Jump to content

Gomeo redirection virus- continued


dfs
 Share

Recommended Posts

Hi Forum,

I have followed the instructions (very well written BTW) and hope now that someone would be kind enough to read through the log and attached files below so I can finally be rid of this Gomeo affliction!!!!

Many thanks

DDS (Ver_10-12-12.02) - NTFS_AMD64

Run by Dave at 19:48:19.80 on 23/02/2011

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3999.2161 [GMT 0:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}

============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskhost.exe

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\PLFSetI.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Launch Manager\dsiwmis.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Acer\Registration\GregHSRW.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe

C:\Program Files (x86)\AVG\AVG10\avgnsa.exe

C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe

C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Acer\Acer Updater\UpdaterService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Launch Manager\LManager.exe

C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\AVG\AVG10\avgtray.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\igfxext.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\PROGRA~2\AVG\AVG10\avgrsa.exe

C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe

C:\Windows\SysWOW64\NOTEPAD.EXE

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Users\Dave\Downloads\dds.scr

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig

uSearch Bar = Preserve

mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

uInternet Settings,ProxyOverride = *.local

mWinlogon: Userinit=userinit.exe,

BHO: 968e912a: {01f0eb39-d41c-22c3-3361-e89284d2ad3d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {05aa6de2-aab0-9a41-210a-45609e620ce0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {072262e1-1b17-9d2a-8f46-2d41dbfe7076} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0a0a268e-a5f4-bfb7-db1e-08d6eaaa227f} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0bb05c92-cba4-6caf-a888-5fe3f2e1e9c3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {11d85875-bbab-92e4-7c92-c3062ba17b6d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: 968e912a: {1f3c55ee-d9df-a8ea-ceab-d40c7868b278} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {1fab249b-f355-c68f-ac47-bef336b7878d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {28f24b82-7973-9ca4-bbf7-6ad1c80bbc6e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2a4acff4-b943-2d4a-6edd-27f2461d52f8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2dd9babd-054d-4d43-1092-5a0723d6530d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3bcdf770-6e8e-f430-fc9d-80b4ed772d39} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3c5d37ab-b99c-8518-958e-955b6951d15b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

BHO: 968e912a: {3cac861c-57f0-e58c-5f0f-96692408100d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4a52745e-23dc-2c05-8198-bb0832f2ab88} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e017b42-a27c-4d52-e766-374a2e15d79c} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e38e399-aeb7-dda4-d634-ac3e8dbd4227} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {52e7ea7d-2d56-fef1-3b01-278089e16f3b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {543f6def-6c26-8f97-eee8-e5a108f205c5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {604ce7f6-4c8a-14f7-8e1b-3887d6a7a645} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68aa5918-ac4e-780b-c880-102aa8381ab2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68e6fa04-0e01-86ce-63ed-5d95445e0fb0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {6cc82fa9-4464-b8fc-0ce9-765362ac1bdb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

BHO: 968e912a: {6fb0f356-cf41-da8a-58c1-481b5d985587} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {71604fac-4ce3-6cc5-b5cb-a6eff9dc24a8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO: 968e912a: {795026d0-63a3-efdd-2954-b88ff5358fe3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {80548c5f-b624-13b2-a1d6-cc9cc27cfed5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8622be47-ccdb-e6df-4249-8f9a1833cf20} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8a4286f0-ff6d-7744-0e26-f535977d5811} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8f4874a1-2162-49b1-95a4-10b8ebfc36f4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8fb83466-d655-b8ca-fcb2-fb116f2293d2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: 968e912a: {91a0f813-6032-da57-488a-cdd96a0ecc7e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {94bf2316-f749-8b37-8331-1594c3a270b5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {96df3f31-2ade-8d8b-4749-5ec2e20c9cb4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {974e0edf-4354-ab30-25e5-48a8a05b71c9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {976f7f6c-75ec-1d72-e13b-73685fe63fd6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {97857535-508f-3a83-14b4-bd9cff03dc54} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {99fe6a35-c1f6-3e6b-82ef-a57d3c9f40eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9b328dc8-cec3-2919-913b-8be07e82d3f6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9dad7119-3f96-5fb7-e8bd-21bf38c36dff} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9f04f58b-7f65-f05e-9ba4-dfe0b6d50389} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: 968e912a: {a521da05-7bfd-dfdb-569b-4396ab727de9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: 968e912a: {ab49d6e8-6b04-0510-2aa4-a7b9e4310e94} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {add8c1b1-b70f-2509-cc59-dacdc1eb0fa9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll

BHO: 968e912a: {afe4e744-3cbb-7af8-80b9-60e3a37bd78b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {aff8ddcc-e9a4-265d-9072-22fbe0553ba8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b19ebe5e-1052-6365-659f-9f435d2cd83b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b26fe1b4-bf8e-d9d2-753b-0a69571b1876} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: 968e912a: {c7da786b-57b4-5751-9653-6158418a56eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {c9fa9486-3249-52aa-1bae-9c8e77abb655} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {d15806a8-930d-b6be-5513-74324a3c2ac2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

BHO: 968e912a: {da0dfc3d-33a1-aa78-425f-09f79adf34b8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: 968e912a: {dc6580af-7371-3b1e-f546-c71818f1cb42} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {ee79840b-1044-7371-ad2c-546161db2e61} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f3ae5066-83fd-d072-250f-03bdbb6ccc08} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f4403d5c-a596-de07-4f4a-df3ebca33753} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f82e7aa0-b0d9-672b-9a78-e926b17e3957} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll

TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe

mRun: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [backupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k

mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED

mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"

mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [NPSStartup]

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun: [Nike+ Connect] "C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [plawow.exe] c:\windows\plawow.exe

mRun: [iaswow.exe] c:\windows\iaswow.exe

mRun: [werwow.exe] c:\windows\werwow.exe

mRun: [authfwwizfwkwow.exe] c:\windows\authfwwizfwkwow.exe

mRun: [apisetschemawow.exe] c:\windows\apisetschemawow.exe

mRun: [wfhcwow.exe] c:\windows\wfhcwow.exe

mRun: [nciwow.exe] c:\windows\nciwow.exe

mRun: [clbwow.exe] c:\windows\clbwow.exe

mRun: [dmrcwow.exe] c:\windows\dmrcwow.exe

mRun: [evrwow.exe] c:\windows\evrwow.exe

mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACERVC~1.LNK - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

AppInit_DLLs: C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll

BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [iAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe

mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

mRun-x64: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe

mRun-x64: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun-x64: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

mRun-x64: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe

mRun-x64: [igfxTray] C:\Windows\system32\igfxtray.exe

mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe

mRun-x64: [PLFSetL] C:\Windows\\PLFSetL.exe

mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe

mRun-x64: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig

FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll

FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll

FF - component: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com

FF - Ext: XUL Cache: {ea99277b-8ca0-462a-aa62-110c24995993} - %profile%\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}

FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]

R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]

R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-2-20 69376]

R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304]

R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]

R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032]

R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576]

R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016]

R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]

R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]

R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]

R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-9-4 107016]

R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-9-4 787968]

R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-6-4 1150496]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-2-18 1405384]

R2 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-8-6 311592]

R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-8-21 62720]

R2 RS_Service;Raw Socket Service;C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-9-4 253952]

R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-9-4 240160]

R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-3 157264]

R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-3 35920]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2009-9-4 138752]

R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-9-4 58880]

R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-2-18 17152]

R3 NETw1v64;Intel® Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw1v64.sys [2009-9-4 7058432]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-9 136176]

S2 Power32;Power ;c:\windows\system32\winbrand32.exe --> c:\windows\system32\winbrand32.exe [?]

S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-10-22 48488]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]

S3 hitmanpro35;Hitman Pro 3.5 Support Driver;C:\Windows\System32\drivers\hitmanpro35.sys [2011-2-14 19528]

S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]

S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2009-9-4 5435904]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-9-4 215552]

S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2010-12-5 16448]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-14 1255736]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

=============== Created Last 30 ================

2011-02-20 22:45:49 -------- d-----w- C:\PROGRA~3\STOPzilla!

2011-02-20 22:36:46 -------- d-----w- C:\PROGRA~3\AWEM

2011-02-20 13:08:21 16432 ----a-w- C:\Windows\System32\lsdelete.exe

2011-02-20 10:25:26 69376 ----a-w- C:\Windows\System32\drivers\Lbd.sys

2011-02-20 10:25:23 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys

2011-02-20 10:23:17 -------- d-----w- C:\Users\Dave\AppData\Local\Sunbelt Software

2011-02-20 10:22:39 -------- dc-h--w- C:\PROGRA~3\{3D8A16C3-37D5-4543-A6B3-D545F952AD73}

2011-02-20 10:22:17 -------- d-----w- C:\Program Files (x86)\Lavasoft

2011-02-19 21:46:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\Malwarebytes

2011-02-19 21:45:08 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

2011-02-19 21:45:08 -------- d-----w- C:\PROGRA~3\Malwarebytes

2011-02-19 21:45:05 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-02-19 21:45:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-02-19 11:26:18 -------- d--h--w- C:\$AVG

2011-02-19 11:24:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\AVG10

2011-02-19 11:22:31 -------- d--h--w- C:\PROGRA~3\Common Files

2011-02-19 11:22:20 -------- d-----w- C:\Windows\SysWow64\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\Windows\System32\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\PROGRA~3\AVG10

2011-02-19 11:20:51 -------- d-----w- C:\Program Files (x86)\AVG

2011-02-19 10:59:27 -------- d-----w- C:\PROGRA~3\MFAData

2011-02-18 07:18:28 7844688 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{AF5EEE2D-23D2-4562-9732-CF54BE1FB0FF}\mpengine.dll

2011-02-14 17:54:33 19528 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys

2011-02-14 16:31:58 -------- d-----w- C:\PROGRA~3\Hitman Pro

2011-02-10 08:14:59 97280 ----a-w- C:\Windows\System32\wscsvc.dll

2011-02-04 08:42:39 181608 ----a-w- C:\PROGRA~3\Microsoft\Windows\Sqm\Manifest\Sqm10137.bin

2011-02-02 14:06:06 -------- d-----w- C:\Users\Dave\AppData\Roaming\SUPERAntiSpyware.com

2011-02-02 14:06:06 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com

2011-02-02 14:05:26 -------- d-----w- C:\PROGRA~3\!SASCORE

2011-02-02 14:05:23 -------- d-----w- C:\Program Files\SUPERAntiSpyware

2011-02-01 20:41:47 -------- d-sh--w- C:\PROGRA~3\SysWoW32

2011-02-01 20:41:32 203776 --sh--w- C:\PROGRA~3\unrar.exe

2011-02-01 20:41:27 -------- d-sh--w- C:\PROGRA~3\A62BD338E38D783414C503FF194910D4

2011-02-01 20:00:13 -------- d-----w- C:\Users\Dave\AppData\Roaming\FrostWire

2011-02-01 19:59:15 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-02-01 19:59:15 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

2011-01-26 16:22:37 -------- d-----w- C:\Program Files (x86)\Nike

2011-01-26 16:22:37 -------- d-----w- C:\PROGRA~3\Nike

==================== Find3M ====================

2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll

2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll

2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll

2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll

2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll

2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll

2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys

2010-12-21 06:16:27 62976 ----a-w- C:\Windows\System32\wscapi.dll

2010-12-21 06:16:16 214016 ----a-w- C:\Windows\System32\winsrv.dll

2010-12-21 06:16:14 442880 ----a-w- C:\Windows\System32\winhttp.dll

2010-12-21 06:16:14 1197056 ----a-w- C:\Windows\System32\wininet.dll

2010-12-21 06:16:09 258048 ----a-w- C:\Windows\System32\WebClnt.dll

2010-12-21 06:15:55 264192 ----a-w- C:\Windows\System32\upnp.dll

2010-12-21 06:15:31 15360 ----a-w- C:\Windows\System32\slwga.dll

2010-12-21 06:13:03 2003968 ----a-w- C:\Windows\System32\msxml6.dll

2010-12-21 06:13:03 1880576 ----a-w- C:\Windows\System32\msxml3.dll

2010-12-21 06:10:22 100864 ----a-w- C:\Windows\System32\davclnt.dll

2010-12-21 05:38:24 51200 ----a-w- C:\Windows\SysWow64\wscapi.dll

2010-12-21 05:38:22 981504 ----a-w- C:\Windows\SysWow64\wininet.dll

2010-12-21 05:38:22 350720 ----a-w- C:\Windows\SysWow64\winhttp.dll

2010-12-21 05:38:21 204800 ----a-w- C:\Windows\SysWow64\WebClnt.dll

2010-12-21 05:38:19 204288 ----a-w- C:\Windows\SysWow64\upnp.dll

2010-12-21 05:38:16 14336 ----a-w- C:\Windows\SysWow64\slwga.dll

2010-12-21 05:36:17 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll

2010-12-21 05:36:16 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll

2010-12-21 05:34:12 80384 ----a-w- C:\Windows\SysWow64\davclnt.dll

2010-12-18 06:11:41 57856 ----a-w- C:\Windows\System32\licmgr10.dll

2010-12-18 06:11:34 714752 ----a-w- C:\Windows\System32\kerberos.dll

2010-12-18 05:29:40 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll

2010-12-18 05:29:31 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll

2010-12-18 04:55:03 482816 ----a-w- C:\Windows\System32\html.iec

2010-12-18 04:20:55 386048 ----a-w- C:\Windows\SysWow64\html.iec

2010-12-18 04:13:40 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

2010-12-18 03:47:59 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2010-12-08 04:12:36 308304 ----a-w- C:\Windows\System32\drivers\avgldx64.sys

2010-11-29 17:38:30 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx

2010-11-29 17:38:30 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts

============= FINISH: 19:49:15.38 ===============

Attach.zip

Link to post
Share on other sites

Hello dfs! Welcome to Malwarebytes' Anti-Malware Forums!

My name is Borislav and I will be glad to help you solve your problems with malware. Before we begin, please note the following:

  • The process of cleaning your system may take some time, so please be patient.
  • Follow my instructions step by step if there is a problem somewhere, stop and tell me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • If you don't know or can't understand something please ask.
  • Do not install or uninstall any software or hardware, while work on.
  • Keep me informed about any changes.
  • Post all of your log files, don't attach them.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be [bAF0-Skip, choose it.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • Click the Report button and copy/paste the contents of it into your next reply.

Note:It will also create a log in the C:\ directory.

In your next reply, please post these log(s):

  1. TDSSKiller log
  2. a new fresh DDS log only

Link to post
Share on other sites

2011/02/23 22:20:47.0816 2152 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08

2011/02/23 22:20:48.0138 2152 ================================================================================

2011/02/23 22:20:48.0138 2152 SystemInfo:

2011/02/23 22:20:48.0138 2152

2011/02/23 22:20:48.0139 2152 OS Version: 6.1.7600 ServicePack: 0.0

2011/02/23 22:20:48.0139 2152 Product type: Workstation

2011/02/23 22:20:48.0139 2152 ComputerName: DAVE-PC

2011/02/23 22:20:48.0139 2152 UserName: Dave

2011/02/23 22:20:48.0139 2152 Windows directory: C:\Windows

2011/02/23 22:20:48.0139 2152 System windows directory: C:\Windows

2011/02/23 22:20:48.0139 2152 Running under WOW64

2011/02/23 22:20:48.0139 2152 Processor architecture: Intel x64

2011/02/23 22:20:48.0139 2152 Number of processors: 2

2011/02/23 22:20:48.0139 2152 Page size: 0x1000

2011/02/23 22:20:48.0139 2152 Boot type: Normal boot

2011/02/23 22:20:48.0139 2152 ================================================================================

2011/02/23 22:20:48.0578 2152 Initialize success

2011/02/23 22:21:02.0059 1596 ================================================================================

2011/02/23 22:21:02.0059 1596 Scan started

2011/02/23 22:21:02.0059 1596 Mode: Manual;

2011/02/23 22:21:02.0059 1596 ================================================================================

2011/02/23 22:21:02.0646 1596 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys

2011/02/23 22:21:02.0702 1596 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys

2011/02/23 22:21:02.0754 1596 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys

2011/02/23 22:21:02.0829 1596 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys

2011/02/23 22:21:02.0960 1596 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys

2011/02/23 22:21:03.0078 1596 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys

2011/02/23 22:21:03.0172 1596 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys

2011/02/23 22:21:03.0222 1596 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys

2011/02/23 22:21:03.0318 1596 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys

2011/02/23 22:21:03.0391 1596 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys

2011/02/23 22:21:03.0423 1596 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys

2011/02/23 22:21:03.0455 1596 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys

2011/02/23 22:21:03.0495 1596 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys

2011/02/23 22:21:03.0544 1596 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys

2011/02/23 22:21:03.0597 1596 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys

2011/02/23 22:21:03.0649 1596 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys

2011/02/23 22:21:03.0772 1596 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys

2011/02/23 22:21:03.0822 1596 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys

2011/02/23 22:21:03.0881 1596 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys

2011/02/23 22:21:03.0935 1596 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys

2011/02/23 22:21:04.0141 1596 AVGIDSDriver (0f562e8bcf79facdfb58a5b3b95e5cfe) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys

2011/02/23 22:21:04.0288 1596 AVGIDSEH (656366fd0c0e2481a89196fb3d1be49a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys

2011/02/23 22:21:04.0339 1596 AVGIDSFilter (fdf9f596316bc1bc10726ece268a0237) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys

2011/02/23 22:21:04.0504 1596 Avgldx64 (91be0147bc27059aba6d0a478adeb1ee) C:\Windows\system32\DRIVERS\avgldx64.sys

2011/02/23 22:21:04.0693 1596 Avgmfx64 (f5ffa3053d26c55edc112e66197eed09) C:\Windows\system32\DRIVERS\avgmfx64.sys

2011/02/23 22:21:04.0839 1596 Avgrkx64 (5b3f127b26c08b1c7df5c5f111ca4030) C:\Windows\system32\DRIVERS\avgrkx64.sys

2011/02/23 22:21:04.0957 1596 Avgtdia (9140455490a9298f5a43500f1c886afe) C:\Windows\system32\DRIVERS\avgtdia.sys

2011/02/23 22:21:05.0111 1596 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys

2011/02/23 22:21:05.0171 1596 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys

2011/02/23 22:21:05.0246 1596 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys

2011/02/23 22:21:05.0328 1596 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys

2011/02/23 22:21:05.0422 1596 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys

2011/02/23 22:21:05.0474 1596 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys

2011/02/23 22:21:05.0502 1596 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys

2011/02/23 22:21:05.0555 1596 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys

2011/02/23 22:21:05.0613 1596 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys

2011/02/23 22:21:05.0654 1596 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys

2011/02/23 22:21:05.0684 1596 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys

2011/02/23 22:21:05.0735 1596 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys

2011/02/23 22:21:05.0804 1596 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys

2011/02/23 22:21:05.0857 1596 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys

2011/02/23 22:21:05.0975 1596 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys

2011/02/23 22:21:06.0045 1596 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys

2011/02/23 22:21:06.0196 1596 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys

2011/02/23 22:21:06.0228 1596 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys

2011/02/23 22:21:06.0270 1596 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys

2011/02/23 22:21:06.0345 1596 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys

2011/02/23 22:21:06.0431 1596 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys

2011/02/23 22:21:06.0655 1596 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys

2011/02/23 22:21:06.0796 1596 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys

2011/02/23 22:21:06.0865 1596 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys

2011/02/23 22:21:06.0918 1596 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys

2011/02/23 22:21:07.0030 1596 DKbFltr (d5bcb77be83cf99f508943945d46343d) C:\Windows\SysWOW64\Drivers\DKbFltr.sys

2011/02/23 22:21:07.0169 1596 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys

2011/02/23 22:21:07.0327 1596 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys

2011/02/23 22:21:07.0513 1596 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys

2011/02/23 22:21:07.0698 1596 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys

2011/02/23 22:21:07.0785 1596 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys

2011/02/23 22:21:07.0902 1596 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys

2011/02/23 22:21:07.0951 1596 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys

2011/02/23 22:21:08.0011 1596 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys

2011/02/23 22:21:08.0129 1596 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys

2011/02/23 22:21:08.0164 1596 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys

2011/02/23 22:21:08.0198 1596 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys

2011/02/23 22:21:08.0260 1596 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys

2011/02/23 22:21:08.0354 1596 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys

2011/02/23 22:21:08.0448 1596 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys

2011/02/23 22:21:08.0524 1596 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys

2011/02/23 22:21:08.0596 1596 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys

2011/02/23 22:21:08.0641 1596 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys

2011/02/23 22:21:08.0710 1596 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys

2011/02/23 22:21:08.0865 1596 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys

2011/02/23 22:21:08.0923 1596 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys

2011/02/23 22:21:08.0960 1596 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys

2011/02/23 22:21:09.0001 1596 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys

2011/02/23 22:21:09.0066 1596 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys

2011/02/23 22:21:09.0133 1596 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys

2011/02/23 22:21:09.0200 1596 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys

2011/02/23 22:21:09.0338 1596 hitmanpro35 (5cd53fc677705cc5e402611c81b2ac41) C:\Windows\system32\drivers\hitmanpro35.sys

2011/02/23 22:21:09.0413 1596 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys

2011/02/23 22:21:09.0485 1596 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys

2011/02/23 22:21:09.0543 1596 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys

2011/02/23 22:21:09.0590 1596 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys

2011/02/23 22:21:09.0666 1596 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys

2011/02/23 22:21:09.0730 1596 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys

2011/02/23 22:21:10.0007 1596 igfx (dfeaf0a1d98d397035012c8e28d1520f) C:\Windows\system32\DRIVERS\igdkmd64.sys

2011/02/23 22:21:10.0282 1596 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys

2011/02/23 22:21:10.0429 1596 IntcAzAudAddService (d8bce8176cb1084c6f5830c019d47166) C:\Windows\system32\drivers\RTKVHD64.sys

2011/02/23 22:21:10.0626 1596 IntcHdmiAddService (d485d3bd3e2179aa86853a182f70699f) C:\Windows\system32\drivers\IntcHdmi.sys

2011/02/23 22:21:10.0678 1596 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys

2011/02/23 22:21:10.0738 1596 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys

2011/02/23 22:21:10.0794 1596 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys

2011/02/23 22:21:10.0850 1596 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys

2011/02/23 22:21:10.0885 1596 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys

2011/02/23 22:21:11.0013 1596 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys

2011/02/23 22:21:11.0047 1596 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys

2011/02/23 22:21:11.0108 1596 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys

2011/02/23 22:21:11.0252 1596 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys

2011/02/23 22:21:11.0328 1596 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys

2011/02/23 22:21:11.0373 1596 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys

2011/02/23 22:21:11.0417 1596 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys

2011/02/23 22:21:11.0449 1596 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys

2011/02/23 22:21:11.0608 1596 L1C (2377ec4cc3e356655b996f39b43486b6) C:\Windows\system32\DRIVERS\L1C62x64.sys

2011/02/23 22:21:11.0795 1596 Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys

2011/02/23 22:21:11.0916 1596 Lbd (c8b3131857931ae76798a741cc52b021) C:\Windows\system32\DRIVERS\Lbd.sys

2011/02/23 22:21:12.0011 1596 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys

2011/02/23 22:21:12.0119 1596 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys

2011/02/23 22:21:12.0164 1596 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys

2011/02/23 22:21:12.0205 1596 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys

2011/02/23 22:21:12.0247 1596 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys

2011/02/23 22:21:12.0300 1596 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys

2011/02/23 22:21:12.0436 1596 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys

2011/02/23 22:21:12.0478 1596 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys

2011/02/23 22:21:12.0541 1596 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys

2011/02/23 22:21:12.0588 1596 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys

2011/02/23 22:21:12.0630 1596 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys

2011/02/23 22:21:12.0733 1596 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys

2011/02/23 22:21:12.0774 1596 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys

2011/02/23 22:21:12.0813 1596 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys

2011/02/23 22:21:12.0849 1596 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys

2011/02/23 22:21:12.0902 1596 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys

2011/02/23 22:21:12.0948 1596 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys

2011/02/23 22:21:12.0989 1596 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys

2011/02/23 22:21:13.0029 1596 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys

2011/02/23 22:21:13.0092 1596 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys

2011/02/23 22:21:13.0123 1596 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys

2011/02/23 22:21:13.0187 1596 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys

2011/02/23 22:21:13.0225 1596 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys

2011/02/23 22:21:13.0261 1596 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys

2011/02/23 22:21:13.0327 1596 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys

2011/02/23 22:21:13.0372 1596 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys

2011/02/23 22:21:13.0404 1596 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys

2011/02/23 22:21:13.0448 1596 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys

2011/02/23 22:21:13.0498 1596 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys

2011/02/23 22:21:13.0542 1596 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys

2011/02/23 22:21:13.0577 1596 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys

2011/02/23 22:21:13.0627 1596 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys

2011/02/23 22:21:13.0668 1596 mwlPSDFilter (6ffecc25b39dc7652a0cec0ada9db589) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys

2011/02/23 22:21:13.0708 1596 mwlPSDNServ (0befe32ca56d6ee89d58175725596a85) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys

2011/02/23 22:21:13.0753 1596 mwlPSDVDisk (d43bc633b8660463e446e28e14a51262) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys

2011/02/23 22:21:13.0823 1596 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys

2011/02/23 22:21:13.0905 1596 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys

2011/02/23 22:21:13.0980 1596 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys

2011/02/23 22:21:14.0031 1596 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys

2011/02/23 22:21:14.0069 1596 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys

2011/02/23 22:21:14.0130 1596 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys

2011/02/23 22:21:14.0169 1596 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys

2011/02/23 22:21:14.0217 1596 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys

2011/02/23 22:21:14.0254 1596 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys

2011/02/23 22:21:14.0535 1596 NETw1v64 (e72f4522801ffb8f0456924fb0017bff) C:\Windows\system32\DRIVERS\NETw1v64.sys

2011/02/23 22:21:14.0944 1596 netw5v64 (705283c02177809ca9fa7cc58a4f1e77) C:\Windows\system32\DRIVERS\netw5v64.sys

2011/02/23 22:21:15.0130 1596 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys

2011/02/23 22:21:15.0182 1596 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys

2011/02/23 22:21:15.0241 1596 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys

2011/02/23 22:21:15.0333 1596 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys

2011/02/23 22:21:15.0436 1596 NTIDrvr (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys

2011/02/23 22:21:15.0472 1596 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys

2011/02/23 22:21:15.0537 1596 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys

2011/02/23 22:21:15.0581 1596 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys

2011/02/23 22:21:15.0620 1596 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys

2011/02/23 22:21:15.0664 1596 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys

2011/02/23 22:21:15.0764 1596 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys

2011/02/23 22:21:15.0806 1596 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys

2011/02/23 22:21:15.0853 1596 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys

2011/02/23 22:21:15.0890 1596 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys

2011/02/23 22:21:15.0945 1596 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys

2011/02/23 22:21:15.0988 1596 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys

2011/02/23 22:21:16.0041 1596 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys

2011/02/23 22:21:16.0284 1596 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys

2011/02/23 22:21:16.0322 1596 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys

2011/02/23 22:21:16.0384 1596 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys

2011/02/23 22:21:16.0460 1596 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys

2011/02/23 22:21:16.0549 1596 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys

2011/02/23 22:21:16.0594 1596 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys

2011/02/23 22:21:16.0639 1596 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys

2011/02/23 22:21:16.0682 1596 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys

2011/02/23 22:21:16.0740 1596 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys

2011/02/23 22:21:16.0789 1596 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys

2011/02/23 22:21:16.0869 1596 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys

2011/02/23 22:21:16.0917 1596 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys

2011/02/23 22:21:16.0972 1596 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys

2011/02/23 22:21:17.0003 1596 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys

2011/02/23 22:21:17.0040 1596 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys

2011/02/23 22:21:17.0170 1596 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys

2011/02/23 22:21:17.0203 1596 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys

2011/02/23 22:21:17.0258 1596 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys

2011/02/23 22:21:17.0359 1596 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys

2011/02/23 22:21:17.0494 1596 RSUSBSTOR (4a25dc970c58104602ed274dacafd784) C:\Windows\system32\Drivers\RtsUStor.sys

2011/02/23 22:21:17.0629 1596 SASDIFSV (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS

2011/02/23 22:21:17.0663 1596 SASKUTIL (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS

2011/02/23 22:21:17.0756 1596 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys

2011/02/23 22:21:17.0796 1596 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys

2011/02/23 22:21:17.0917 1596 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys

2011/02/23 22:21:17.0992 1596 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys

2011/02/23 22:21:18.0074 1596 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys

2011/02/23 22:21:18.0105 1596 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys

2011/02/23 22:21:18.0171 1596 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys

2011/02/23 22:21:18.0197 1596 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys

2011/02/23 22:21:18.0235 1596 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys

2011/02/23 22:21:18.0269 1596 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys

2011/02/23 22:21:18.0320 1596 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys

2011/02/23 22:21:18.0353 1596 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys

2011/02/23 22:21:18.0393 1596 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys

2011/02/23 22:21:18.0487 1596 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys

2011/02/23 22:21:18.0664 1596 sptd (602884696850c86434530790b110e8eb) C:\Windows\System32\Drivers\sptd.sys

2011/02/23 22:21:18.0762 1596 srv (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys

2011/02/23 22:21:18.0827 1596 srv2 (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys

2011/02/23 22:21:18.0875 1596 srvnet (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys

2011/02/23 22:21:18.0945 1596 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys

2011/02/23 22:21:18.0988 1596 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys

2011/02/23 22:21:19.0058 1596 SynTP (bcf305959b53b200ceb2ad25ad22f8a7) C:\Windows\system32\DRIVERS\SynTP.sys

2011/02/23 22:21:19.0217 1596 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys

2011/02/23 22:21:19.0405 1596 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys

2011/02/23 22:21:19.0469 1596 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys

2011/02/23 22:21:19.0515 1596 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys

2011/02/23 22:21:19.0550 1596 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys

2011/02/23 22:21:19.0589 1596 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys

2011/02/23 22:21:19.0622 1596 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys

2011/02/23 22:21:19.0808 1596 TFsExDisk (48d9d00c2e0e72c3d4f52772c80355f6) C:\Windows\System32\Drivers\TFsExDisk.sys

2011/02/23 22:21:19.0942 1596 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys

2011/02/23 22:21:19.0991 1596 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys

2011/02/23 22:21:20.0034 1596 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys

2011/02/23 22:21:20.0069 1596 UBHelper (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys

2011/02/23 22:21:20.0107 1596 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys

2011/02/23 22:21:20.0175 1596 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys

2011/02/23 22:21:20.0223 1596 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys

2011/02/23 22:21:20.0257 1596 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys

2011/02/23 22:21:20.0347 1596 USBAAPL64 (f724b03c3dfaacf08d17d38bf3333583) C:\Windows\system32\Drivers\usbaapl64.sys

2011/02/23 22:21:20.0483 1596 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys

2011/02/23 22:21:20.0524 1596 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys

2011/02/23 22:21:20.0587 1596 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys

2011/02/23 22:21:20.0625 1596 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys

2011/02/23 22:21:20.0671 1596 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys

2011/02/23 22:21:20.0706 1596 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys

2011/02/23 22:21:20.0747 1596 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys

2011/02/23 22:21:20.0797 1596 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS

2011/02/23 22:21:20.0826 1596 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys

2011/02/23 22:21:20.0888 1596 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys

2011/02/23 22:21:20.0950 1596 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys

2011/02/23 22:21:21.0025 1596 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys

2011/02/23 22:21:21.0071 1596 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys

2011/02/23 22:21:21.0099 1596 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys

2011/02/23 22:21:21.0151 1596 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys

2011/02/23 22:21:21.0191 1596 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys

2011/02/23 22:21:21.0233 1596 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys

2011/02/23 22:21:21.0272 1596 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys

2011/02/23 22:21:21.0310 1596 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys

2011/02/23 22:21:21.0364 1596 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys

2011/02/23 22:21:21.0411 1596 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys

2011/02/23 22:21:21.0486 1596 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys

2011/02/23 22:21:21.0534 1596 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys

2011/02/23 22:21:21.0562 1596 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys

2011/02/23 22:21:21.0651 1596 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys

2011/02/23 22:21:21.0704 1596 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys

2011/02/23 22:21:21.0835 1596 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys

2011/02/23 22:21:21.0869 1596 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys

2011/02/23 22:21:22.0032 1596 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys

2011/02/23 22:21:22.0109 1596 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys

2011/02/23 22:21:22.0180 1596 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys

2011/02/23 22:21:22.0247 1596 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys

2011/02/23 22:21:22.0298 1596 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys

2011/02/23 22:21:22.0418 1596 ================================================================================

2011/02/23 22:21:22.0418 1596 Scan finished

2011/02/23 22:21:22.0418 1596 ================================================================================

DDS (Ver_10-12-12.02) - NTFS_AMD64

Run by Dave at 22:23:57.36 on 23/02/2011

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3999.2065 [GMT 0:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}

============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskhost.exe

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\PLFSetI.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Launch Manager\dsiwmis.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Acer\Registration\GregHSRW.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe

C:\Program Files (x86)\AVG\AVG10\avgnsa.exe

C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe

C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Acer\Acer Updater\UpdaterService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Launch Manager\LManager.exe

C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\AVG\AVG10\avgtray.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\igfxext.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\PROGRA~2\AVG\AVG10\avgrsa.exe

C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe

C:\Windows\SysWOW64\NOTEPAD.EXE

C:\Windows\system32\DllHost.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Users\Dave\Desktop\TDSSKiller.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Users\Dave\Downloads\dds(2).scr

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig

uSearch Bar = Preserve

mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

uInternet Settings,ProxyOverride = *.local

mWinlogon: Userinit=userinit.exe,

BHO: 968e912a: {01f0eb39-d41c-22c3-3361-e89284d2ad3d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {05aa6de2-aab0-9a41-210a-45609e620ce0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {072262e1-1b17-9d2a-8f46-2d41dbfe7076} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0a0a268e-a5f4-bfb7-db1e-08d6eaaa227f} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0bb05c92-cba4-6caf-a888-5fe3f2e1e9c3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {11d85875-bbab-92e4-7c92-c3062ba17b6d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: 968e912a: {1f3c55ee-d9df-a8ea-ceab-d40c7868b278} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {1fab249b-f355-c68f-ac47-bef336b7878d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {28f24b82-7973-9ca4-bbf7-6ad1c80bbc6e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2a4acff4-b943-2d4a-6edd-27f2461d52f8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2dd9babd-054d-4d43-1092-5a0723d6530d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3bcdf770-6e8e-f430-fc9d-80b4ed772d39} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3c5d37ab-b99c-8518-958e-955b6951d15b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

BHO: 968e912a: {3cac861c-57f0-e58c-5f0f-96692408100d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4a52745e-23dc-2c05-8198-bb0832f2ab88} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e017b42-a27c-4d52-e766-374a2e15d79c} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e38e399-aeb7-dda4-d634-ac3e8dbd4227} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {52e7ea7d-2d56-fef1-3b01-278089e16f3b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {543f6def-6c26-8f97-eee8-e5a108f205c5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {604ce7f6-4c8a-14f7-8e1b-3887d6a7a645} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68aa5918-ac4e-780b-c880-102aa8381ab2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68e6fa04-0e01-86ce-63ed-5d95445e0fb0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {6cc82fa9-4464-b8fc-0ce9-765362ac1bdb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

BHO: 968e912a: {6fb0f356-cf41-da8a-58c1-481b5d985587} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {71604fac-4ce3-6cc5-b5cb-a6eff9dc24a8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO: 968e912a: {795026d0-63a3-efdd-2954-b88ff5358fe3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {80548c5f-b624-13b2-a1d6-cc9cc27cfed5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8622be47-ccdb-e6df-4249-8f9a1833cf20} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8a4286f0-ff6d-7744-0e26-f535977d5811} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8f4874a1-2162-49b1-95a4-10b8ebfc36f4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8fb83466-d655-b8ca-fcb2-fb116f2293d2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: 968e912a: {91a0f813-6032-da57-488a-cdd96a0ecc7e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {94bf2316-f749-8b37-8331-1594c3a270b5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {96df3f31-2ade-8d8b-4749-5ec2e20c9cb4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {974e0edf-4354-ab30-25e5-48a8a05b71c9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {976f7f6c-75ec-1d72-e13b-73685fe63fd6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {97857535-508f-3a83-14b4-bd9cff03dc54} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {99fe6a35-c1f6-3e6b-82ef-a57d3c9f40eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9b328dc8-cec3-2919-913b-8be07e82d3f6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9dad7119-3f96-5fb7-e8bd-21bf38c36dff} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9f04f58b-7f65-f05e-9ba4-dfe0b6d50389} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: 968e912a: {a521da05-7bfd-dfdb-569b-4396ab727de9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: 968e912a: {ab49d6e8-6b04-0510-2aa4-a7b9e4310e94} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {add8c1b1-b70f-2509-cc59-dacdc1eb0fa9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll

BHO: 968e912a: {afe4e744-3cbb-7af8-80b9-60e3a37bd78b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {aff8ddcc-e9a4-265d-9072-22fbe0553ba8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b19ebe5e-1052-6365-659f-9f435d2cd83b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b26fe1b4-bf8e-d9d2-753b-0a69571b1876} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: 968e912a: {c7da786b-57b4-5751-9653-6158418a56eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {c9fa9486-3249-52aa-1bae-9c8e77abb655} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {d15806a8-930d-b6be-5513-74324a3c2ac2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

BHO: 968e912a: {da0dfc3d-33a1-aa78-425f-09f79adf34b8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: 968e912a: {dc6580af-7371-3b1e-f546-c71818f1cb42} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {ee79840b-1044-7371-ad2c-546161db2e61} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f3ae5066-83fd-d072-250f-03bdbb6ccc08} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f4403d5c-a596-de07-4f4a-df3ebca33753} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f82e7aa0-b0d9-672b-9a78-e926b17e3957} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll

TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe

mRun: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [backupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k

mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED

mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"

mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [NPSStartup]

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun: [Nike+ Connect] "C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [plawow.exe] c:\windows\plawow.exe

mRun: [iaswow.exe] c:\windows\iaswow.exe

mRun: [werwow.exe] c:\windows\werwow.exe

mRun: [authfwwizfwkwow.exe] c:\windows\authfwwizfwkwow.exe

mRun: [apisetschemawow.exe] c:\windows\apisetschemawow.exe

mRun: [wfhcwow.exe] c:\windows\wfhcwow.exe

mRun: [nciwow.exe] c:\windows\nciwow.exe

mRun: [clbwow.exe] c:\windows\clbwow.exe

mRun: [dmrcwow.exe] c:\windows\dmrcwow.exe

mRun: [evrwow.exe] c:\windows\evrwow.exe

mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACERVC~1.LNK - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

AppInit_DLLs: C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll

BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [iAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe

mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

mRun-x64: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe

mRun-x64: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun-x64: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

mRun-x64: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe

mRun-x64: [igfxTray] C:\Windows\system32\igfxtray.exe

mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe

mRun-x64: [PLFSetL] C:\Windows\\PLFSetL.exe

mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe

mRun-x64: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig

FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll

FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll

FF - component: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com

FF - Ext: XUL Cache: {ea99277b-8ca0-462a-aa62-110c24995993} - %profile%\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}

FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]

R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]

R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-2-20 69376]

R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304]

R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]

R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032]

R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576]

R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016]

R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]

R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]

R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]

R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-9-4 107016]

R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-9-4 787968]

R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-6-4 1150496]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-2-18 1405384]

R2 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-8-6 311592]

R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-8-21 62720]

R2 RS_Service;Raw Socket Service;C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-9-4 253952]

R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-9-4 240160]

R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-3 157264]

R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-3 35920]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2009-9-4 138752]

R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-9-4 58880]

R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-2-18 17152]

R3 NETw1v64;Intel® Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw1v64.sys [2009-9-4 7058432]

R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-9 136176]

S2 Power32;Power ;c:\windows\system32\winbrand32.exe --> c:\windows\system32\winbrand32.exe [?]

S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-10-22 48488]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]

S3 hitmanpro35;Hitman Pro 3.5 Support Driver;C:\Windows\System32\drivers\hitmanpro35.sys [2011-2-14 19528]

S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]

S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2009-9-4 5435904]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-9-4 215552]

S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2010-12-5 16448]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-14 1255736]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

=============== Created Last 30 ================

2011-02-20 22:45:49 -------- d-----w- C:\PROGRA~3\STOPzilla!

2011-02-20 22:36:46 -------- d-----w- C:\PROGRA~3\AWEM

2011-02-20 13:08:21 16432 ----a-w- C:\Windows\System32\lsdelete.exe

2011-02-20 10:25:26 69376 ----a-w- C:\Windows\System32\drivers\Lbd.sys

2011-02-20 10:25:23 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys

2011-02-20 10:23:17 -------- d-----w- C:\Users\Dave\AppData\Local\Sunbelt Software

2011-02-20 10:22:39 -------- dc-h--w- C:\PROGRA~3\{3D8A16C3-37D5-4543-A6B3-D545F952AD73}

2011-02-20 10:22:17 -------- d-----w- C:\Program Files (x86)\Lavasoft

2011-02-19 21:46:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\Malwarebytes

2011-02-19 21:45:08 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

2011-02-19 21:45:08 -------- d-----w- C:\PROGRA~3\Malwarebytes

2011-02-19 21:45:05 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-02-19 21:45:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-02-19 11:26:18 -------- d--h--w- C:\$AVG

2011-02-19 11:24:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\AVG10

2011-02-19 11:22:31 -------- d--h--w- C:\PROGRA~3\Common Files

2011-02-19 11:22:20 -------- d-----w- C:\Windows\SysWow64\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\Windows\System32\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\PROGRA~3\AVG10

2011-02-19 11:20:51 -------- d-----w- C:\Program Files (x86)\AVG

2011-02-19 10:59:27 -------- d-----w- C:\PROGRA~3\MFAData

2011-02-18 07:18:28 7844688 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{AF5EEE2D-23D2-4562-9732-CF54BE1FB0FF}\mpengine.dll

2011-02-14 17:54:33 19528 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys

2011-02-14 16:31:58 -------- d-----w- C:\PROGRA~3\Hitman Pro

2011-02-10 08:14:59 97280 ----a-w- C:\Windows\System32\wscsvc.dll

2011-02-04 08:42:39 181608 ----a-w- C:\PROGRA~3\Microsoft\Windows\Sqm\Manifest\Sqm10137.bin

2011-02-02 14:06:06 -------- d-----w- C:\Users\Dave\AppData\Roaming\SUPERAntiSpyware.com

2011-02-02 14:06:06 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com

2011-02-02 14:05:26 -------- d-----w- C:\PROGRA~3\!SASCORE

2011-02-02 14:05:23 -------- d-----w- C:\Program Files\SUPERAntiSpyware

2011-02-01 20:41:47 -------- d-sh--w- C:\PROGRA~3\SysWoW32

2011-02-01 20:41:32 203776 --sh--w- C:\PROGRA~3\unrar.exe

2011-02-01 20:41:27 -------- d-sh--w- C:\PROGRA~3\A62BD338E38D783414C503FF194910D4

2011-02-01 20:00:13 -------- d-----w- C:\Users\Dave\AppData\Roaming\FrostWire

2011-02-01 19:59:15 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-02-01 19:59:15 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

2011-01-26 16:22:37 -------- d-----w- C:\Program Files (x86)\Nike

2011-01-26 16:22:37 -------- d-----w- C:\PROGRA~3\Nike

==================== Find3M ====================

2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll

2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll

2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll

2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll

2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll

2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll

2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys

2010-12-21 06:16:27 62976 ----a-w- C:\Windows\System32\wscapi.dll

2010-12-21 06:16:16 214016 ----a-w- C:\Windows\System32\winsrv.dll

2010-12-21 06:16:14 442880 ----a-w- C:\Windows\System32\winhttp.dll

2010-12-21 06:16:14 1197056 ----a-w- C:\Windows\System32\wininet.dll

2010-12-21 06:16:09 258048 ----a-w- C:\Windows\System32\WebClnt.dll

2010-12-21 06:15:55 264192 ----a-w- C:\Windows\System32\upnp.dll

2010-12-21 06:15:31 15360 ----a-w- C:\Windows\System32\slwga.dll

2010-12-21 06:13:03 2003968 ----a-w- C:\Windows\System32\msxml6.dll

2010-12-21 06:13:03 1880576 ----a-w- C:\Windows\System32\msxml3.dll

2010-12-21 06:10:22 100864 ----a-w- C:\Windows\System32\davclnt.dll

2010-12-21 05:38:24 51200 ----a-w- C:\Windows\SysWow64\wscapi.dll

2010-12-21 05:38:22 981504 ----a-w- C:\Windows\SysWow64\wininet.dll

2010-12-21 05:38:22 350720 ----a-w- C:\Windows\SysWow64\winhttp.dll

2010-12-21 05:38:21 204800 ----a-w- C:\Windows\SysWow64\WebClnt.dll

2010-12-21 05:38:19 204288 ----a-w- C:\Windows\SysWow64\upnp.dll

2010-12-21 05:38:16 14336 ----a-w- C:\Windows\SysWow64\slwga.dll

2010-12-21 05:36:17 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll

2010-12-21 05:36:16 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll

2010-12-21 05:34:12 80384 ----a-w- C:\Windows\SysWow64\davclnt.dll

2010-12-18 06:11:41 57856 ----a-w- C:\Windows\System32\licmgr10.dll

2010-12-18 06:11:34 714752 ----a-w- C:\Windows\System32\kerberos.dll

2010-12-18 05:29:40 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll

2010-12-18 05:29:31 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll

2010-12-18 04:55:03 482816 ----a-w- C:\Windows\System32\html.iec

2010-12-18 04:20:55 386048 ----a-w- C:\Windows\SysWow64\html.iec

2010-12-18 04:13:40 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

2010-12-18 03:47:59 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2010-12-08 04:12:36 308304 ----a-w- C:\Windows\System32\drivers\avgldx64.sys

2010-11-29 17:38:30 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx

2010-11-29 17:38:30 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts

============= FINISH: 22:24:45.79 ===============

Link to post
Share on other sites

Thanks!

Step 1

Please, uninstall the following applications:

  1. McAfee Security Scan Plus

You can read, how to do this here:

Step 2

You should not have more than one anti-virus program installed as they will conflict and cause problems. You have two so you need to uninstall one of them. Of the two, I would recommend keeping AVG, so please uninstall Ad-Aware.

Step 3

  • Launch Malwarebytes' Anti-Malware
  • Go to Update" tab and select Check for Updates.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

In your next reply, please post these log(s):

  1. Malwarebytes' Anti-Malware log
  2. a new fresh DDS log only

Link to post
Share on other sites

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 5857

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

23/02/2011 22:58:19

mbam-log-2011-02-23 (22-58-19).txt

Scan type: Quick scan

Objects scanned: 164223

Time elapsed: 3 minute(s), 8 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

DDS (Ver_10-12-12.02) - NTFS_AMD64

Run by Dave at 22:59:17.48 on 23/02/2011

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3999.2006 [GMT 0:00]

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskhost.exe

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\PLFSetI.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Launch Manager\dsiwmis.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Acer\Registration\GregHSRW.exe

C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe

C:\Program Files (x86)\AVG\AVG10\avgnsa.exe

C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe

C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Acer\Acer Updater\UpdaterService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Launch Manager\LManager.exe

C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe

C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\AVG\AVG10\avgtray.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\igfxext.exe

C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\PROGRA~2\AVG\AVG10\avgrsa.exe

C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe

C:\Windows\SysWOW64\NOTEPAD.EXE

C:\Windows\system32\DllHost.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\msiexec.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Users\Dave\Downloads\dds(2).scr

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig

uSearch Bar = Preserve

mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

uInternet Settings,ProxyOverride = *.local

mWinlogon: Userinit=userinit.exe,

BHO: 968e912a: {01f0eb39-d41c-22c3-3361-e89284d2ad3d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {05aa6de2-aab0-9a41-210a-45609e620ce0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {072262e1-1b17-9d2a-8f46-2d41dbfe7076} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0a0a268e-a5f4-bfb7-db1e-08d6eaaa227f} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {0bb05c92-cba4-6caf-a888-5fe3f2e1e9c3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {11d85875-bbab-92e4-7c92-c3062ba17b6d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: 968e912a: {1f3c55ee-d9df-a8ea-ceab-d40c7868b278} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {1fab249b-f355-c68f-ac47-bef336b7878d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {28f24b82-7973-9ca4-bbf7-6ad1c80bbc6e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2a4acff4-b943-2d4a-6edd-27f2461d52f8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {2dd9babd-054d-4d43-1092-5a0723d6530d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3bcdf770-6e8e-f430-fc9d-80b4ed772d39} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {3c5d37ab-b99c-8518-958e-955b6951d15b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

BHO: 968e912a: {3cac861c-57f0-e58c-5f0f-96692408100d} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4a52745e-23dc-2c05-8198-bb0832f2ab88} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e017b42-a27c-4d52-e766-374a2e15d79c} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {4e38e399-aeb7-dda4-d634-ac3e8dbd4227} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {52e7ea7d-2d56-fef1-3b01-278089e16f3b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {543f6def-6c26-8f97-eee8-e5a108f205c5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {604ce7f6-4c8a-14f7-8e1b-3887d6a7a645} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68aa5918-ac4e-780b-c880-102aa8381ab2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {68e6fa04-0e01-86ce-63ed-5d95445e0fb0} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {6cc82fa9-4464-b8fc-0ce9-765362ac1bdb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

BHO: 968e912a: {6fb0f356-cf41-da8a-58c1-481b5d985587} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {71604fac-4ce3-6cc5-b5cb-a6eff9dc24a8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO: 968e912a: {795026d0-63a3-efdd-2954-b88ff5358fe3} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {80548c5f-b624-13b2-a1d6-cc9cc27cfed5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8622be47-ccdb-e6df-4249-8f9a1833cf20} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8a4286f0-ff6d-7744-0e26-f535977d5811} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8f4874a1-2162-49b1-95a4-10b8ebfc36f4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {8fb83466-d655-b8ca-fcb2-fb116f2293d2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: 968e912a: {91a0f813-6032-da57-488a-cdd96a0ecc7e} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {94bf2316-f749-8b37-8331-1594c3a270b5} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {96df3f31-2ade-8d8b-4749-5ec2e20c9cb4} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {974e0edf-4354-ab30-25e5-48a8a05b71c9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {976f7f6c-75ec-1d72-e13b-73685fe63fd6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {97857535-508f-3a83-14b4-bd9cff03dc54} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {99fe6a35-c1f6-3e6b-82ef-a57d3c9f40eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9b328dc8-cec3-2919-913b-8be07e82d3f6} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9dad7119-3f96-5fb7-e8bd-21bf38c36dff} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {9f04f58b-7f65-f05e-9ba4-dfe0b6d50389} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: 968e912a: {a521da05-7bfd-dfdb-569b-4396ab727de9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: 968e912a: {ab49d6e8-6b04-0510-2aa4-a7b9e4310e94} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {add8c1b1-b70f-2509-cc59-dacdc1eb0fa9} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll

BHO: 968e912a: {afe4e744-3cbb-7af8-80b9-60e3a37bd78b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {aff8ddcc-e9a4-265d-9072-22fbe0553ba8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b19ebe5e-1052-6365-659f-9f435d2cd83b} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {b26fe1b4-bf8e-d9d2-753b-0a69571b1876} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: 968e912a: {c7da786b-57b4-5751-9653-6158418a56eb} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {c9fa9486-3249-52aa-1bae-9c8e77abb655} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {d15806a8-930d-b6be-5513-74324a3c2ac2} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

BHO: 968e912a: {da0dfc3d-33a1-aa78-425f-09f79adf34b8} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: 968e912a: {dc6580af-7371-3b1e-f546-c71818f1cb42} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {ee79840b-1044-7371-ad2c-546161db2e61} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f3ae5066-83fd-d072-250f-03bdbb6ccc08} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f4403d5c-a596-de07-4f4a-df3ebca33753} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

BHO: 968e912a: {f82e7aa0-b0d9-672b-9a78-e926b17e3957} - C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll

TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe

mRun: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [backupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k

mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED

mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"

mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [NPSStartup]

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun: [Nike+ Connect] "C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [plawow.exe] c:\windows\plawow.exe

mRun: [iaswow.exe] c:\windows\iaswow.exe

mRun: [werwow.exe] c:\windows\werwow.exe

mRun: [authfwwizfwkwow.exe] c:\windows\authfwwizfwkwow.exe

mRun: [apisetschemawow.exe] c:\windows\apisetschemawow.exe

mRun: [wfhcwow.exe] c:\windows\wfhcwow.exe

mRun: [nciwow.exe] c:\windows\nciwow.exe

mRun: [clbwow.exe] c:\windows\clbwow.exe

mRun: [dmrcwow.exe] c:\windows\dmrcwow.exe

mRun: [evrwow.exe] c:\windows\evrwow.exe

mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACERVC~1.LNK - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

AppInit_DLLs: C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll

BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [iAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe

mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

mRun-x64: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe

mRun-x64: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun-x64: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe

mRun-x64: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe

mRun-x64: [igfxTray] C:\Windows\system32\igfxtray.exe

mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe

mRun-x64: [PLFSetL] C:\Windows\\PLFSetL.exe

mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe

mRun-x64: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig

FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll

FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll

FF - component: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com

FF - Ext: XUL Cache: {ea99277b-8ca0-462a-aa62-110c24995993} - %profile%\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}

FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]

R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]

R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304]

R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]

R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032]

R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576]

R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016]

R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]

R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]

R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]

R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-9-4 107016]

R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-9-4 787968]

R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-6-4 1150496]

R2 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-8-6 311592]

R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-8-21 62720]

R2 RS_Service;Raw Socket Service;C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-9-4 253952]

R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-9-4 240160]

R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-3 157264]

R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-3 35920]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2009-9-4 138752]

R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-9-4 58880]

R3 NETw1v64;Intel® Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw1v64.sys [2009-9-4 7058432]

R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-9 136176]

S2 Power32;Power ;c:\windows\system32\winbrand32.exe --> c:\windows\system32\winbrand32.exe [?]

S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-10-22 48488]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]

S3 hitmanpro35;Hitman Pro 3.5 Support Driver;C:\Windows\System32\drivers\hitmanpro35.sys [2011-2-14 19528]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]

S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2009-9-4 5435904]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-9-4 215552]

S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2010-12-5 16448]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-14 1255736]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

=============== Created Last 30 ================

2011-02-20 22:45:49 -------- d-----w- C:\PROGRA~3\STOPzilla!

2011-02-20 22:36:46 -------- d-----w- C:\PROGRA~3\AWEM

2011-02-20 10:25:23 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys

2011-02-20 10:23:17 -------- d-----w- C:\Users\Dave\AppData\Local\Sunbelt Software

2011-02-20 10:22:39 -------- dc-h--w- C:\PROGRA~3\~0

2011-02-19 21:46:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\Malwarebytes

2011-02-19 21:45:08 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

2011-02-19 21:45:08 -------- d-----w- C:\PROGRA~3\Malwarebytes

2011-02-19 21:45:05 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-02-19 21:45:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-02-19 11:26:18 -------- d--h--w- C:\$AVG

2011-02-19 11:24:03 -------- d-----w- C:\Users\Dave\AppData\Roaming\AVG10

2011-02-19 11:22:31 -------- d--h--w- C:\PROGRA~3\Common Files

2011-02-19 11:22:20 -------- d-----w- C:\Windows\SysWow64\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\Windows\System32\drivers\AVG

2011-02-19 11:21:35 -------- d-----w- C:\PROGRA~3\AVG10

2011-02-19 11:20:51 -------- d-----w- C:\Program Files (x86)\AVG

2011-02-19 10:59:27 -------- d-----w- C:\PROGRA~3\MFAData

2011-02-18 07:18:28 7844688 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{AF5EEE2D-23D2-4562-9732-CF54BE1FB0FF}\mpengine.dll

2011-02-14 17:54:33 19528 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys

2011-02-14 16:31:58 -------- d-----w- C:\PROGRA~3\Hitman Pro

2011-02-10 08:14:59 97280 ----a-w- C:\Windows\System32\wscsvc.dll

2011-02-04 08:42:39 181608 ----a-w- C:\PROGRA~3\Microsoft\Windows\Sqm\Manifest\Sqm10137.bin

2011-02-02 14:06:06 -------- d-----w- C:\Users\Dave\AppData\Roaming\SUPERAntiSpyware.com

2011-02-02 14:06:06 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com

2011-02-02 14:05:26 -------- d-----w- C:\PROGRA~3\!SASCORE

2011-02-02 14:05:23 -------- d-----w- C:\Program Files\SUPERAntiSpyware

2011-02-01 20:41:47 -------- d-sh--w- C:\PROGRA~3\SysWoW32

2011-02-01 20:41:32 203776 --sh--w- C:\PROGRA~3\unrar.exe

2011-02-01 20:41:27 -------- d-sh--w- C:\PROGRA~3\A62BD338E38D783414C503FF194910D4

2011-02-01 20:00:13 -------- d-----w- C:\Users\Dave\AppData\Roaming\FrostWire

2011-02-01 19:59:15 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-02-01 19:59:15 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

2011-01-26 16:22:37 -------- d-----w- C:\Program Files (x86)\Nike

2011-01-26 16:22:37 -------- d-----w- C:\PROGRA~3\Nike

==================== Find3M ====================

2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll

2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll

2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll

2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll

2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll

2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll

2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys

2010-12-21 06:16:27 62976 ----a-w- C:\Windows\System32\wscapi.dll

2010-12-21 06:16:16 214016 ----a-w- C:\Windows\System32\winsrv.dll

2010-12-21 06:16:14 442880 ----a-w- C:\Windows\System32\winhttp.dll

2010-12-21 06:16:14 1197056 ----a-w- C:\Windows\System32\wininet.dll

2010-12-21 06:16:09 258048 ----a-w- C:\Windows\System32\WebClnt.dll

2010-12-21 06:15:55 264192 ----a-w- C:\Windows\System32\upnp.dll

2010-12-21 06:15:31 15360 ----a-w- C:\Windows\System32\slwga.dll

2010-12-21 06:13:03 2003968 ----a-w- C:\Windows\System32\msxml6.dll

2010-12-21 06:13:03 1880576 ----a-w- C:\Windows\System32\msxml3.dll

2010-12-21 06:10:22 100864 ----a-w- C:\Windows\System32\davclnt.dll

2010-12-21 05:38:24 51200 ----a-w- C:\Windows\SysWow64\wscapi.dll

2010-12-21 05:38:22 981504 ----a-w- C:\Windows\SysWow64\wininet.dll

2010-12-21 05:38:22 350720 ----a-w- C:\Windows\SysWow64\winhttp.dll

2010-12-21 05:38:21 204800 ----a-w- C:\Windows\SysWow64\WebClnt.dll

2010-12-21 05:38:19 204288 ----a-w- C:\Windows\SysWow64\upnp.dll

2010-12-21 05:38:16 14336 ----a-w- C:\Windows\SysWow64\slwga.dll

2010-12-21 05:36:17 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll

2010-12-21 05:36:16 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll

2010-12-21 05:34:12 80384 ----a-w- C:\Windows\SysWow64\davclnt.dll

2010-12-18 06:11:41 57856 ----a-w- C:\Windows\System32\licmgr10.dll

2010-12-18 06:11:34 714752 ----a-w- C:\Windows\System32\kerberos.dll

2010-12-18 05:29:40 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll

2010-12-18 05:29:31 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll

2010-12-18 04:55:03 482816 ----a-w- C:\Windows\System32\html.iec

2010-12-18 04:20:55 386048 ----a-w- C:\Windows\SysWow64\html.iec

2010-12-18 04:13:40 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

2010-12-18 03:47:59 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2010-12-08 04:12:36 308304 ----a-w- C:\Windows\System32\drivers\avgldx64.sys

2010-11-29 17:38:30 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx

2010-11-29 17:38:30 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts

============= FINISH: 23:00:07.28 ===============

Link to post
Share on other sites

Thanks! :)

**Note: If you need more detailed information, please visit the web page of ComboFix in BleepingComputer. **

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper.

Please download ComboFix from

Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  1. If you are using Firefox, make sure that your download settings are as follows:
    • Open Tools -> Options -> Main tab
    • Set to Always ask me where to Save the files.

[*]During the download, rename Combofix to Combo-Fix as follows:

CF_download_FF.gif

CF_download_rename.gif

[*]It is important you rename Combofix during the download, but not after.

[*]Please do not rename Combofix to other names, but only to the one indicated.

[*]Close any open browsers.

[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ----------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\Combo-Fix.txt for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Link to post
Share on other sites

ComboFix 11-02-24.01 - Dave 24/02/2011 22:55:20.1.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3999.2578 [GMT 0:00]

Running from: c:\users\Dave\Desktop\Combo-Fix.exe

AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\programdata\api-ms-win-core-misc-l1-1-032.dll

c:\programdata\SysWoW32

c:\programdata\SysWoW32\@u1017617189v0

c:\programdata\SysWoW32\@u1017617189v1

c:\programdata\SysWoW32\@u1017617189v2

c:\programdata\SysWoW32\@u1017617189v3

c:\programdata\SysWoW32\_u1017617189v0

c:\programdata\SysWoW32\_u1017617189v1

c:\programdata\SysWoW32\_u1017617189v2

c:\programdata\SysWoW32\_u1017617189v3

c:\programdata\SysWoW32\mu1017617189v4.kwd

c:\programdata\SysWoW32\mu1017617189v5.kwd

c:\programdata\SysWoW32\mu1017617189v6.kwd

c:\programdata\SysWoW32\mu1017617189v7.kwd

c:\programdata\SysWoW32\wu1017617189v0

c:\programdata\SysWoW32\wu1017617189v0.kwd

c:\programdata\SysWoW32\wu1017617189v1

c:\programdata\SysWoW32\wu1017617189v1.kwd

c:\programdata\SysWoW32\wu1017617189v2

c:\programdata\SysWoW32\wu1017617189v2.kwd

c:\programdata\SysWoW32\wu1017617189v3

c:\programdata\SysWoW32\wu1017617189v3.kwd

c:\programdata\unrar.exe

c:\users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\{A16B97E5-BC22-4D7E-B4CF-EA9FACA8349A}.xps

c:\users\Dave\AppData\Roaming\.#

c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}

c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}\chrome.manifest

c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}\chrome\xulcache.jar

c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}\defaults\preferences\xulcache.js

c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\extensions\{ea99277b-8ca0-462a-aa62-110c24995993}\install.rdf

.

((((((((((((((((((((((((( Files Created from 2011-01-24 to 2011-02-24 )))))))))))))))))))))))))))))))

.

2011-02-24 22:51 . 2011-02-24 22:52 -------- d-----w- C:\Combo-Fix

2011-02-24 06:44 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll

2011-02-24 06:43 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll

2011-02-23 18:49 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll

2011-02-23 18:49 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2011-02-23 18:49 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll

2011-02-23 18:49 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2011-02-20 22:45 . 2011-02-20 23:41 -------- d-----w- c:\programdata\STOPzilla!

2011-02-20 22:36 . 2011-02-20 22:36 -------- d-----w- c:\programdata\AWEM

2011-02-20 10:25 . 2011-02-20 10:25 49752 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-02-20 10:23 . 2011-02-20 10:23 -------- d-----w- c:\users\Dave\AppData\Local\Sunbelt Software

2011-02-20 10:22 . 2011-02-23 22:53 -------- d-----w- c:\programdata\Lavasoft

2011-02-19 21:46 . 2011-02-19 21:46 -------- d-----w- c:\users\Dave\AppData\Roaming\Malwarebytes

2011-02-19 21:45 . 2011-02-19 21:45 -------- d-----w- c:\programdata\Malwarebytes

2011-02-19 21:45 . 2010-12-20 18:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-02-19 21:45 . 2011-02-19 21:45 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-02-19 21:45 . 2010-12-20 18:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-02-19 11:24 . 2011-02-19 11:24 -------- d-----w- c:\users\Dave\AppData\Roaming\AVG10

2011-02-19 11:22 . 2011-02-19 11:22 -------- d--h--w- c:\programdata\Common Files

2011-02-19 11:21 . 2011-02-24 23:02 -------- d-----w- c:\programdata\AVG10

2011-02-19 11:20 . 2011-02-19 11:20 -------- d-----w- c:\program files (x86)\AVG

2011-02-19 10:59 . 2011-02-19 11:20 -------- d-----w- c:\programdata\MFAData

2011-02-18 07:18 . 2011-01-13 10:20 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AF5EEE2D-23D2-4562-9732-CF54BE1FB0FF}\mpengine.dll

2011-02-14 17:54 . 2011-02-14 18:50 19528 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys

2011-02-14 16:31 . 2011-02-14 18:48 -------- d-----w- c:\programdata\Hitman Pro

2011-02-14 16:24 . 2011-02-14 16:24 -------- d-----w- c:\windows\Sun

2011-02-11 19:28 . 2011-02-11 19:28 -------- d-----w- c:\program files (x86)\Common Files\Skype

2011-02-10 08:14 . 2010-12-21 06:16 97280 ----a-w- c:\windows\system32\wscsvc.dll

2011-02-04 08:42 . 2011-02-04 08:42 181608 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10137.bin

2011-02-02 14:06 . 2011-02-02 14:06 -------- d-----w- c:\users\Dave\AppData\Roaming\SUPERAntiSpyware.com

2011-02-02 14:06 . 2011-02-02 14:06 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

2011-02-02 14:05 . 2011-02-02 14:05 -------- d-----w- c:\programdata\!SASCORE

2011-02-02 14:05 . 2011-02-02 14:06 -------- d-----w- c:\program files\SUPERAntiSpyware

2011-02-01 20:41 . 2011-02-18 22:34 -------- d-sh--w- c:\programdata\A62BD338E38D783414C503FF194910D4

2011-02-01 20:00 . 2011-02-01 20:48 -------- d-----w- c:\users\Dave\AppData\Roaming\FrostWire

2011-02-01 19:59 . 2011-02-01 19:59 -------- d-----w- c:\program files (x86)\Common Files\Java

2011-02-01 19:59 . 2010-11-12 18:53 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2011-02-01 19:59 . 2010-11-12 18:53 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

2011-02-01 19:59 . 2011-02-14 19:02 -------- d-----w- c:\program files (x86)\Java

2011-01-26 16:22 . 2011-01-26 16:22 -------- d-----w- c:\programdata\Nike

2011-01-26 16:22 . 2011-01-26 16:22 -------- d-----w- c:\program files (x86)\Nike

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-29 17:38 . 2010-11-29 17:38 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

2010-11-29 17:38 . 2010-11-29 17:38 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2009-08-06 17:18 120104 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-04 39408]

"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-01-13 2988784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-08-27 1191432]

"EgisTecLiveUpdate"="c:\program files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-08-21 261888]

"NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]

"RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-15 91432]

"PDVD8LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-15 50472]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-12-13 421160]

"Nike+ Connect"="c:\program files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe" [2010-10-01 299008]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2009-9-4 708608]

Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-6-17 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

@=""

R0 szkg5;szkg5;c:\windows\SySWOW64\DRIVERS\szkg64.sys [x]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-09 136176]

R2 Power32;Power ;c:\windows\system32\winbrand32.exe [x]

R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-02-14 19528]

R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]

R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-05-14 5435904]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552]

R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]

R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-09-28 51712]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-14 1255736]

R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-06-17 834544]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]

S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]

S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]

S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]

S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]

S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-08-19 787968]

S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]

S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]

S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-21 62720]

S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]

S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]

S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 138752]

S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [2009-07-27 58880]

S3 NETw1v64;Intel® Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw1v64.sys [2009-07-20 7058432]

.

Contents of the 'Scheduled Tasks' folder

2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-09 12:12]

2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-09 12:12]

.

--------- x86-64 -----------

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2009-08-06 17:19 137512 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-06 7940128]

"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504]

"mwlDaemon"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]

"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2009-08-19 489472]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-08-12 165912]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-08-12 387608]

"Persistence"="c:\windows\system32\igfxpers.exe" [2009-08-12 365592]

"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]

"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/ig

uLocal Page = c:\windows\system32\blank.htm

mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_3810tz&r=273606102506l0341z195t48i1v625

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx

FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\vaqtafn4.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com

.

- - - - ORPHANS REMOVED - - - -

BHO-{01F0EB39-D41C-22C3-3361-E89284D2AD3D} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{05AA6DE2-AAB0-9A41-210A-45609E620CE0} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{072262E1-1B17-9D2A-8F46-2D41DBFE7076} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{0A0A268E-A5F4-BFB7-DB1E-08D6EAAA227F} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{0BB05C92-CBA4-6CAF-A888-5FE3F2E1E9C3} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{11D85875-BBAB-92E4-7C92-C3062BA17B6D} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{1F3C55EE-D9DF-A8EA-CEAB-D40C7868B278} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{1FAB249B-F355-C68F-AC47-BEF336B7878D} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{28F24B82-7973-9CA4-BBF7-6AD1C80BBC6E} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{2A4ACFF4-B943-2D4A-6EDD-27F2461D52F8} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{2DD9BABD-054D-4D43-1092-5A0723D6530D} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{3BCDF770-6E8E-F430-FC9D-80B4ED772D39} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{3C5D37AB-B99C-8518-958E-955B6951D15B} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{3CAC861C-57F0-E58C-5F0F-96692408100D} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{4A52745E-23DC-2C05-8198-BB0832F2AB88} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{4E017B42-A27C-4D52-E766-374A2E15D79C} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{4E38E399-AEB7-DDA4-D634-AC3E8DBD4227} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{52E7EA7D-2D56-FEF1-3B01-278089E16F3B} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{543F6DEF-6C26-8F97-EEE8-E5A108F205C5} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{604CE7F6-4C8A-14F7-8E1B-3887D6A7A645} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{68AA5918-AC4E-780B-C880-102AA8381AB2} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{68E6FA04-0E01-86CE-63ED-5D95445E0FB0} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{6CC82FA9-4464-B8FC-0CE9-765362AC1BDB} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{6FB0F356-CF41-DA8A-58C1-481B5D985587} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{71604FAC-4CE3-6CC5-B5CB-A6EFF9DC24A8} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{795026D0-63A3-EFDD-2954-B88FF5358FE3} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{80548C5F-B624-13B2-A1D6-CC9CC27CFED5} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{8622BE47-CCDB-E6DF-4249-8F9A1833CF20} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{8A4286F0-FF6D-7744-0E26-F535977D5811} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{8F4874A1-2162-49B1-95A4-10B8EBFC36F4} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{8FB83466-D655-B8CA-FCB2-FB116F2293D2} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{91A0F813-6032-DA57-488A-CDD96A0ECC7E} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{94BF2316-F749-8B37-8331-1594C3A270B5} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{96DF3F31-2ADE-8D8B-4749-5EC2E20C9CB4} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{974E0EDF-4354-AB30-25E5-48A8A05B71C9} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{976F7F6C-75EC-1D72-E13B-73685FE63FD6} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{97857535-508F-3A83-14B4-BD9CFF03DC54} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{99FE6A35-C1F6-3E6B-82EF-A57D3C9F40EB} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{9B328DC8-CEC3-2919-913B-8BE07E82D3F6} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{9DAD7119-3F96-5FB7-E8BD-21BF38C36DFF} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{9F04F58B-7F65-F05E-9BA4-DFE0B6D50389} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{A521DA05-7BFD-DFDB-569B-4396AB727DE9} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{AB49D6E8-6B04-0510-2AA4-A7B9E4310E94} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{ADD8C1B1-B70F-2509-CC59-DACDC1EB0FA9} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{AFE4E744-3CBB-7AF8-80B9-60E3A37BD78B} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{AFF8DDCC-E9A4-265D-9072-22FBE0553BA8} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{B19EBE5E-1052-6365-659F-9F435D2CD83B} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{B26FE1B4-BF8E-D9D2-753B-0A69571B1876} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{C7DA786B-57B4-5751-9653-6158418A56EB} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{C9FA9486-3249-52AA-1BAE-9C8E77ABB655} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{D15806A8-930D-B6BE-5513-74324A3C2AC2} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{DA0DFC3D-33A1-AA78-425F-09F79ADF34B8} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{DC6580AF-7371-3B1E-F546-C71818F1CB42} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{EE79840B-1044-7371-AD2C-546161DB2E61} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{F3AE5066-83FD-D072-250F-03BDBB6CCC08} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{F4403D5C-A596-DE07-4F4A-DF3EBCA33753} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

BHO-{F82E7AA0-B0D9-672B-9A78-E926B17E3957} - c:\programdata\api-ms-win-core-misc-l1-1-032.dll

Toolbar-Locked - (no file)

Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe

Wow6432Node-HKLM-Run-NPSStartup - (no file)

Wow6432Node-HKLM-Run-plawow.exe - c:\windows\plawow.exe

Wow6432Node-HKLM-Run-iaswow.exe - c:\windows\iaswow.exe

Wow6432Node-HKLM-Run-werwow.exe - c:\windows\werwow.exe

Wow6432Node-HKLM-Run-authfwwizfwkwow.exe - c:\windows\authfwwizfwkwow.exe

Wow6432Node-HKLM-Run-apisetschemawow.exe - c:\windows\apisetschemawow.exe

Wow6432Node-HKLM-Run-wfhcwow.exe - c:\windows\wfhcwow.exe

Wow6432Node-HKLM-Run-nciwow.exe - c:\windows\nciwow.exe

Wow6432Node-HKLM-Run-clbwow.exe - c:\windows\clbwow.exe

Wow6432Node-HKLM-Run-dmrcwow.exe - c:\windows\dmrcwow.exe

Wow6432Node-HKLM-Run-evrwow.exe - c:\windows\evrwow.exe

SafeBoot-mcmscsvc

SafeBoot-MCODS

Toolbar-Locked - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

HKLM-Run-PLFSetL - c:\windows\\PLFSetL.exe

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"

"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"

"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\program files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe

c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

.

**************************************************************************

.

Completion time: 2011-02-24 23:08:52 - machine was rebooted

ComboFix-quarantined-files.txt 2011-02-24 23:08

Pre-Run: 167,037,349,888 bytes free

Post-Run: 168,624,082,944 bytes free

- - End Of File - - 8DF1F6A9EE7C2D1E46CC53D93113FFB6

Link to post
Share on other sites

... so far, so good...

Thanks loads for advising me, I have no idea what the various tests were that I was running for you to check my computer but it seems to have done the trick. Iam very keen to reinstall AVG so I have some protection. Can I do this now or should I wait a little longer?

Thanks again

Link to post
Share on other sites

It's makes no sense to re-install AVG. If you want to have some protection change your AV. More information about that in my last step.

Last steps for you:

Step 1

Go to Start => Run... and copy & paste next command in the field:

ComboFix /uninstall

Then hit Enter button.

This procedure will do the following:

  • Uninstall ComboFix
  • Delete its related folders and files
  • Reset your clock settings
  • Hide file extensions
  • Hide the system/hidden files
  • Resets System Restore again

Note: Make sure there's a space between ComboFix and /uninstall

Step 2

Please manually delete DDS, GMER and TDSSKiller.

Step 3

Keep your software up-to-date:

http://www.bleepingcomputer.com/tutorials/tutorial174.html

Some malware preventions:

http://forums.malwarebytes.org/index.php?showtopic=9365

Safe surfing! :)

Link to post
Share on other sites

  • 2 weeks later...
Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.