameServer = 192.168.254.254

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\4414E4755424 : DhcpNameServer = 209.18.47.61 209.18.47.62

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\44255475D20534F5E4564777F627B6 : DhcpNameServer = 192.168.2.1

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\6627F6E64796562713732464 : DhcpNameServer = 192.168.254.254 192.168.254.254

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\B40216E64602B4 : DhcpNameServer = 209.18.47.61 209.18.47.62

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\E4544574541425 : DhcpNameServer = 192.168.1.1

    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO-X64: AcroIEHelperStub - No File

    BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll

    BHO-X64: AVG Do Not Track - No File

    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll

    BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

    BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    BHO-X64: Search Helper - No File

    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO-X64: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    BHO-X64: AIM Toolbar Loader - No File

    BHO-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    BHO-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    BHO-X64: uTorrentBar - No File

    BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

    TB-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    TB-X64: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    TB-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll

    TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

    mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

    mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

    mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"

    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath - C:\Users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\

    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)

    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll

    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll

    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll

    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll

    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll

    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]

    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]

    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

    R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?]

    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]

    R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]

    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]

    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]

    R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2012\avgfws.exe [2012-3-23 2321520]

    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-4-30 5106744]

    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 193288]

    R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]

    R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-8-27 1253376]

    R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-8 373640]

    R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-9-17 15928]

    R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]

    R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-11-15 658656]

    R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]

    R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]

    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]

    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]

    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-12 135664]

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-24 257224]

    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]

    S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-8-7 3276800]

    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-12 135664]

    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-6 129976]

    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

    .

    =============== Created Last 30 ================

    .

    2012-06-18 23:15:08 -------- d-sh--w- C:\$RECYCLE.BIN

    2012-06-18 22:55:27 2622464 ----a-w- C:\Windows\System32\wucltux.dll

    2012-06-18 22:54:59 99840 ----a-w- C:\Windows\System32\wudriver.dll

    2012-06-18 22:54:30 36864 ----a-w- C:\Windows\System32\wuapp.exe

    2012-06-18 22:54:30 186752 ----a-w- C:\Windows\System32\wuwebv.dll

    2012-06-18 22:52:23 98816 ----a-w- C:\Windows\sed.exe

    2012-06-18 22:52:23 518144 ----a-w- C:\Windows\SWREG.exe

    2012-06-18 22:52:23 256000 ----a-w- C:\Windows\PEV.exe

    2012-06-18 22:52:23 208896 ----a-w- C:\Windows\MBR.exe

    2012-06-18 22:50:52 -------- d-----w- C:\ComboFix

    2012-06-17 04:12:24 -------- d-----w- C:\Users\Ben McCracken\AppData\Local\Macromedia

    2012-06-14 02:59:59 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe

    2012-06-14 02:59:55 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

    2012-06-14 02:59:55 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

    2012-06-14 02:59:50 3146752 ----a-w- C:\Windows\System32\win32k.sys

    2012-06-14 02:59:46 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys

    2012-06-14 02:59:40 3216384 ----a-w- C:\Windows\System32\msi.dll

    2012-06-14 02:59:39 2342400 ----a-w- C:\Windows\SysWow64\msi.dll

    2012-06-14 02:59:30 1462272 ----a-w- C:\Windows\System32\crypt32.dll

    2012-06-14 02:59:28 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll

    2012-06-14 02:59:27 184320 ----a-w- C:\Windows\System32\cryptsvc.dll

    2012-06-14 02:59:27 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll

    2012-06-14 02:59:27 140288 ----a-w- C:\Windows\System32\cryptnet.dll

    2012-06-14 02:59:27 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll

    2012-05-25 03:11:25 8769696 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

    2012-05-25 02:47:30 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

    .

    ==================== Find3M ====================

    .

    2012-06-17 03:58:36 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-05-15 04:01:31 1188864 ----a-w- C:\Windows\System32\wininet.dll

    2012-05-15 03:03:54 981504 ----a-w- C:\Windows\SysWow64\wininet.dll

    2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll

    2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll

    2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll

    2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe

    2012-04-20 03:45:41 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

    2012-04-20 03:16:44 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

    2012-04-19 08:50:26 28480 ----a-w- C:\Windows\System32\drivers\avgidsha.sys

    2012-04-19 00:56:30 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx

    2012-04-19 00:56:30 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts

    2012-04-04 19:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

    2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys

    .

    ============= FINISH: 21:26:31.52 ===============

  6. Full scan for MBAM worked. These were the results.

    Malwarebytes' Anti-Malware 1.51.2.1300

    www.malwarebytes.org

    Database version: 7804

    Windows 6.1.7601 Service Pack 1

    Internet Explorer 8.0.7601.17514

    9/28/2011 10:21:45 AM

    mbam-log-2011-09-28 (10-21-45).txt

    Scan type: Full scan (C:\|D:\|)

    Objects scanned: 489311

    Time elapsed: 3 hour(s), 38 minute(s), 22 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 0

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 0

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    (No malicious items detected)

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    (No malicious items detected)

  7. Ok. So I ran MBAM full scan three times. Every single time, it crashes about half way through the scan. I've let it sit and it was the only thing running at the time. I'll try it one more time and see if it works. I tried the quick scan, and it worked just fine. These were the results:

    Malwarebytes' Anti-Malware 1.51.2.1300

    www.malwarebytes.org

    Database version: 7800

    Windows 6.1.7601 Service Pack 1

    Internet Explorer 8.0.7601.17514

    9/26/2011 11:23:27 AM

    mbam-log-2011-09-26 (11-23-27).txt

    Scan type: Quick scan

    Objects scanned: 191153

    Time elapsed: 3 minute(s), 46 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 0

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 0

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    (No malicious items detected)

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    (No malicious items detected)

    ---------------------

    I used the internet a little bit more today. No re-directs, no threats detected.

  8. Ok: I put Junction into C:\Windows. When I enter the command into run, the Junction window flashes and then disappears. I turned AVG off again, and it still did the same thing.

    So far, I haven't had any problems with threats or popups. But my internet usage has been limited just to be safe. Thank you for being so patient and such a big help so far. I TRULY appreciate it! :)

  9. I'm in a bit of a perfect storm type deal where I do not have access to a secure computer before tomorrow. However, I am only staying connected to the internet to check here and post.

    Here is the Combofix text:

    ----------------------

    ComboFix 11-09-24.04 - Ben McCracken 09/25/2011 14:44:28.1.2 - x64

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3032.983 [GMT -4:00]

    Running from: c:\users\Ben McCracken\Downloads\ComboFix.exe

    AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    * Created a new restore point

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\program files (x86)\AutocompletePro

    c:\program files (x86)\AutocompletePro\InstTracker.exe

    c:\program files (x86)\Search Toolbar

    c:\program files (x86)\Search Toolbar\SearchToolbar.dll

    c:\users\Ben McCracken\AppData\Local\Temp\658792545Wsy.dll

    c:\users\Ben McCracken\AppData\Roaming\3108.4F8

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{23d25d7a-7daa-45fa-9dab-8673c3e3a46b}

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{23d25d7a-7daa-45fa-9dab-8673c3e3a46b}\chrome.manifest

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{23d25d7a-7daa-45fa-9dab-8673c3e3a46b}\chrome\xulcache.jar

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{23d25d7a-7daa-45fa-9dab-8673c3e3a46b}\defaults\preferences\xulcache.js

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{23d25d7a-7daa-45fa-9dab-8673c3e3a46b}\install.rdf

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{60ff3786-194a-448a-94bd-14fac3c4b102}

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{60ff3786-194a-448a-94bd-14fac3c4b102}\chrome.manifest

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{60ff3786-194a-448a-94bd-14fac3c4b102}\chrome\xulcache.jar

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{60ff3786-194a-448a-94bd-14fac3c4b102}\defaults\preferences\xulcache.js

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{60ff3786-194a-448a-94bd-14fac3c4b102}\install.rdf

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{d4a4471a-7859-4a40-abc5-8d25f14c7c0e}

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{d4a4471a-7859-4a40-abc5-8d25f14c7c0e}\chrome.manifest

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{d4a4471a-7859-4a40-abc5-8d25f14c7c0e}\chrome\xulcache.jar

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{d4a4471a-7859-4a40-abc5-8d25f14c7c0e}\defaults\preferences\xulcache.js

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{d4a4471a-7859-4a40-abc5-8d25f14c7c0e}\install.rdf

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{e0b2a38c-336e-436a-bf90-9cae3582e006}

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{e0b2a38c-336e-436a-bf90-9cae3582e006}\chrome.manifest

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{e0b2a38c-336e-436a-bf90-9cae3582e006}\chrome\xulcache.jar

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{e0b2a38c-336e-436a-bf90-9cae3582e006}\defaults\preferences\xulcache.js

    c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{e0b2a38c-336e-436a-bf90-9cae3582e006}\install.rdf

    c:\users\Ben McCracken\Documents\~WRL0003.tmp

    c:\users\Ben McCracken\Documents\~WRL0544.tmp

    c:\users\Ben McCracken\Documents\~WRL0909.tmp

    c:\users\Ben McCracken\Documents\~WRL1798.tmp

    c:\users\Ben McCracken\Documents\~WRL2064.tmp

    c:\users\BENMCC~1\AppData\Local\Temp\658792545Wsy.dll

    c:\windows\system32\consrv.dll

    c:\windows\System64

    .

    .

    ((((((((((((((((((((((((( Files Created from 2011-08-25 to 2011-09-25 )))))))))))))))))))))))))))))))

    .

    .

    2011-09-25 19:03 . 2011-09-25 19:03 -------- d-----w- c:\users\Default\AppData\Local\temp

    2011-09-25 04:06 . 2011-09-25 04:06 -------- d-----w- c:\users\Ben McCracken\AppData\Local\ElevatedDiagnostics

    2011-09-25 00:54 . 2011-09-25 00:54 -------- d-----w- c:\programdata\PC Tools

    2011-09-24 21:40 . 2011-09-24 21:40 -------- d-----w- c:\windows\Sun

    2011-09-23 17:02 . 2011-09-23 17:05 -------- d-----w- c:\program files (x86)\Warcraft III Reign of Chaos & The Frozen Throne

    2011-09-12 01:03 . 2011-09-12 01:03 -------- d-----w- c:\users\Ben McCracken\AppData\Roaming\DarkWave Studio

    2011-09-12 00:58 . 2011-09-12 00:58 -------- d-----w- c:\program files (x86)\ExperimentalScene

    2011-08-31 17:06 . 2011-08-31 17:06 -------- d-----w- c:\users\Ben McCracken\AppData\Roaming\MAGIX

    2011-08-31 17:03 . 2011-09-02 05:52 -------- d-----w- c:\programdata\MAGIX

    2011-08-31 17:03 . 2011-09-02 05:48 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services

    2011-08-28 05:50 . 2011-08-28 05:51 -------- d-----w- c:\program files\iTunes

    2011-08-28 05:50 . 2011-08-28 05:50 -------- d-----w- c:\program files\iPod

    .

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2011-09-24 22:17 . 2011-05-29 00:40 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2011-07-22 05:22 . 2011-08-09 23:03 1638912 ----a-w- c:\windows\system32\mshtml.tlb

    2011-07-22 04:54 . 2011-08-09 23:03 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb

    2011-07-16 05:41 . 2011-08-09 23:04 362496 ----a-w- c:\windows\system32\wow64win.dll

    2011-07-16 05:41 . 2011-08-09 23:04 243200 ----a-w- c:\windows\system32\wow64.dll

    2011-07-16 05:41 . 2011-08-09 23:04 13312 ----a-w- c:\windows\system32\wow64cpu.dll

    2011-07-16 05:39 . 2011-08-09 23:04 16384 ----a-w- c:\windows\system32\ntvdm64.dll

    2011-07-16 05:37 . 2011-08-09 23:04 421888 ----a-w- c:\windows\system32\KernelBase.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll

    2011-07-16 05:21 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll

    2011-07-16 04:29 . 2011-08-09 23:04 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

    2011-07-16 04:26 . 2011-08-09 23:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll

    2011-07-16 04:25 . 2011-08-09 23:04 25600 ----a-w- c:\windows\SysWow64\setup16.exe

    2011-07-16 04:24 . 2011-08-09 23:04 5120 ----a-w- c:\windows\SysWow64\wow32.dll

    2011-07-16 04:24 . 2011-08-09 23:04 272384 ----a-w- c:\windows\SysWow64\KernelBase.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll

    2011-07-16 04:15 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll

    2011-07-16 02:21 . 2011-08-09 23:04 7680 ----a-w- c:\windows\SysWow64\instnm.exe

    2011-07-16 02:21 . 2011-08-09 23:04 2048 ----a-w- c:\windows\SysWow64\user.exe

    2011-07-16 02:17 . 2011-08-09 23:04 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

    2011-07-16 02:17 . 2011-08-09 23:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

    2011-07-16 02:17 . 2011-08-09 23:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

    2011-07-16 02:17 . 2011-08-09 23:04 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

    2011-07-12 15:34 . 2011-07-12 15:34 96104 ----a-w- c:\windows\system32\dns-sd.exe

    2011-07-12 15:34 . 2011-07-12 15:34 85864 ----a-w- c:\windows\system32\dnssd.dll

    2011-07-12 15:34 . 2011-07-12 15:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll

    2011-07-12 15:34 . 2011-07-12 15:34 212840 ----a-w- c:\windows\system32\dnssdX.dll

    2011-07-12 15:20 . 2011-07-12 15:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe

    2011-07-12 15:20 . 2011-07-12 15:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll

    2011-07-12 15:20 . 2011-07-12 15:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll

    2011-07-12 15:20 . 2011-07-12 15:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll

    2011-07-09 05:26 . 2011-08-24 23:30 2048 ----a-w- c:\windows\system32\tzres.dll

    2011-07-09 04:29 . 2011-08-24 23:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll

    2011-07-09 02:46 . 2011-08-09 23:04 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys

    2011-07-05 22:37 . 2011-07-05 22:37 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

    2011-07-05 22:37 . 2011-07-05 22:37 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

    "{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\tbVuze.dll" [2009-12-31 2349080]

    .

    [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

    .

    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

    2011-03-18 12:11 2471240 ----a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    .

    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

    2009-12-31 16:53 2349080 ----a-w- c:\program files (x86)\Vuze_Remote\tbVuze.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-03-18 2471240]

    "{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\tbVuze.dll" [2009-12-31 2349080]

    .

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    .

    [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Wisdom-soft ScreenHunter 5.1 Free"="0" [X]

    "Wisdom-soft ScreenHunter 5.1 Plus"="0" [X]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

    "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]

    "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]

    "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064]

    "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]

    "AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]

    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]

    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-19 421736]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]

    "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-09-24 560128]

    .

    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

    "mixer"=wdmaud.drv

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    @="Driver"

    .

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-12 135664]

    R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-03-18 947528]

    R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]

    R3 dc3d;MS Hardware Device Detection Driver (HID);c:\windows\system32\DRIVERS\dc3d.sys [x]

    R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]

    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-12 135664]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

    S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]

    S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]

    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

    S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]

    S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]

    S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

    S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-08-18 7390560]

    S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]

    S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]

    S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]

    S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-08 373640]

    S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]

    S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-03-04 658656]

    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]

    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]

    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]

    .

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-12 05:27]

    .

    2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-12 05:27]

    .

    .

    --------- x86-64 -----------

    .

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 384296]

    "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-30 165912]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-30 385560]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-30 365080]

    "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]

    "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2009-07-02 3180624]

    "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]

    "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-09-17 57928]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    "LoadAppInit_DLLs"=0x1

    .

    ------- Supplementary Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uInternet Settings,ProxyServer = http=127.0.0.1:49354

    uInternet Settings,ProxyOverride = *.local

    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    FF - ProfilePath - c:\users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\

    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-Locked - (no file)

    Wow6432Node-HKLM-Run-DellSupportCenter - c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe

    SafeBoot-mcmscsvc

    SafeBoot-MCODS

    Toolbar-Locked - (no file)

    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

    AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

    .

    .

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_USERS\S-1-5-21-4031671661-1594054384-3898363525-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

    @Denied: (2) (LocalSystem)

    "Progid"="WindowsLiveMail.Email.1"

    .

    [HKEY_USERS\S-1-5-21-4031671661-1594054384-3898363525-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

    @Denied: (2) (LocalSystem)

    "Progid"="WindowsLiveMail.VCard.1"

    .

    [HKEY_USERS\S-1-5-21-4031671661-1594054384-3898363525-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Ü*z**%\OpenWithList]

    @Class="Shell"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.10"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker4"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    ------------------------ Other Running Processes ------------------------

    .

    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    c:\program files (x86)\Bonjour\mDNSResponder.exe

    c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    c:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    .

    **************************************************************************

    .

    Completion time: 2011-09-25 15:16:00 - machine was rebooted

    ComboFix-quarantined-files.txt 2011-09-25 19:15

    .

    Pre-Run: 17,160,491,008 bytes free

    Post-Run: 21,888,512,000 bytes free

    .

    - - End Of File - - 5B73A80BEF2A1DC3EE23BDE523364208

    I never had those windows for Microsoft Recovery Console pop up. Does that mean it's already installed on my machine?

  10. Thank you for the help, Elise!

    Here are the results:

    .

    DDS (Ver_2011-08-26.01) - NTFSAMD64

    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_22

    Run by Ben McCracken at 12:09:11 on 2011-09-25

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3032.1390 [GMT -4:00]

    .

    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    ============== Running Processes ===============

    .

    C:\PROGRA~2\AVG\AVG10\avgchsva.exe

    C:\Windows\system32\wininit.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Program Files\Dell\DellDock\DockLogin.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

    C:\Windows\system32\WLANExt.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

    C:\Program Files (x86)\Bonjour\mDNSResponder.exe

    C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

    C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

    C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

    C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

    C:\Program Files (x86)\AVG\AVG10\avgnsa.exe

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

    C:\Windows\System32\rundll32.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Program Files\IDT\WDM\sttray64.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files\Dell\QuickSet\quickset.exe

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

    C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe

    C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

    C:\Program Files (x86)\AVG\AVG10\avgtray.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Windows\SysWOW64\rundll32.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\Windows Media Player\wmpnetwk.exe

    C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Windows\System32\svchost.exe -k LocalServicePeerNet

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\Windows\system32\wuauclt.exe

    C:\PROGRA~2\AVG\AVG10\avgrsa.exe

    C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe

    C:\Program Files (x86)\iTunes\iTunes.exe

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

    C:\Windows\system32\conhost.exe

    C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

    C:\Windows\system32\conhost.exe

    C:\Windows\system32\msiexec.exe

    C:\Windows\servicing\TrustedInstaller.exe

    C:\Windows\SysWOW64\ping.exe

    C:\Windows\system32\conhost.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\system32\conhost.exe

    C:\Windows\SysWOW64\cscript.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    .

    ============== Pseudo HJT Report ===============

    .

    uInternet Settings,ProxyServer = http=127.0.0.1:49354

    uInternet Settings,ProxyOverride = *.local

    uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    mWinlogon: Userinit=userinit.exe

    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File

    BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File

    TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

    uRun: [sysinfo] C:\Windows\system32\rundll32.exe C:\Users\BENMCC~1\AppData\Local\Temp\658792545Wsy.dll,Sets

    uRun: [Wisdom-soft ScreenHunter 5.1 Free] 0

    uRun: [Wisdom-soft ScreenHunter 5.1 Plus] 0

    mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

    mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

    mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

    mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

    mRunOnce: [sTToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe

    mPolicies-explorer: NoActiveDesktop = 1 (0x1)

    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL

    LSP: mswsock.dll

    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

    TCP: DhcpNameServer = 192.168.1.1

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3} : DhcpNameServer = 192.168.1.1

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\44255475D20534F5E4564777F627B6 : DhcpNameServer = 192.168.2.1

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\444424 : DhcpNameServer = 209.18.47.61 209.18.47.62

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\6627F6E64796562713732464 : DhcpNameServer = 192.168.254.254 192.168.254.254

    TCP: Interfaces\{2B92D360-4A27-4D74-ACF5-1344FDD043E3}\B40216E64602B4 : DhcpNameServer = 209.18.47.61 209.18.47.62

    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4

    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO-X64: AcroIEHelperStub - No File

    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

    BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

    BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    BHO-X64: Search Helper - No File

    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File

    BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    BHO-X64: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    BHO-X64: AIM Toolbar Loader - No File

    BHO-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll

    TB-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    TB-X64: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll

    TB-X64: {9D425283-D487-4337-BAB6-AB8354A81457} - No File

    TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

    mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

    mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

    mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

    mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

    mRunOnce-x64: [sTToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath - C:\Users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\

    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)

    FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll

    FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll

    FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll

    FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll

    FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll

    FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll

    FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll

    FF - component: C:\Users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll

    FF - component: C:\Users\Ben McCracken\AppData\Roaming\Mozilla\Firefox\Profiles\w8wm8eoq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll

    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll

    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll

    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll

    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll

    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]

    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]

    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]

    R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]

    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]

    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-8-18 7390560]

    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]

    R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]

    R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-8-27 1253376]

    R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-9-17 15928]

    R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]

    R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]

    R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]

    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]

    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

    S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-4-10 947528]

    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]

    S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-8-7 3276800]

    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

    .

    =============== Created Last 30 ================

    .

    2011-09-25 04:06:49 -------- d-----w- C:\Users\Ben McCracken\AppData\Local\ElevatedDiagnostics

    2011-09-25 00:54:20 -------- d-----w- C:\ProgramData\PC Tools

    2011-09-24 19:47:57 -------- d-----we C:\Windows\system64

    2011-09-23 17:02:13 -------- d-----w- C:\Program Files (x86)\Warcraft III Reign of Chaos & The Frozen Throne

    2011-09-12 01:03:45 -------- d-----w- C:\Users\Ben McCracken\AppData\Roaming\DarkWave Studio

    2011-09-12 00:58:00 -------- d-----w- C:\Program Files (x86)\ExperimentalScene

    2011-08-31 17:06:18 -------- d-----w- C:\Users\Ben McCracken\AppData\Roaming\MAGIX

    2011-08-31 17:03:49 -------- d-----w- C:\ProgramData\MAGIX

    2011-08-31 17:03:47 -------- d-----w- C:\Program Files (x86)\Common Files\MAGIX Services

    2011-08-28 05:50:51 -------- d-----w- C:\Program Files\iTunes

    2011-08-28 05:50:51 -------- d-----w- C:\Program Files\iPod

    .

    ==================== Find3M ====================

    .

    2011-09-24 22:17:35 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll

    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll

    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll

    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll

    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe

    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

    2011-07-12 15:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe

    2011-07-12 15:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll

    2011-07-12 15:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll

    2011-07-12 15:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll

    2011-07-12 15:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

    2011-07-12 15:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

    2011-07-12 15:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll

    2011-07-12 15:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll

    2011-07-09 05:26:20 2048 ----a-w- C:\Windows\System32\tzres.dll

    2011-07-09 04:29:46 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys

    2011-07-05 22:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx

    2011-07-05 22:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts

    .

    ============= FINISH: 12:13:48.21 ===============

    And this is file I was told to attach:

    Attach.zip

  11. I'm running Windows 7 x64 bit. I've had the virus for about a week. I did my research and I'm pretty sure I have the TDL3 rootkit. For it was just annoying and I did deleted some temporary internet files and it went away for about a day,and then it started up again. Today, my firewall will not turn on and my AVG keeps detecting threats, but cannot move them to the vault. So, I need some help ASAP.

    I'm not very good with the technical aspect of computers, so I could use the help.

    Thanks!

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.